Cloud desktops have been around for a long time. For a while, the sales pitch was mostly that you could put a Windows desktop in the cloud instead of running it on a computer in the office.
That can still be useful, but it is not the most interesting reason to look at cloud desktops now.
BYOD changes the conversation.
If someone wants to work from a personal laptop, the question should not just be whether they can sign in to Microsoft 365. The better question is how much business data actually needs to leave Microsoft 365 and reside on a computer the business does not manage.
BYOD is really a question of trust
The simple BYOD model usually looks something like this: an employee or contractor has a personal laptop, installs Outlook and the Office applications, signs in to OneDrive, and starts working.
It works, but the business has now allowed its information to become part of an endpoint it does not control.
That personal computer might have unknown security software, poor patching, other users with access to it, personal cloud storage applications, uncontrolled backups, USB storage, unwanted software or very little meaningful security monitoring.
Once OneDrive starts synchronising company files locally, part of the security boundary has moved from Microsoft 365 onto that personal computer.
This is why our preferred question is:
How much of our data actually needs to live on this device?

Microsoft 365 gives us a useful middle ground
BYOD does not have to mean giving a personal device the same access as a managed business computer.
Personal phones and tablets
On iPhone, iPad and Android devices, Microsoft Intune App Protection Policies can protect organisational information inside supported applications without requiring the business to fully manage the employee’s personal device.
That means the work side of applications such as Outlook, Teams, OneDrive, Word and Excel can have controls around things like copying data into personal applications, saving company information to personal storage, access requirements and selective removal of business data.
The employee can still own and use the phone as their personal device. The business is protecting its information inside the work applications rather than taking over the whole phone.
Windows BYOD is different
Windows now has its own Intune application protection model for unmanaged devices, but there is an important difference.
Microsoft’s current Windows MAM model is centred on Microsoft Edge for Business. It does not place the traditional Windows desktop versions of Outlook, Word, Excel and OneDrive inside the same protected application boundary on a personal PC.
At first that sounds restrictive. For plenty of users, it really is not.
Through a protected Edge for Business work profile, someone can still use Outlook on the web, Teams, OneDrive, SharePoint, Word, Excel, PowerPoint and the other Microsoft 365 web applications they rely on day to day.
Microsoft also supports limited web-only access for SharePoint and OneDrive on unmanaged devices. When configured appropriately, users can be prevented from downloading, printing or synchronising files locally, while still being able to work in the browser.
For a contractor, occasional remote worker or someone who mostly needs email, Teams and access to documents, the browser may provide everything they actually need.
More importantly, the entire SharePoint library or OneDrive account does not need to be synchronised onto a computer the business does not control.
Sometimes the safest answer really is just the browser
There is a tendency in IT to make BYOD more complicated than it needs to be.
If someone needs to read email, join Teams meetings, review a few documents and update a spreadsheet, there may be very little benefit in installing the full Office desktop suite and synchronising business files onto their personal computer.
Personal Windows PC → protected Edge work profile → Microsoft 365
That is a perfectly sensible access model for many BYOD users.
And when the browser is not enough, cloud desktops get interesting again
This is where the cloud desktop starts to make much more sense.
VDI, Remote Desktop Services and hosted desktops are not new. Many businesses have spent the last decade moving away from traditional remote desktop environments as applications moved to Microsoft 365 and other cloud services.
But BYOD creates a very useful reason to separate the device someone is physically using from the business Windows environment they are actually working inside.

Instead of putting Office, OneDrive and business applications directly onto a personal laptop, the user connects to a Windows environment controlled by the business.
Personal computer → secure remote desktop service → managed Windows environment → Microsoft 365 and business applications
The personal computer becomes an access endpoint rather than the place where all of the business applications and data have to live.
Importantly, that remote desktop layer does not have to live in one vendor’s cloud. Depending on the client and the workload, it could be a Q10-managed environment in private infrastructure or a datacentre, Amazon WorkSpaces Personal, Windows 365, Azure Virtual Desktop, or a properly designed Remote Desktop Services or VDI environment.
The platform is a design choice
Microsoft’s own options include Windows 365 and Azure Virtual Desktop. AWS provides WorkSpaces Personal for persistent virtual desktops. Private or hosted RDS and VDI environments can also make sense where a business wants more control over hosting, application compatibility, networking or the commercial model.
Q10’s position is deliberately platform-agnostic. We would rather choose the environment that fits the business than force every client into the same cloud. In some cases that may be Microsoft. In others it may be AWS or a Q10-managed private platform.
The right option depends on the user, the applications involved, licensing, performance requirements, security requirements and how much operational complexity the business actually wants.
A cloud desktop can be a security boundary
This is the part of the cloud desktop conversation that has become more interesting.
The value is not simply that Windows is running somewhere else. The value is that the business can control the Windows environment without needing to treat the user’s personal computer as a fully trusted corporate endpoint.
Different platforms expose different controls over how information moves between the remote desktop and the physical device. Administrators may be able to restrict things such as clipboard, local drive, printer and USB redirection. As one example, Microsoft’s current Windows 365 guidance says clipboard, drive, opaque low-level USB and printer redirection are disabled by default for newly provisioned Cloud PCs.
That does not magically make every personal computer safe. Authentication, Conditional Access, session controls, patching, endpoint risk and the design of the remote environment still matter.
But it changes the problem from “how do we make this random personal computer part of our environment?” to “how do we let this device securely reach an environment we already control?”
The access model we prefer
Personal mobile device
Use Intune App Protection Policies with supported Microsoft applications. Protect the organisational data without unnecessarily taking over the person’s entire phone or tablet.
Personal Windows computer
Keep Microsoft 365 inside a protected Edge for Business work environment where practical. Use web applications and keep SharePoint and OneDrive data in Microsoft 365 rather than synchronising it locally.
Cloud desktop
If the person genuinely needs desktop Office applications, line-of-business software, a persistent Windows environment, OneDrive synchronisation or more substantial daily access, give them a managed Windows environment rather than pushing all of that directly onto an unmanaged computer. That environment could be Q10-hosted, AWS-based, Microsoft-hosted or another appropriately designed remote desktop platform.
Managed physical computer
If the employee needs full offline capability, significant local hardware integration or a normal high-performance workstation experience, provide a properly managed business computer.
BYOD should not mean copying the business environment onto whatever computer someone owns
There is a big difference between these two ideas:
“You can install our applications and synchronise our files onto your computer.”
and:
“You can use your computer to securely access the business environment we provide.”
The second model gives the business far more control over where information lives and how it can move.
Sometimes the browser is enough.
When it is not, a desktop in the cloud starts to make sense again.
Cloud desktops have a better job now
We do not think every user needs a cloud desktop, and we would not deploy one simply because it sounds modern.
For lightweight access, protected mobile applications or a protected browser can be simpler and cheaper. For users who need a complete Windows environment, a Q10-hosted desktop, Amazon WorkSpaces Personal, Windows 365, Azure Virtual Desktop or an appropriately designed RDS or VDI environment can create a useful separation between the device a person owns and the business environment they work in.
That makes the cloud desktop more than a replacement for an office PC.
It can be a practical way to give someone a complete business desktop without giving their personal computer direct, unrestricted access to the business environment.
If you are reviewing BYOD, it is also worth reading our guide on BYOD vs company-owned devices. Q10 can also help review how Microsoft 365, cybersecurity controls, managed computers and cloud desktops should fit together for your team.
Talk to Q10 about your Microsoft 365 or BYOD setup.
Cloud desktop, Microsoft 365 and Intune capabilities change over time. Product behaviour described here reflects published guidance available in August 2026. Featured photo by Clay Banks on Unsplash.
