Mycelium 365
    Back to Case Studies

    Case study

    How an Australian Manufacturer Replaced Legacy VPN with Azure Virtual Desktop

    Manufacturing and logistics
    120-person multi-site Australian manufacturer

    A multi-site Australian manufacturer with engineers, planners and field staff was struggling with an ageing VPN, ageing desktops and slow remote access to its line-of-business ERP. Mycelium 365 designed and deployed Azure Virtual Desktop with Entra ID-based access, Defender protection and a managed image — letting the business shift to a thin-client and BYOD model while reducing hardware refresh costs.

    The challenge

    The manufacturer was running a mix of ageing desktops at head office and unmanaged laptops at regional sites, all connecting back through a legacy VPN appliance that had become a daily support burden. ERP performance suffered over the VPN, and contractors waited days for hardware before they could become productive.

    Leadership wanted to flatten the hardware refresh bill, support genuine BYOD for office staff and contractors, and ensure intellectual property — drawings, formulations and customer data — never sat unencrypted on personal devices.

    The approach

    Mycelium 365 ran a workload assessment across ERP, CAD-adjacent tools and general productivity, then designed an Azure Virtual Desktop environment sized for predictable concurrency with auto-scaling for peak shifts.

    We built a managed AVD image with the ERP client, Microsoft 365 Apps and security baselines pre-installed, paired with FSLogix profile containers in Azure Files so users get a consistent experience on any session host.

    Access was moved off the legacy VPN onto Microsoft Entra ID with conditional access — requiring compliant devices for administrators and phishing-resistant MFA for all users. Microsoft Defender for Endpoint was extended across the AVD estate.

    A managed change programme paired with floor-level training helped operators, planners and contractors adopt the new desktop model with minimal disruption to production schedules.

    The outcome

    The legacy VPN was decommissioned within the first quarter of cutover, removing a recurring source of after-hours incidents. ERP response times for regional users improved noticeably because compute now runs next to data in Azure rather than tunnelling over consumer-grade links.

    The manufacturer avoided a full desktop refresh cycle, reusing existing hardware as thin clients and onboarding contractors on their own devices within hours rather than days. IP and customer data now stay inside the AVD session, never written to personal devices.

    Operationally, Mycelium 365 manages image updates, scaling rules and security posture under a fixed monthly service, giving the business a predictable run-rate and a clear path to retiring more on-premises infrastructure over time.

    Technologies used

    • Azure Virtual Desktop (multi-session)
    • FSLogix profile containers on Azure Files
    • Microsoft Entra ID with conditional access
    • Microsoft Defender for Endpoint
    • Microsoft Intune (BYOD enrolment)
    • Azure monitoring and cost management

    Need a similar outcome?

    Book a Discovery Call with Mycelium 365 to discuss your environment, security priorities, and the practical next step.

    Most businesses we talk to are surprised by how much they're overpaying — and how exposed they actually are.

    Book a Discovery Call with Mycelium 365 to discuss your Microsoft 365, Azure, security, cloud, support, or advisory needs.

    We respond to every enquiry within 4 business hours. Monday to Friday, 7am–7pm AEST.