Cloud & infrastructure

Migrate from the Remote Desktop client to Windows App with Intune

Replace the retired Remote Desktop MSI client with Windows App on managed devices: find remaining users, deploy through Intune, control updates and remove the legacy client.

11 min read
On this page

The standalone Remote Desktop client (MSI) for Windows is no longer supported for public cloud customers as of March 27, 2026, and it doesn't upgrade itself: you must deploy Windows App and remove the old client. With Intune, add Windows App as a Microsoft Store app (new) (Store ID 9N1F85V9T8BN) or as an MSIX line-of-business app, use the Win32 app uninstall assignment to remove the Remote Desktop client, and track stragglers with the WVDConnections table for Azure Virtual Desktop or the Microsoft Graph client usage report for Windows 365.

Who this is for and what you will have

This guide is for endpoint administrators whose users connect to Azure Virtual Desktop (AVD), Windows 365 or Microsoft Dev Box from managed Windows devices. At the end you will have:

  • A list of users still connecting with the legacy client.
  • Windows App deployed through Intune by the method that suits each device group.
  • A deliberate update policy for Windows App.
  • The Remote Desktop client removed, with a way to verify nobody is left behind.

What retired and when

ClientStatus
Remote Desktop client for Windows (MSI), public cloudNot supported since March 27, 2026
Remote Desktop client for Windows (MSI), Azure Government, Azure operated by 21Vianet, AVD classicSupport was extended until September 28, 2026
Remote Desktop app from the Microsoft StoreEnd of support September 2025; connections to Windows 365, AVD and Dev Box blocked from September 30, 2025; no longer available to download
Remote Desktop on macOS, iOS, iPadOS, AndroidUpdates automatically to Windows App

Microsoft continued to ship security updates for the MSI client during 2026; the latest listed release, 1.2.7391, appeared on September 8, 2026. That doesn't change its support status for public cloud, and Microsoft directs users to migrate to Windows App to keep access to AVD and Windows 365.

One exception matters for planning: Windows App on Windows doesn't yet support connections to Remote Desktop Services, and Microsoft's documentation tells those users to keep using the Remote Desktop app on Windows. Scope this migration to AVD, Windows 365 and Dev Box connections, and handle on-premises RDS users separately.

Prerequisites

  • Supported Windows versions: Windows 11, including LTSC and IoT Enterprise; Windows 10 version 1809 and later, including LTSC and IoT Enterprise; or Windows Server 2019 and later. Windows 10 devices outside mainstream support need Extended Security Updates.
  • Network: user devices must reach the end-user endpoints in Microsoft's AVD required FQDN list, including *.wvd.microsoft.com, login.microsoftonline.com, windows.cloud.microsoft, *.windows.cloud.microsoft and *.windows.static.microsoft.
  • For the Microsoft Store app (new) type: at least two processor cores, support for the Intune Management Extension, and access to the Microsoft Store and its content locations.
  • For offline MSIX installs: Windows App 2.0.1314.0 and later depend on Microsoft.WindowsAppRuntime.2 version 2.1.3.0 or later.
  • Roles: an Intune role that can create and assign apps, and access to the Log Analytics workspace used by AVD Insights.

Step 1: Find users still on the Remote Desktop client

Azure Virtual Desktop

Open AVD Insights at https://aka.ms/avdi, select your subscriptions, resource groups and host pools, and open the Clients tab. Users with potentially outdated clients lists each client type with its newest version and the users behind it, and you can export the table.

To get user names, run this query in the Log Analytics workspace that receives AVD diagnostics. It's the query Microsoft publishes in its migration guidance:

WVDConnections
| where ClientType has_any ("com.microsoft.rdc.windows.msrdc.arm64", "com.microsoft.rdc.windows.msrdc.x86", "com.microsoft.rdc.windows.msrdc.x64")
| summarize Connections=count(), LastSeen=max(TimeGenerated) by UserName, ClientType, ClientVersion, ClientOS
| order by Connections desc

For a quick view of every client type and version in use, Microsoft's sample query for the same table is:

WVDConnections
| summarize UserCount=dcount(UserName) by ClientType, ClientVersion
| sort by ClientVersion, ClientType, UserCount desc

Windows 365

Intune doesn't currently have a built-in report of Remote Desktop client users. Microsoft Graph has one in the beta endpoint, which needs the CloudPC.ReadWrite.All permission:

POST https://graph.microsoft.com/beta/deviceManagement/virtualEndpoint/report/retrieveCloudPcClientAppUsageReport
Content-Type: application/json
{
  "filter": "",
  "reportType": "microsoftRemoteDesktopClientUsageReport",
  "select": ["UPN", "LastSignOn", "DaysWithUsage"],
  "search": "",
  "skip": 0,
  "top": 50
}

The response lists each user's UPN, the last date they signed in with the legacy client and the number of days with usage in the last 28 days. Beta APIs can change and aren't supported for production applications, so use it for migration tracking only.

Step 2: Choose a deployment method

MethodWhen to use itUpdates
Microsoft Store app (new)Default for Intune-managed physical devicesDelivered by the Microsoft Store, checked every 8 hours and installed when Windows App is closed
MSIX as a line-of-business appDevices without Store access, or when you need to control the versionDelivered from a Microsoft CDN by default, configurable through the registry
Both side by side with the old clientTraining periodUsers can run Windows App and the Remote Desktop client on the same device

Microsoft states that apps with an ARM64 installer aren't supported through the Microsoft Store app (new) type. If you manage Arm64 devices, test the Store deployment on them in your pilot and keep the Arm64 MSIX package available as the fallback.

Step 3: Deploy Windows App from the Microsoft Store

  1. In the Microsoft Intune admin center, go to Apps > All apps > Add.
  2. In Select app type, choose Microsoft Store app (new) > Select.
  3. Select Search the Microsoft Store app (new), search for Windows App (package identifier 9N1F85V9T8BN) and choose Select.
  4. On App information, set Install behavior. Use System for devices that are Microsoft Entra registered; Microsoft also advises not mixing install contexts for the same app.
  5. On Assignments, add your device groups under Required so the app installs before users sign in. Optionally add user groups under Available for enrolled devices so Windows App appears in Company Portal.
  6. Select Review + create > Create.

Two Store policies can break this deployment:

  • Leave Turn off Automatic Download and Install of updates set to Disabled or Not configured, or Store-delivered Windows App updates stop.
  • To stop users from installing arbitrary Store apps, Microsoft's Intune documentation recommends Turn off the Store application over Only display the private store within the Microsoft Store app (RequirePrivateStoreOnly). Neither setting blocks Intune from installing Store apps.

Step 4: Deploy the MSIX package instead (optional)

Use this path for devices that can't reach the Store or when you need version control.

  1. Download the 64-bit, 32-bit or Arm64 MSIX from the Latest release section of Microsoft's What's new in Windows App page.
  2. In Intune, go to Apps > All apps > Add, choose Line-of-business app, and upload the .msix file. Intune reads the name, publisher and version from the package.
  3. Set App install context to Device for a machine-wide install.
  4. Assign it as Required to the target device groups.

Make sure the Windows App Runtime dependency is present on offline devices. To publish a newer version through Intune yourself, upload the new MSIX to the same app; Intune uses the version number in the package to detect the update.

Step 5: Decide how Windows App updates

Windows App reads a registry value that controls update behavior:

Value of DisableAutomaticUpdatesBehavior
0Updates enabled (default)
1Updates disabled from all locations
2Updates disabled from the Microsoft Store
3Updates disabled from the CDN

The value lives under HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\WindowsApp as a REG_DWORD. Values 2 and 3 only stop Windows App from looking for updates itself; if Windows App came from the Store, the Store still pushes updates as usual. You can't disable automatic updates for a Store-installed Windows App; it follows the Store update settings. To set the value, close Windows App and run this as an administrator, or deliver the same value with Intune:

$path = "HKLM:\SOFTWARE\Microsoft\WindowsApp"
If (!(Test-Path $path)) {
    New-Item -Path $path -Force
}
New-ItemProperty -Path $path -Name DisableAutomaticUpdates -PropertyType DWORD -Value 1 -Force

No restart is needed; the next launch uses the new behavior. To lock the update ring, set AdminReleaseRing in the same key to 0 for Public or 3 for Insider, which also hides the Insider toggle from users.

Microsoft doesn't recommend disabling Windows App updates. If you do, your organization takes on responsibility for patching, because updates carry security fixes, and Microsoft may block outdated clients from connecting.

Step 6: Remove the Remote Desktop client

  • Deployed through Intune or another tool: users may not have rights to uninstall it. Microsoft recommends using the uninstall function of the Win32 app type: on the existing Remote Desktop client app in Intune, move the target groups from Required to Uninstall.
  • Installed by users: they can right-click the Remote Desktop client and select Uninstall.
  • Complex estates: Microsoft publishes a Remote Desktop client migration script in its Windows365-PSScripts GitHub repository that you can use as is or adapt.

Sequence it after Windows App is confirmed installed on each device, so nobody is left without a client.

Step 7: Tell users what changes and verify

On a managed device, users who are signed in to Windows with a work or school account are signed in to Windows App automatically. After sign-in, the Devices and Apps tabs show their Cloud PCs, AVD desktops and RemoteApps; tabs are hidden when a user has no resources of that type. Users can pin favorites, and Windows 365 users can also add Cloud PCs to Task view in Windows 11.

To verify:

  1. In Intune, open the Windows App entry and check Device install status and User install status.
  2. Rerun the WVDConnections query and the Windows 365 Graph report until no recent sign-ins come from the legacy client.
  3. Recheck the AVD Insights Clients tab for outdated Windows App versions, especially if you disabled automatic updates.

Troubleshooting

The application was not detected after installation completed successfully (0x87D1041C). This appears when a Store app with System install behavior is assigned to a device that already has the app installed. Microsoft notes the app still installs correctly.

Requirements Not Met in Company Portal. A User context Store app was made available to a Microsoft Entra registered device. Use System install behavior for those devices.

The Store app never installs. Check that the device can reach the Microsoft Store and its content locations, that the Intune Management Extension is running, and that the device has at least two processor cores.

MSIX error 0x80073CF3. A newer version is already installed on the device, which can happen once Windows App has updated itself. Upload a higher version or remove the conflicting package.

MSIX error 0x80073CF0. The package couldn't be opened, usually because of an incomplete upload. Upload the file again.

Windows App shows no devices or apps. The user has no AVD or Windows 365 assignment, or is signed in with a different account. Check assignments and the account shown in Windows App.

Users can't connect to on-premises RDS hosts. Windows App on Windows doesn't support Remote Desktop Services; keep those users on the Remote Desktop app for those connections.

Windows App can't connect from a restricted network. Allow the end-user device endpoints in Microsoft's AVD required FQDN list. If your Cloud PCs are on your own network and fail provisioning instead, see Windows 365 Azure network connection health check failures.

If you are still deciding where users' desktops should run, Windows 365 vs Azure Virtual Desktop compares licensing, cost and management.

Migration checklist

  • Remaining Remote Desktop client users identified for AVD and Windows 365.
  • RDS-only users scoped out and handled separately.
  • Windows App deployed as a Microsoft Store app (new) or MSIX line-of-business app, with Arm64 devices tested.
  • Store auto-update policy left enabled, and Store access restricted with Turn off the Store application if needed.
  • Update behavior decided, with registry values deployed only if you accept the patching responsibility.
  • Remote Desktop client uninstalled through Intune after Windows App is confirmed.
  • Client usage rechecked until the legacy client disappears.

References

Questions people ask

When did the Remote Desktop client for Windows reach end of support?

The Remote Desktop client for Windows (MSI) stopped being supported for public cloud customers on March 27, 2026. Support for Azure Government, Azure operated by 21Vianet and AVD classic was extended until September 28, 2026. The Remote Desktop app from the Microsoft Store reached end of support in September 2025.

Does the Remote Desktop client upgrade itself to Windows App?

Not on Windows. You must install Windows App and uninstall the Remote Desktop client; both can run side by side while users learn the new app. On macOS, iOS, iPadOS and Android the Remote Desktop app updates to Windows App automatically.

How do I deploy Windows App with Intune?

Add it as a Microsoft Store app (new) by searching the Store for Windows App (Store ID 9N1F85V9T8BN) and assign it as Required to device or user groups. If you can't use the Store, deploy the standalone MSIX package as a line-of-business app instead.

Can Windows App connect to on-premises Remote Desktop Services?

Not on Windows yet. Microsoft's Windows App documentation states it doesn't support connecting to Remote Desktop Services and directs users to keep using the Remote Desktop app for that. Plan for those users separately from your Azure Virtual Desktop and Windows 365 migration.

Windows AppAzure Virtual DesktopWindows 365Microsoft Intune
  1. Windows 365 vs Azure Virtual Desktop: licensing, cost and management

    Compare Windows 365 Cloud PCs and Azure Virtual Desktop on licensing, cost model, management, networking and user experience, and pick the right platform for each group of users.

  2. Autopilot device preparation vs classic Autopilot: choosing the right one

    Compare Windows Autopilot device preparation and classic Windows Autopilot on join types, modes, app limits, registration, ESP and reporting, and pick the right one for each device population.

  3. AVD pooled host pool with FSLogix profiles on Azure Files (Entra Kerberos)

    Build an Azure Virtual Desktop pooled host pool with Microsoft Entra joined session hosts and FSLogix profile containers stored on Azure Files, using Microsoft Entra Kerberos instead of domain controllers.