Two updates landed on the Windows 365 What’s New page this week, and both are worth paying attention to. One moves a key provisioning feature to general availability for Windows 365 Reserve, while the other introduces a new admin-controlled display setting that’s entering public preview.
Let’s break down what’s new, why it matters, and what IT teams need to do.
1. Autopilot Device Preparation for Windows 365 Reserve Hits GA
The Background
Windows 365 Reserve — Microsoft’s on-demand Cloud PC SKU for temporary and emergency access scenarios — has historically had a provisioning gap. Unlike Windows 365 Enterprise and Flex, which have supported Autopilot Device Preparation (DPP) for some time, Reserve was still relying on manual or custom image-based provisioning to get required apps and configurations onto Cloud PCs.
DPP for Reserve entered public preview back in April 2026. Now, as of the week of August 24, 2026, it’s generally available.
What It Does
Autopilot Device Preparation in automatic mode lets administrators link a Device Preparation policy to a Windows 365 Reserve provisioning policy in Microsoft Intune. When a Reserve Cloud PC is provisioned, it stays in a “Preparing” state while required applications, PowerShell scripts, and configurations are installed and validated. Only after those requirements are met is the Cloud PC marked as provisioned and made available to the user.
This brings Reserve to parity with the other Windows 365 SKUs — Enterprise, Flex Dedicated, Flex Shared, and Cloud Apps — which already had GA support for DPP automatic mode.
Why It Matters
For IT admins, this is about closing the last provisioning gap in the Windows 365 family:
- Zero-touch provisioning for Reserve Cloud PCs — required corporate agents, productivity apps, and baseline configs are applied automatically, no manual intervention needed
- Consistency across all Windows 365 SKUs — every Cloud PC type now uses the same modern provisioning approach, simplifying documentation, training, and automation
- Better security posture — user sign-in can be gated on successful installation of required security tools like EDR agents, VPN clients, and hardening scripts
- Reduced dependency on custom images — apps and configurations are delivered via Intune policies instead of being baked into images, making updates and changes much easier to manage
Use Cases
- Emergency replacement devices — when a user’s physical PC fails, a Reserve Cloud PC can be provisioned automatically with all required security tools and apps already in place
- Temporary contractor access — provision Reserve Cloud PCs with department-specific app baselines without building custom images
- Seasonal or project-based workers — quickly spin up Reserve capacity with guaranteed configuration consistency across hundreds of Cloud PCs
- Security-first deployments — ensure EDR/AV agents, VPN/ZTNA clients, and hardening scripts are installed and verified before employees can access their Cloud PCs
Prerequisites
To use DPP with Windows 365 Reserve, you’ll need:
- OS: Windows 11, version 24H2 or later
- Identity: Microsoft Entra ID join only (hybrid join is not supported)
- Enrollment: Automatic Intune enrollment must be configured for your tenant
- Licensing: Appropriate Windows 365 Reserve licenses and Intune subscription
- Intune configuration:
- An assigned device group for Cloud PCs
- Required apps and PowerShell scripts targeted to that device group
- A Windows Autopilot Device Preparation policy in Automatic mode
- A Windows 365 Reserve provisioning policy that references the Device Preparation policy
Limitations to Be Aware Of
- Only Microsoft Entra join is supported — hybrid join environments cannot use DPP automatic mode
- Device Preparation policies support a finite number of required apps and scripts (up to 10 each)
- Custom images must meet specific OS and update baselines (Windows 11 24H2 with required cumulative updates)
- Misconfiguration can lead to Cloud PCs stuck in “Preparing” status — make sure to test policies before broad deployment
What IT Admins Should Do
- Review your Reserve provisioning policies — in the Microsoft Intune admin center, navigate to Provision Cloud PCs > Provisioning policies and check whether your Reserve policies have a Device Preparation policy linked
- Create a DPP policy — if you haven’t already, create a Windows Autopilot Device Preparation policy in Automatic mode with the required apps and scripts for your Reserve use cases
- Test with a small group first — assign the DPP policy to a test provisioning policy and provision a few Cloud PCs to validate the workflow before rolling out broadly
- Update your runbooks — Reserve Cloud PC provisioning documentation should be updated to reflect the new DPP workflow, replacing any manual or custom image-based steps
- Communicate with your team — let helpdesk and support teams know about the “Preparing” status and what it means, so they don’t treat it as a provisioning failure
2. Default Display Settings for Cloud PCs (Public Preview)
The Problem It Solves
If you’ve managed Windows 365 environments, you know the scenario: some users want their Cloud PC to open on all their monitors, while others (especially in call center or shared workstation environments) only need a single display. Until now, display behavior was largely driven by the client app defaults and user choices in Windows App. There was no admin-controlled default.
That changes with this new feature, which is now in public preview.
What It Does
IT administrators can now configure the default display setting for Windows 365 Cloud PCs through the Remote Connection Experience settings in Intune. Admins can choose between:
- Single display — Cloud PCs open on the primary monitor only
- All displays — Cloud PCs open across all available monitors on the client device
Users can still override the default in the Windows App, so this is a preference, not a lockdown.
Why It Matters
This is a quality-of-life improvement that has real operational impact:
- Persona-based configuration — set multi-display as default for developers and analysts who need screen real estate, and single-display for front-line staff who don’t
- Reduced helpdesk overhead — fewer “how do I set up my monitors?” tickets because Cloud PCs open in the expected configuration by default
- Standardized experience across departments — in mixed hardware environments with laptops, docking stations, and thin clients, a policy-driven default ensures predictable behavior
- User flexibility preserved — power users can still override the default to match their personal workflow
How to Configure It
The setting is configured through the Remote Connection Experience settings for Cloud PCs in Microsoft Intune:
- In the Microsoft Intune admin center, navigate to the Windows 365 settings area
- Create or edit a Remote Connection Experience policy
- Set the default display option (single display or all displays)
- Assign the policy to the appropriate user or device groups
Limitations
- Public preview — behavior, UI, and policy options may change before GA
- SKU availability — documented for Windows 365 Enterprise and Windows 365 Flex; other SKUs may not initially support this
- User override — admin-set defaults are not enforced; users can change their display preference in Windows App
- Client dependency — effectiveness depends on Windows App version and platform support
What IT Admins Should Do
- Identify your personas — map out which user groups would benefit from single-display vs. multi-display defaults
- Create Remote Connection Experience policies — set up policies with the appropriate display defaults for each persona group
- Pilot with a small group — test the behavior with a few users to confirm the defaults work as expected on different client devices and hardware configurations
- Communicate the override option — let users know they can still change their display settings in Windows App if the default doesn’t suit their workflow
- Monitor for GA — since this is public preview, watch for updates that may change the configuration experience or add SKU support
The Bigger Picture
These two updates, while different in scope, both reflect Microsoft’s ongoing investment in making Windows 365 more manageable and user-friendly:
- DPP for Reserve GA completes the provisioning modernization story across all Windows 365 SKUs. Every Cloud PC type — Enterprise, Flex Dedicated, Flex Shared, Cloud Apps, and now Reserve — can leverage zero-touch, policy-driven provisioning through Intune.
- Default display settings adds another layer of admin control to the Remote Connection Experience framework, giving IT teams more tools to tailor the Cloud PC experience to different user personas without locking users out of their own preferences.
For organizations already deep into Windows 365, these are incremental but meaningful improvements. For those still evaluating, they’re further evidence that Microsoft is continuing to invest in the platform’s manageability and user experience.
Summary
| Feature | Status | SKU | Key Benefit |
|---|---|---|---|
| Autopilot Device Preparation for Reserve | GA | Windows 365 Reserve | Zero-touch provisioning with policy-driven app/script installation |
| Default display settings for Cloud PCs | Public Preview | Windows 365 Enterprise & Flex | Admin-controlled default display mode (single or multi-monitor) |
For more information, see the Windows 365 What’s New documentation, Managing Windows 365 Reserve, and Remote connection experience.
Follow Kevin Kaminski on X for daily Windows 365 updates and analysis.