Nerdio Manager for Enterprise 8.1 reached General Availability today, and I want to walk you through what actually changed — feature by feature, in plain language.
Here is the short version of the timeline. Version 8.1.0 arrived as a Public Preview on July 21, 2026. Today, August 4, 8.1.1 went GA. If you have been holding off on the upgrade while the preview settled, that wait is over.
Who this is for: AVD and Windows 365 admins, Intune admins, and anyone responsible for a Windows Cloud estate that has grown past the point where clicking through the Azure portal is a reasonable plan. It is also for those looking to optimize costs. Duh.
What this covers: the new features and enhancements in 8.1. That is the whole focus — new capability, not the fix list.
What this does not cover: resolved issues, known limitations, and upgrade mechanics. Those live in Nerdio’s own release notes, and I link them at the end.
Let’s get into it.
Global Pools: The One Everybody Will Talk About
If you only read one section, read this one. Global Pools is the headline feature of 8.1, and it is aimed squarely at the largest AVD deployments — the ones where a single host pool stopped being enough a long time ago.
The idea is straightforward. Instead of managing dozens of host pools as dozens of independent islands, you group them into Pool Groups under a Global Pool, and then you manage distribution, failover, and assignment at that higher level. Here is what ships in this first release:
- Create host pools as part of a Global Pool. New pools can be born into the structure rather than retrofitted. Note that this initial release supports multi-session desktop and RemoteApp experiences — personal pools are not in scope yet.
- Group host pools into Pool Groups. This is the organizing unit that everything else hangs off of.
- Auto-scale and Scripted Actions still work. Host pools inside a Global Pool keep their auto-scale configuration and their scripted actions, so you are not trading away automation to gain structure.
- Assignment Policies driven by Entra group membership. You define the rule once, and Nerdio Manager assigns — or re-assigns — users to the right Pool Group automatically. For anyone who has maintained user-to-pool mappings by hand, this is the part worth getting excited about.
- Failover Policies with a manual trigger. When a Pool Group is in trouble, you reassign its users to a different Pool Group. The trigger is manual in this release, which I actually think is the right call for a first version — you want a human in the loop the first few times you exercise a failover path.
- A User Assignment page. Look up a user and see exactly which host pool and which Pool Group they landed in. Simple, and enormously useful during a support call.
NOTE: Global Pools is a Premium-only feature and it is in Preview with this release. Treat it the way you would treat any preview capability touching user assignment — validate it in a non-production workspace, and get comfortable with the failover path before you need it at 9:00 on a Monday morning.
Why does this matter? Scale changes the nature of the problem. At ten host pools, consistency is a discipline. At a hundred, consistency has to be a structure. Global Pools is Nerdio’s answer to that shift.
Windows 365 Gets a Genuinely Big Release
Windows 365 may be the busiest area in 8.1, and some of it is Microsoft’s naming catching up with reality.
Frontline is now Flex
Windows 365 Frontline has been renamed to Windows 365 Flex, following Microsoft’s rename of both the license and the product. Nothing functional changed — but your documentation, your runbooks, and your internal wiki all just went slightly stale. Worth an hour of cleanup.
Migration paths keep opening up
Two separate items here, and they are at different maturity levels:
- AVD Personal to Windows 365 Enterprise migration is now GA. This one graduated. Single and bulk migration, production-ready.
- AVD Personal to Windows 365 Flex Dedicated migration is in Public Preview. The migration wizard now offers Flex Dedicated as a destination alongside Windows 365 Enterprise, with both single and bulk support.
If you have a fleet of personal AVD hosts that were really always Cloud PC workloads in disguise, the road out is considerably better paved than it was a year ago.
AI-enabled Cloud PCs, managed from one place
This is the item I did not expect. Admins can now create and manage Cloud PC configurations directly under Windows 365 > Settings, including enabling AI-enabled features for targeted user groups. Nerdio Manager surfaces Microsoft’s requirements inline and validates Frontier enrollment, which spares you a round trip to the documentation to find out why a toggle refuses to stick.
Paired with that, the All Devices grid gained an AI Status column for Windows 365 Cloud PCs. Three states — Enabled, Disabled, and N/A — filterable and sortable. That last part is what makes it operationally useful: you can answer “where are AI features actually applied, and where are they blocked?” across the whole estate without exporting anything.
User Experience Sync, finally in the console
User Experience Sync (UES) management comes to Nerdio Manager in 8.1. You can enable or disable sync, select the storage size, review which users and devices a provisioning policy actually covers, and delete profiles — all without leaving the console.
A settings surface that will make more sense later
The Windows 365 User Settings tab has been renamed to Settings and restructured to align with Microsoft’s Cloud PC settings taxonomy. Creating a new object now starts with a Settings Type selector. On its own that is a modest change; the interesting part is what it signals, because that selector exists to make room for additional setting types in future releases.
Storage and Profiles: The FSLogix View We Have Been Asking For
Two items here, and one of them quietly solves a problem that has burned a lot of admins.
Azure Files > User Profiles tab is a new dedicated page that lists details for all FSLogix user profiles. Assigned user, file name, file share, last logon time, size, quota, usage, and health — in one grid. It also handles the messy real-world case where a single user has multiple profiles scattered across different file shares.
Think about the last time you chased a profile problem. You probably knew the user, and you probably did not know which share their profile actually lived on. That is the gap this page closes.
Azure Files v2 support also arrives: Nerdio Manager can now create Azure Files v2 storage accounts. One caveat to plan around — auto-scale support for v2 is coming in a future release, so if auto-scaling your file storage is part of the design, v1 remains the safer choice for now.
Auto-scale Gets More Precise
Auto-scale is Nerdio’s signature capability, so incremental improvements here tend to pay off quickly.
- Percentage-based host pool sizing. When configuring host pool sizing, you can now express the sizing as percentages in addition to absolute counts. For pools whose baseline shifts over time, a percentage is often the more durable way to describe intent.
- Auto-revert for the Azure Capacity Extender. When the Extender resizes a stopped session host to an alternative SKU because your preferred SKU was unavailable, that host can now revert automatically to the host pool’s default VM size during auto-scaling. Configuration drift closes itself. The option is off by default, so you will want to turn it on deliberately.
- Auto-scale Analytics for Azure Local. Analytics now covers Azure Local host pools and can make recommendations around provisioning loads.
AVD Hybrid for Nutanix Keeps Filling In
The Nutanix AHV story has been building steadily since 8.0, and 8.1 closes three more gaps in the Preview:
- Console Connect support. Out-of-band access to Nutanix-hosted session hosts. When a host loses network, this is the difference between a fix and a rebuild.
- Auto-scale support. The Nutanix hosts join the auto-scale story.
- Session Time Limits as a host pool profile. Configure them once as a profile rather than per host pool.
For anyone running a genuinely hybrid estate, the pattern to notice is that Nutanix support is converging on feature parity rather than staying a special case.
Intune: Policy Studio Goes Deeper, Change Approvals Grows Up
Policy Studio (Preview)
Two additions, both about seeing further into a policy:
- Nested policy settings are now editable. For supported policy types, you can edit nested setting values directly from the Settings Explorer tab.
- Nested values in Policy Results. The Policy Results page can now display nested values, which is where conflict investigations usually stall.
Change Approvals (Preview)
This is the area that changed the most, and it reads like a feature that has been through a real pilot:
- Scheduled approvals. A requestor can set the execution time when they create the request, rather than waiting for approval and then scheduling. Approvers see the intended time before they act, and either side can reject or cancel before it fires. One exception: this is not supported for Intune User Operating Mode.
- Lifecycle management. Pending requests auto-cancel after a configurable inactivity period, so the queue stops accumulating ghosts. If you disable approvals entirely, pending requests convert to Cancelled and the history is retained for a minimum of three years.
- A new Failed status. Requests get marked Failed when real-time execution did not succeed, or when a scheduled request exhausted three retry attempts. There is a visual indicator, plus options to Execute now, Schedule, Cancel, or Reject.
- Auto-cancel on feature disable. Pending and approved requests cancel automatically when Intune integration, Policy Approvals, or User Mode settings conflict with their execution.
Two quieter Intune wins
- Enhanced Intune logging. Intune-related actions now appear as a separate task within job details, which makes post-mortems much less of a hunt.
- Configurable Graph API retry limits. Large environments can raise the default Graph retry count using separate app service settings for web (
Feature:HttpOption:MaxRetries:Graph:Web, up to 5) and background (Feature:HttpOption:MaxRetries:Graph:Background, up to 6) services. If throttling has been your ceiling at scale, this is your dial.
Observability and AI
Real-Time Insights
- AVD host overview. A new host-level view covering CPU, memory, session state, session load, and session input delay. During an investigation, “which host is actually hurting?” is usually the first question, and now there is a page that answers it.
- From / To date-time range pickers. Select an exact window down to the minute, alongside the existing relative time selector.
- Alert drill-down. Jump from an Alerts view straight into the relevant graph, already focused on the alert timeframe with the occurrence highlighted in severity-matched color.
- Intune scope validation at deployment. When you deploy the Real-Time Insights worker script, Nerdio Manager now checks that every selected endpoint is in Intune scope and warns you about the ones that are not — because those endpoints simply cannot be monitored.
Also worth noting: Intune Insights Update Ring reporting now applies an Update Ring’s deferral period before starting the update-age countdown. If you mark devices amber at 7 days and red at 14, that clock now starts when the deferral ends rather than penalizing devices for doing exactly what you told them to do.
Nerdio Manager Copilot
Copilot received the longest list of enhancements in the release:
- An internal virtual file system, letting the agent read, search, write, and validate data
- Chat context stored between sessions, with 30-day retention
- Visible action logging in the UI, so you can see what the agent actually did
- Multiple PowerShell scripts or KQL queries from a single prompt
- Previous chat session loading raised to 50 interactions
- A new OpenAI Responses API integration for better chat streaming, LLM reasoning, and iterative script refinement
- Conformance with Azure Data Loss Prevention standards for Foundry Tools
- Dynamic retrieval of model deployment types (Global Standard, Data Zone Standard, and so on) from the subscription during deployment, showing only what is actually available for your chosen model and region
That last item is a small mercy. Picking a deployment type your region does not offer is a mistake you only need to make once to appreciate its removal.
Search
Search has become one of the more quietly powerful parts of the product:
- A dedicated full-page results view. Press Enter in global search and you get a real results page instead of a dropdown — much better for browsing matches across users, sessions, apps, and policies.
- Custom Azure tag search. Search by tag name or tag value to find every matching resource in your deployment.
- Intune policy search directly from the global search bar.
- Approval request search, respecting permissions and working across every Intune tenant the user can access. Search by user and choose requests they created or reviewed; results open the Approval Requests page with the filter already applied.
Cost and Efficiency Insights
- User Cost Attribution now shows the Azure tags in use and in scope of the page’s calculations — helpful when the numbers surprise you and you need to know why.
- User Cost Attribution supports TLS 1.3.
- Operational Efficiency now recommends backing up Intune scripts.
Platform and Security
This section is less glamorous and possibly more important, especially if you have a security review in your future.
- Least-privilege Azure custom role support (Preview). Nerdio Manager can now run with a least-privilege custom Azure role instead of requiring Contributor. If Contributor has been the sticking point in your security review, this is the item to bring to the next meeting.
- Granular RBAC for secure variables. Secure variables get a dedicated RBAC module with three independent levels — Read Only, Manage, and Show Secret. You can let someone manage a secret without letting them read its plaintext value. Never hand out plaintext access more broadly than the job requires.
- Azure Key Vault RBAC authorization model. New deployments create key vaults using Azure’s RBAC permission model. Existing environments on the access-policy model keep working, with updated APIs maintaining support.
- Egress method indicator. Host pool and individual session host pages now display the outbound egress method in use — NAT Gateway, Azure Firewall, Default Outbound Access — with a warning indicator when a host or pool still relies on deprecated Default Outbound Access. Given Microsoft’s retirement plans, this is a report you should run soon.
- Console Connect Japan region support, for data residency requirements.
- Refreshed Updates page, with a cleaner layout and additional versions available for rollback.
- Offline install support for Terraform. A new optional
app_package_local_pathvariable in the NME Terraform installer lets you point at a local zip package. If your IaC environment is disconnected or restricted, this unblocks you. - New REST API endpoints: full CRUD for Scripted Action profiles, full CRUD for Scripted Action groups, a new endpoint to query a user’s entitlements and assignments, and
encryptionAtHostsupport on the Desktop Image creation endpoint.
Applications and Automations
Applications
- View native Intune application properties directly from the application dropdown in the UAM catalog.
- CSV export for deployment policy targets (pool, group, workspace), deployment policy applications, Shell Apps, and the Unified Catalog (repository, name, type, publisher, version, and favorite status).
- AD service account support restored for app deployment and desktop image application. This one is hidden by default and enabled with the
Features:UamServiceAccountsfeature flag — built for environments where domain policy forbids local admin or non-approved accounts.
Automations
- Concurrency balancer for Scripted Sequences (Preview). The Run Scripted Sequence dialog for AVD gained a concurrency balancer, letting you cap concurrent executions globally or per host pool. In a large environment, this is how you run a sequence broadly without creating your own incident.
- Task Worker deletion. Delete task workers straight from the Task Workers page. Nerdio Manager sends a deletion signal, the endpoint worker removes itself from the device, and it reports back to confirm. Deleted workers stay visible under Show Deleted, and they must be redeployed if you want them back.
Housekeeping You Should Not Skip
The new navigation menu is now on by default. The redesigned left nav that arrived as an opt-in toggle in 8.0 is now the default for everyone. New alongside it is a Favorites menu item — star the pages you use most from the All Features page and they collect there.
NOTE: The legacy menu will be retired with Nerdio Manager 8.2. If any of your internal documentation, training material, or screen recordings still show the old navigation, now is the moment to schedule that refresh rather than discover it later.
One removal: the Basic network features option is gone when creating or modifying Azure NetApp Files volumes, because Microsoft deprecated it effective July 2026.
And one deadline that is not an 8.1 item but deserves the reminder: Microsoft retires AVD Classic on September 30, 2026. Version 8.0 was the last release of Nerdio Manager to support AVD Classic tenants and host pools, and after that date AVD Classic stops functioning regardless of which version you run. If anything in your estate is still on Classic, the automated migration process inside Nerdio Manager is the path forward — and there is less runway left than there looks.
Where to Look First, Depending on Your Day Job
There is a lot in 8.1, so here is my honest triage.
| If you are… | Start with | Why |
|---|---|---|
| Running large-scale AVD | Global Pools (Premium, Preview) | Structural answer to multi-pool sprawl, with policy-driven assignment and failover |
| Managing Windows 365 | AI-enabled Cloud PC config, UES, the Flex rename | Real new capability, plus naming your docs need to catch up on |
| Chasing profile problems | Azure Files > User Profiles | Every FSLogix profile, its share, and its health in one grid |
| Living in Intune | Change Approvals, Policy Studio nesting | Scheduling, lifecycle, and visibility into nested settings |
| Answering to security | Least-privilege custom role, secure variable RBAC, Key Vault RBAC | Removes the Contributor conversation and tightens secret handling |
| Watching the network | Egress method indicator | Finds every host still on deprecated Default Outbound Access |
| Optimizing cost | Percentage-based sizing, Capacity Extender auto-revert | Auto-scale that holds its shape over time |
What This Release Tells Us
Read 8.1 as a whole and a pattern shows up. Global Pools is about managing structure instead of instances. The User Profiles tab, the AI Status column, the egress indicator, and the host-level Real-Time Insights view are all about seeing your estate rather than inferring it. The least-privilege role and the secure variable RBAC module are about running with less power than you used to need.
Structure, visibility, and least privilege. Those are the three threads, and they are exactly the threads that matter once an environment outgrows the ability of any one person to hold it in their head.
The tagline Nerdio put on this release is “Plan. Deploy. Optimize. Evolve.” I would argue 8.1 leans hardest on that last word. Evolving an estate you cannot fully see is guesswork — and 8.1 hands you a great deal more to see.
Go upgrade. Then go turn on the reports you have been guessing about.
Sources and further reading
- Nerdio Manager for Enterprise Release Notes — the authoritative list, including resolved issues and known limitations
- Nerdio Manager for Enterprise Help Center
Have you turned on Global Pools yet, or are you waiting for GA? I would like to hear how the failover path behaves in a real environment — leave a comment and let me know.