Two general-availability announcements landed on the Windows 365 What’s New page this week, and both close important gaps for specific Windows 365 audiences. First, Autopilot Device Preparation (DPP) for Citrix Cloud PCs is now generally available for Windows 365 Government. Second, Microsoft Purview Customer Key (CMK) for Windows 365 Reserve has moved from public preview to GA, completing the enterprise encryption story for the on-demand Cloud PC SKU.
What Changed
Autopilot Device Preparation for Citrix Cloud PCs — GA for Windows 365 Government (Week of August 31, 2026)
Autopilot Device Preparation support for Citrix Cloud PCs is now generally available for Windows 365 Government. Administrators in GCC High and DoD environments can use device preparation policies with Citrix-integrated Cloud PCs to help ensure required apps and scripts are installed during provisioning — before the Cloud PC is ready for use.
This is the government extension of a capability Microsoft shipped for commercial tenants in late July 2026. At the time, DPP for Citrix brought the Citrix Cloud PC provisioning experience in line with native Windows 365 scenarios, and this week’s update does the same for government clouds.
Microsoft Purview Customer Key for Windows 365 Reserve — GA (Week of August 3, 2026 update)
Microsoft Purview Customer Key support for Windows 365 Reserve is now generally available. Administrators can encrypt Reserve Cloud PC disks with customer-managed keys stored in Azure Key Vault, providing greater control over encryption key management — including key rotation, revocation, and auditing.
CMK for Reserve was announced in public preview in early July 2026. With this GA, the capability extends the existing Customer Key experience for Windows 365 Cloud PCs to the Reserve SKU, joining Windows 365 Enterprise and Flex.
Autopilot Device Preparation for Citrix Cloud PCs: Closing the Government Provisioning Gap
If you manage Citrix-integrated Cloud PCs in a government tenant, this update removes one of the last provisioning parity gaps between your environment and commercial Windows 365.
Why DPP for Citrix matters in Government clouds
- Policy-driven Citrix provisioning. Instead of provisioning a Citrix Cloud PC and remediating it after the fact, you attach a DPP policy to the provisioning workflow so required Intune apps and scripts run during setup.
- Consistent first-run readiness. Users get a Cloud PC that is genuinely ready for work on first sign-in, whether it was provisioned through the native Windows 365 path or the Citrix integration.
- Fewer post-provisioning tickets. Staging line-of-business apps, security agents, and configuration scripts during provisioning reduces the “Cloud PC exists but isn’t ready” gap that generates help-desk noise.
- Governable, repeatable builds. Government environments depend on deterministic, auditable deployment processes. DPP policies give Citrix-hosted Cloud PCs the same policy-driven build process as the rest of your fleet.
What to keep in mind
As with other government-cloud DPP scenarios, this is about deployment-time preparation. It doesn’t replace ongoing app management, compliance, or remediation after the device is in use. The value depends on your device preparation policies being well-authored — apps and scripts must be deployable within the provisioning window and compatible with your Cloud PC build process.
Microsoft Purview Customer Key for Windows 365 Reserve: Encryption Control for On-Demand Cloud PCs
Windows 365 Reserve Cloud PCs are temporary by design — provisioned for emergency device replacement, contractor onboarding, seasonal surges, and other short-term needs. But temporary doesn’t mean the data on those disks falls outside your compliance obligations.
What CMK gives Reserve customers
- Customer-controlled keys. Reserve Cloud PC disks are encrypted with keys your organization holds in Azure Key Vault, rather than relying solely on Microsoft-managed keys.
- Key lifecycle control. Rotation, revocation, and auditing are managed under your organization’s security processes — the same controls regulated industries already apply to their other encrypted workloads.
- Compliance alignment. For organizations subject to contractual, regulatory, or sovereignty requirements, CMK provides a defensible answer to “who controls the encryption keys for our data at rest?”
- Portfolio consistency. CMK already covers Windows 365 Enterprise and Flex. With Reserve at GA, every Windows 365 SKU now supports customer-managed encryption.
The operational trade-off
Customer-managed encryption transfers real responsibility to your team. Key rotation, access control, incident handling, and recovery planning become your job. If a key is disabled, revoked, or otherwise unavailable, it can affect access to the encrypted Cloud PCs — so key governance needs to be deliberate, with break-glass processes in place before you enable CMK at scale.
What Admins Should Do Now
Government + Citrix: update your runbooks. If your provisioning documentation still reflects a lack of DPP support for Citrix Cloud PCs in GCC High/DoD, update it and start planning policy-driven Citrix provisioning.
Pilot DPP for Citrix in a test group. Create a device preparation policy, assign required apps and scripts, link it to a Citrix Cloud PC provisioning policy, and validate with a small batch before broad rollout. Watch the provisioning flow closely — misconfigured DPP policies can leave Cloud PCs stuck in a preparing state.
Reserve CMK: review your preview configuration. If you onboarded CMK for Reserve during public preview, confirm your configuration is ready for GA — including key vault permissions, key rotation schedules, and audit logging.
New to CMK on Reserve? Start with prerequisites. Onboard Microsoft Purview Customer Key, provision your Azure Key Vault, and document your key lifecycle and recovery processes before you encrypt production Reserve pools. Test revocation and recovery in a non-production environment.
Update compliance documentation. If you’ve been waiting for Reserve CMK GA to satisfy an internal or external compliance requirement, this is the signal to finalize the rollout and update your evidence records.
Looking Ahead
These two announcements follow a consistent pattern: Microsoft is methodically closing feature gaps — between commercial and government clouds on the provisioning side, and across SKUs on the security side. Government tenants running Citrix now have a provisioning story on par with commercial environments, and Reserve customers now have the same data-at-rest controls as Enterprise and Flex.
For organizations that run Citrix-integrated Cloud PCs in GCC High or DoD, or that use Windows 365 Reserve in regulated industries, both updates are worth acting on now rather than waiting for the next quarterly cycle.
Planning Citrix-integrated Cloud PC deployments in government, or rolling out customer-managed encryption for Windows 365 Reserve? Big Hat Group helps organizations architect, secure, and operate Windows 365 at scale. Follow the conversation on X for daily Windows 365 updates.