And Azure Virtual Desktop =link= - Securing Cloud Pcs

“The problem,” she said, pointing, “is session host sprawl . We have 2,000 Cloud PCs. Each one is a fresh Windows installation. But the connection —the RD Gateway, the Broker—that’s the choke point. Midnight Proxy isn’t attacking the OS. They’re attacking the control plane .”

The forensics team traced the ghost sessions back to a compromised managed identity. Someone had phished a helpdesk admin, stole a service principal’s secret, and used it to register a malicious device to the company’s Entra ID. securing cloud pcs and azure virtual desktop

The CISO read the log. “What’s the lesson for the board?” “The problem,” she said, pointing, “is session host