Global Pools Overview

Global Pools allow administrators to group multiple Azure Virtual Desktop host pools under shared assignment and failover policies, so users are automatically assigned to the right host pool instead of being managed one host pool at a time.

Note

This feature is in Public Preview.

Global Pools is under active development, with additional capabilities and improvements planned in upcoming releases. 

Key capabilities: 

  • Centralized, policy-driven user assignment based on Entra ID group membership and configurable priority if there is a duplicate member in the Entra ID groups

  • Pool Groups that combine one or more host pools under a shared distribution mode

  • Automatic sync every 15 minutes (plus an on-demand manual sync) that adds and removes users from host pool assignment groups to match policy

  • Distribution across host pools within a Pool Group, with automatic rebalancing

  • Percentage-based auto-scale sizing, in addition to standard count-based sizing

  • Failover policies that redirect users from one Pool Group to another

  • Support for multi-session desktop and RemoteApp experiences across multiple identity tenants

  • A single RemoteApp catalog is defined once per Global Pool and is automatically available to every Pool Group -- including host pools added later -- so you can build out your RemoteApp catalog as a placeholder before creating any host pools.

Target users: 

AVD/Nerdio Manager administrators managing large-scale or multi-region Azure Virtual Desktop environments who need centralized, policy-based user assignment instead of configuring assignments on individual host pools.

Typical scenarios: 

  • Large enterprise AVD deployments with many host pools, where manual per-host-pool assignment doesn't scale

  • Staggered desktop image rollouts -- gradually moving users from a production Pool Group to a Pool Group running a newer image

  • Failover between Pool Groups to redirect users during planned maintenance or an outage

  • Organizations using multiple identity tenants that need a single, unified assignment approach

Availability

The feature is available in the following plans:

AVD Core 

AVD Premium 

Limitations and known issues

Issue/limitation

Impact

Mitigation/planned fix

Single-session desktops aren't supported yet

Global Pools can only be used for multi-session desktop experiences

Use multi-session desktop experiences for Global Pools in Public Preview.

Only one host pool can be created at a time within a Pool Group

Building out multiple host pools in a Pool Group requires repeating the process manually

Create host pools individually within each Pool Group.

Assignment policies currently support Entra ID group matching only

Percentage-based or Entra ID attribute-based assignment isn't available yet

Use Entra ID group membership and policy priority to control assignment behavior.

No public API for Global Pools or policies

Global Pools can't be configured or managed via API or automation yet

Use the Nerdio Manager UI to configure and manage Global Pools.

Limited in-UI guardrails and validation

Configuration issues (e.g., overlapping failover group membership) aren't proactively flagged in the UI

Review policy and failover configuration carefully before activating them.

Not all host pool profiles are supported yet

Only core profiles (e.g., Active Directory, VM, RDP/FSLogix) are available for Global Pool host pools in Public Preview

Nerdio is working toward full feature parity with regular host pools; additional profiles are planned.

Configuration and management

Role-based access control (RBAC) and permissions

Nerdio Manager roles

The following Nerdio Manager roles allow you to manage Global Pools:

  • Nerdio Admin role is required to manage Global Pools.

Required Azure and Microsoft Graph permissions

User action in the NME UI

Required Azure / Microsoft Graph permissions

Open the Global Pools page 

  • Microsoft.DesktopVirtualization/hostPools/read 

  • Microsoft.DesktopVirtualization/applicationGroups/read 

  • Microsoft.DesktopVirtualization/workspaces/read 

Create a Global Pool using an existing Entra ID group 

Microsoft Graph application permission Group.Read.All 

Edit Global Pool settings 

No direct Azure write permission. Some selected profiles may require read access to referenced Azure resources during validation.

Delete an empty Global Pool 

No direct Azure or Microsoft Graph permission. Host pools must be deleted separately first.

Create, edit, or delete a Pool Group 

No direct Azure or Microsoft Graph permission

Create, edit, activate, deactivate, or delete an Assignment Policy 

Microsoft Graph Group.Read.All when selecting or validating attribute-distribution groups. The policy operation itself only updates the NME database. 

Create, edit, activate, deactivate, or delete a Failover Policy 

No direct Azure or Microsoft Graph permission. Changes are applied to users during the next synchronization.

Preview generated host pool names 

  • Microsoft.Resources/subscriptions/resourceGroups/read 

  • Microsoft.DesktopVirtualization/hostPools/read 

  • Microsoft.DesktopVirtualization/applicationGroups/read 

Create Host Pools with an existing Entra ID group 

  • Microsoft Graph Group.Read.All 

  • Microsoft.Resources/subscriptions/resourceGroups/read 

  • Microsoft.DesktopVirtualization/workspaces/read 

  • Microsoft.DesktopVirtualization/hostPools/read and /write 

  • Microsoft.DesktopVirtualization/applicationGroups/read and /write 

  • Microsoft.DesktopVirtualization/applicationGroups/desktops/read and /write 

  • Microsoft.DesktopVirtualization/workspaces/write 

  • Microsoft.Authorization/roleDefinitions/read 

  • Microsoft.Authorization/roleAssignments/read and /write 

Create Host Pools and automatically create Entra ID groups 

  • All permissions from Create Host Pools with an existing Entra ID group 

  • Microsoft Graph Group.ReadWrite.All 

Delete a Host Pool, keeping its Entra ID group 

  • Microsoft.DesktopVirtualization/hostPools/read and /delete 

  • Microsoft.DesktopVirtualization/hostPools/sessionHosts/read 

  • Microsoft.Compute/virtualMachines/read 

  • Microsoft.DesktopVirtualization/applicationGroups/read and /delete 

  • Microsoft.DesktopVirtualization/workspaces/read and /write 

  • Microsoft.DesktopVirtualization/hostPools/msixPackages/read and /delete 

Delete a Host Pool and its Entra ID group 

  • All permissions from Delete a Host Pool, keeping its Entra ID group 

  • Microsoft Graph Group.ReadWrite.All 

Add, edit, or delete a RemoteApp in the Global Pool configuration 

No immediate Azure permission. The change is stored in NME and applied to Azure by Sync Global Pool

Run Sync Global Pool for a desktop or personal pool 

  • Microsoft Graph Group.Read.All 

  • Microsoft Graph GroupMember.Read.All 

  • Microsoft Graph GroupMember.ReadWrite.All 

  • Microsoft.DesktopVirtualization/applicationGroups/read 

  • Microsoft.Authorization/roleDefinitions/read 

  • Microsoft.Authorization/roleAssignments/read 

Run Sync Global Pool for a RemoteApp pool 

  • All permissions from desktop/personal pool synchronization

  • Microsoft.DesktopVirtualization/applicationGroups/applications/read 

  • Microsoft.DesktopVirtualization/applicationGroups/applications/write 

  • Microsoft.DesktopVirtualization/applicationGroups/applications/delete 

Save Auto-scale settings 

Read access to the configured resource group, network, image, storage, encryption, capacity, and other resources referenced by the VM deployment profile

Select Force Start Auto-scale 

Azure Compute, Network, Storage, and related write permissions required by the configured VM deployment and auto-scale profiles

Enable Azure Capacity Extender 

Read and write access to the VM sizes, regions, subscriptions, and resources referenced by the selected Capacity Extender profile

Note

When NME creates an Application Group, it attempts to grant its application User Access Administrator on that Application Group. If the NME application does not already have Owner or User Access Administrator, the interactive Azure user context must have Microsoft.Authorization/roleAssignments/write.

Group.ReadWrite.All is only needed when NME creates or deletes Entra ID groups. GroupMember.ReadWrite.All is required for Global Pool synchronization because NME reassigns users between host pool groups.

Troubleshooting

  • Global Pool sync doesn't move users: Check Pool Group existence, active policy type/items, user eligibility (must be in both the Global Pool Entra ID group and a matching policy group), assignment group capacity, and whether a failover policy or priority order is redirecting the user elsewhere.

  • Global Pool sync fails: Check Tasks for details, confirm Nerdio Manager can read/write the relevant Entra ID groups, confirm the host pool has application groups, and confirm the assignment group has the Desktop Virtualization User role assigned.

  • Users assigned to an unexpected Pool Group: Check the active policy and priority order, overlapping Entra ID group membership, active failover policies, distribution mode, and assignment capacity.

Deployment considerations

Required resources

Global Pools requires additional resources to be deployed to your Azure tenant.

Additional resources

The table below specifies supplementary resources used by Global Pools, including the following information for each resource:

  • Whether the resource is required or optional

  • Whether the resource is deployed automatically when the feature is enabled or requires manual configuration

  • Any additional costs or subscriptions associated with the resource, and the billing method for these costs.

Resource name

Required?

Deployment

Costs and billing

Entra ID security groups (pool-level eligibility group and per-host-pool assignment groups)

Auto or manual

No direct cost beyond your existing Entra ID licensing tier

Azure Virtual Desktop workspace, host pool, and application group (per host pool in a Pool Group)

Manual

Standard Azure Virtual Desktop/compute costs apply, same as a standalone host pool

Scaling considerations

Considerations: 

  • Global Pools support percentage-based autoscale sizing (minimum active host capacity % and burst-beyond-capacity %) as an alternative to fixed host counts -- useful when capacity needs to scale with the overall size of the pool rather than a fixed number of hosts.

  • Assignment sync runs automatically every 15 minutes; for large user populations or many policy changes, allow a full sync cycle before validating results, or trigger the manual sync button to sync on demand.

  • Rebalancing requires more than one host pool assignment in a Pool Group, and honors the Pool Group's Distribution Mode (Depth-first or Breadth-first).

Recommendations: 

  • Pre-stage failover target Pool Groups (host pools and autoscale) ahead of time.

  • Since RemoteApps and the desktop image are shared across an entire Global Pool (not per Pool Group), plan separate Global Pools for use cases that need different app sets or desktop experiences.

Was this article helpful?

0 out of 0 found this helpful
Have more questions? Submit a request

Comments (0 comments)

Please sign in to leave a comment.