Azure Virtual Desktop supports external identities, but “external user” has two different meanings. A contractor working for your company and a customer using an application you sell are different licensing cases. Before inviting a B2B guest, separate the technical sign-in method, commercial purpose, licence in the resource tenant and Azure running costs.

Older search results still say AVD does not support B2B guests. A 2022 Microsoft Q&A answer says exactly that. Current AVD documentation describes external identities and their technical requirements. Both sources are from Microsoft, but their dates and scenarios differ.

An accepted invitation does not guarantee that the guest can see an AVD resource. In a recent Microsoft Q&A case, the guest sees both organisations but not the desktop. The answer suggests checking external-identity requirements, cross-tenant access and the organisation selected in Windows App; the questioner did not confirm a fix. Similar reports appear on Reddit. Use the checks below to distinguish causes, not as a promise that one setting fixes every case.

Keep identity and commercial purpose separate

External identity describes how someone signs in, for example with an account from their home Entra tenant represented by a B2B guest object in yours. External commercial purpose describes the business use: providing a desktop or app to customers as a service. A contractor may be a technical B2B guest while still doing internal work for your company.

Microsoft’s licensing guide gives the example of an outside contractor working for an organisation: that person needs eligible rights for internal AVD use. A Guest account does not make the contractor a customer eligible for per-user access pricing. That measured model is for an external commercial purpose, such as selling access to your application to customers.

Examples of internal and external commercial use of AVD
ScenarioTechnical identityAVD right typeA common mistake
Employee uses an internal desktopAccount in the company tenantEligible user licence for internal useAzure VM costs already cover user rights
Contractor works in an internal accounting appMay be a B2B guestEligible internal-use licence assigned in the AVD tenantA Guest account counts as an external customer
Customer uses an app you sell as a serviceExternal identity as designed for the servicePer-user access pricing for external commercial useA licence in the customer tenant is sufficient
Worker has a licence in another tenant of the groupB2B or another multi-tenant setupAVD entitlement is assessed in the target tenantRights automatically travel with the identity

The table simplifies the decision about access right to AVD. It does not automatically cover Office, Intune, Defender, or other desktop software. For more complex contracts and atypical service delivery, check the current Microsoft Product Terms and licensing partner for exact terms.

Technical requirements for B2B access

Microsoft’s current AVD guidance sets several technical conditions. The session host must be Microsoft Entra joined, the host pool must use single sign-on, and the operating system must be supported. The guidance specifies Windows 11 Enterprise 24H2 or later with updates from September 2025, or Windows Server 2025 with updates from January 2026. Check identity provider and Windows App limitations too. An older hybrid configuration is not supported merely because employees can use it.

The guest also needs access assignments. Microsoft’s procedure assigns a group containing guests to the application group. For a standard host pool, it also assigns the Azure Virtual Machine User Login role on session hosts; the documentation notes an exception for session host configuration. Check each layer separately: invitation, cross-tenant access, group, application group, VM sign-in and the target organisation in Windows App.

There are also restrictions after a successful connection. Microsoft states that an external identity cannot authenticate to local resources using Kerberos or NTLM. If the desktop relies on an old internal application with these protocols, verify its behavior before the pilot. Access to the desktop itself is not proof that all applications will run inside.

Where should the guest licence be assigned?

The right to AVD is not transferred by the B2B invitation. Microsoft recommends that external collaborators assign the appropriate license to their object in the tenant that AVD provides. A license in the vendor's home tenant typically does not grant rights to AVD or other products in the target tenant. The same generally applies to multiple tenants of a single organization; the documentation lists a specific exception for Entra ID P1, but it cannot be automatically applied to AVD.

For Windows 10/11 session guests for internal use, Microsoft lists as eligible, for example, Microsoft 365 Business Premium, E3, E5 and F3, as well as selected Windows Enterprise or Windows VDA licenses. For Windows Server session guests, the list is different: for example, RDS CALs with Software Assurance or RDS User Subscription Licenses. Do not purchase rights based solely on the trade name "AVD"; first determine the guest operating system, the purpose of use, and the specific account of the person connecting.

If the remote desktop uses Microsoft 365 Apps, Teams or other products, assess their rights separately. AVD Licensing Guide specifically notes that per-user access pricing for external commercial purposes does not automatically add a license to Office, Defender, or other services. Similarly, a vendor's license for Office in their home tenant may not cover every feature you want to run in your tenant.

Per-user access pricing is not a guest discount

Per-user access pricing can look like a convenient way to connect any B2B guest and pay only for active months. Microsoft defines it differently: a contractor doing work for your organisation needs internal-use rights. The metered model applies when you provide AVD to customers for an external commercial purpose. For those customers, a user who connects at least once in a month is counted for that month.

Before deciding, write one sentence: "This person is joining to do work for our organization" or "This person is using the service we are selling to them as a customer". If the sentence cannot be filled in clearly, clarify the business relationship first. The technical presence of a Guest account is not the answer to the licensing purpose.

Budget for more than user licences

Even the right user license does not mean that running AVD is without additional costs. Microsoft Cost Guide separates licenses from Azure consumption: guest session computing power, disks, profiled storage, network traffic, logging, and any support services. In the per-user access pricing model, a metered fee is added for external commercial access; infrastructure is billed further.

For a cost estimate, model the number of connecting people, concurrent sessions, session-host operating hours, profile storage and outbound traffic. Do not promise savings against Windows 365 without those figures. Windows 365 Business uses a different licensing and operating model; its comparison with Enterprise does not determine the right AVD host pool for your application.

When a guest cannot see the desktop

Remote contractor working at a desktop monitor

Troubleshoot from identity through to the working session:

  1. Verify purpose and entitlement. Is this internal work for your company or an external commercial service? Is the required licence assigned in the AVD tenant?
  2. Check the invitation and cross-tenant access. Confirm the guest was invited, collaboration is allowed and Conditional Access permits the sign-in.
  3. Confirm technical prerequisites. Check Entra-joined session hosts, supported OS and updates, and host-pool SSO.
  4. Check assignments. Assign the guest group to the application group and the relevant VM login role for the host-pool configuration.
  5. Select the right organisation in Windows App. The guest signs in with home credentials, but the AVD resources live in your tenant. Compare with the supported web client to isolate client-context problems.
  6. Then test the app inside the desktop. Assess Office rights and any legacy authentication or internal-system access separately.

At the end of the pilot, the guest must actually open the intended desktop or RemoteApp and the specific work application. Merely displaying the guest object in Entra is not a test of a functional AVD.

Frequently asked questions

Does AVD support B2B guests now?

Yes, if the current Microsoft requirements are met: supported session hosts, Entra join, SSO and the correct access assignments. Older answers saying B2B is unsupported predate this capability.

Is the contractor’s own Microsoft 365 Business Premium enough?

Do not assume so. Microsoft generally recommends assigning eligible rights to the guest object in the tenant that provides AVD. Rights in the home tenant usually do not transfer.

Is every B2B guest an external user for per-user access pricing?

No. A contractor working for your company is an internal-use case. Per-user access pricing applies when you provide AVD to customers for an external commercial purpose.

Does the AVD right also cover Word and Excel?

Not automatically. Assess AVD access and the rights for each application in the desktop separately.

Why can the guest see our organisation but not RemoteApp?

An accepted invitation is only one step. Check cross-tenant settings, Conditional Access, the host pool, application group, VM login rights and organisation context in Windows App. Sign-in logs are needed to identify the exact cause.

Decide before sending the invitation

Before adding a contractor to a group, record commercial purpose, identity type, the tenant hosting AVD, session-host operating system, required user rights, other applications and expected Azure costs. A working Guest account does not, by itself, verify licensing or operating costs.