AZ-140 Sample Questions & Answers
Building out the Azure Virtual Desktop infrastructure itself takes the biggest share, alongside identity and security planning, user environments and apps, network capacity for session hosts, and RDP Shortpath configuration.
Launch the full AZ-140 simulator →Showing 10 of 20 free samples.
- Question 1Beginner
Plan and implement user environments and apps · Implement storage for FSLogix components
True or False: When using FSLogix Profile Containers stored on Azure Files, the storage account must be joined to an Active Directory Domain Services (AD DS) or Microsoft Entra Domain Services domain to enforce user-level permissions.
Show answer & explanation
Correct answer: B
False. Azure Files supports three identity sources for identity-based SMB access: on-premises AD DS, Microsoft Entra Domain Services and Microsoft Entra Kerberos. With Microsoft Entra Kerberos, Microsoft Entra ID issues the Kerberos tickets, the storage account isn't joined to an AD DS or Microsoft Entra Domain Services domain, and Microsoft Entra joined or hybrid joined clients don't need line of sight to domain controllers; Microsoft lists it as a fit for FSLogix profiles. With any identity source you still assign share-level permissions and configure directory and file (NTFS) permissions so users can access only their own profile containers. Using the storage account key isn't recommended for production.
- Question 2AdvancedSelect 2
Monitor and maintain an Azure Virtual Desktop infrastructure · Monitor Azure Virtual Desktop by using Azure Monitor
An administrator is investigating long session connection times reported by users. In Azure Virtual Desktop Insights, the administrator opens the Connection Performance tab and observes that the 95th percentile of "Time to connect" is consistently over 45 seconds. The breakdown shows that the longest delay occurs during the "Logon" stage. Which two factors are most likely contributing to this long logon duration? (Select TWO)
Show answer & explanation
Correct answers: A, C
In Azure Virtual Desktop Insights, time to connect is broken down into user route, stack connected, logon, and shell start to shell ready. The logon stage, from when the connection to the host is established to when the shell starts to load, includes loading the user profile, applying Group Policy objects, launching FSLogix (frxsvc) and starting the shell. Slow or under-scaled storage for FSLogix profile containers lengthens profile and FSLogix load time. Many or slow-to-apply GPOs lengthen Group Policy processing. Both directly extend the logon stage. Network latency between the client and the gateway affects the user route and stack connected stages instead.
In Azure Virtual Desktop Insights, time to connect is broken down into user route, stack connected, logon, and shell start to shell ready. The logon stage, from when the connection to the host is established to when the shell starts to load, includes loading the user profile, applying Group Policy objects, launching FSLogix (frxsvc) and starting the shell. Slow or under-scaled storage for FSLogix profile containers lengthens profile and FSLogix load time. Many or slow-to-apply GPOs lengthen Group Policy processing. Both directly extend the logon stage. Network latency between the client and the gateway affects the user route and stack connected stages instead.
- Question 3Intermediate
Plan and implement an Azure Virtual Desktop infrastructure · Create an image manually
A retail company is migrating its on-premises VDI environment to Azure Virtual Desktop. They have a custom golden image that is currently a 200 GB VHD file stored in an on-premises file server. The goal is to use this image to deploy session hosts in a new host pool. The administrator has already uploaded the VHD to an Azure Storage account. What is the next step required to make this VHD usable for deploying new session hosts from the Azure portal?
Show answer & explanation
Correct answer: D
To deploy Azure VMs from a custom VHD, the VHD must first be used to create a managed image resource in Azure. This managed image acts as a template. Once the managed image is created, it can be selected during the virtual machine creation process in the Azure portal to deploy new session hosts based on that specific image.
- Question 4Intermediate
Plan and implement user environments and apps · Implement the Start Virtual Machine on Connect feature
You are configuring a personal host pool for a group of developers. The organization has a policy that all Azure VMs must be powered off outside of business hours (9 AM to 6 PM, Monday-Friday) to reduce costs. However, developers occasionally need to work late or on weekends. You need to implement a solution that keeps the VMs deallocated by default but allows a developer to power on their assigned VM on-demand by simply attempting to connect to it. Which feature should you configure on the host pool?
Show answer & explanation
Correct answer: B
The 'Start VM on Connect' feature is designed specifically for this use case, primarily with personal host pools. It allows session host VMs to be deallocated to save costs. When a user assigned to a specific VM attempts to connect via their Remote Desktop client, the AVD service intercepts the request, sends a command to power on the VM, and then brokers the connection once the VM is ready. This provides on-demand access while maximizing cost savings.
- Question 5Intermediate
Plan and implement identity and security · Configure Azure Bastion or just-in-time (JIT) for administrative access to session hosts
A government agency is deploying Azure Virtual Desktop. Its security policy requires that RDP port 3389 on the session hosts stays closed by default. Administrators must request access through the Azure portal, access must be opened only to the requesting administrator's IP address for a limited time, and all access requests must be audited. Which Azure service should be implemented to meet all these requirements?
Show answer & explanation
Correct answer: D
Just-in-time (JIT) VM access, part of Microsoft Defender for Servers Plan 2 in Microsoft Defender for Cloud, keeps deny rules on the selected management ports (such as RDP 3389) in the network security group and Azure Firewall. When a user with the right Azure RBAC permissions requests access from the Azure portal (or programmatically) and the request is approved, Defender for Cloud allows inbound traffic to the port only from the requester's IP address or range for the specified time, then restores the rules. JIT activity can be audited from the VM's Activity Log. Azure Bastion gives portal-based RDP over TLS 443 without opening 3389, but it doesn't provide request-based, time-limited access.
- Question 6Beginner
Monitor and maintain an Azure Virtual Desktop infrastructure · Implement autoscaling in host pools
A consultant is reviewing an Azure Virtual Desktop deployment for cost optimization. They discover a pooled host pool with 20 session hosts that are running 24/7. The usage pattern shows that all users are active only between 8 AM and 7 PM on weekdays. The consultant recommends implementing an autoscaling plan. What is the primary benefit of implementing this plan?
Show answer & explanation
Correct answer: A
The primary driver for autoscaling in AVD is cost optimization. An autoscaling plan can be configured to start and deallocate session host VMs based on a schedule and/or session load. By deallocating VMs when they are not needed (e.g., overnight and on weekends), the organization stops paying for compute resources, leading to significant cost savings.
- Question 7Intermediate
Plan and implement user environments and apps · Implement FSLogix application masking
An organization uses FSLogix application masking to control access to specific applications on their multi-session hosts. An administrator needs to prevent users in the 'Interns' group (an Active Directory group synchronized to Microsoft Entra ID) from seeing or running
regedit.exe. The administrator creates a hiding rule in the FSLogix Rule Editor. In addition to specifying the executable path, which Rule Assignment setting must be configured to achieve this goal?Show answer & explanation
Correct answer: D
A hiding rule hides the specified items from the users or groups the rule set applies to. New rule sets automatically have the Everyone group assigned with Applies set to No, so nobody is affected until you add an assignment. To hide regedit.exe from the Interns, add the Interns group with Applies set to Yes; assignments are processed from top to bottom. Setting Does Not Apply for a group exempts it from the rule. Assignments need groups synchronized from Active Directory, and the session hosts need line of sight to a domain controller to resolve them; Microsoft Entra cloud-only groups aren't supported.
- Question 8Advanced
Plan and implement user environments and apps · Configure FSLogix Cloud Cache
Case Study: Contoso Pharmaceuticals
Company Background:
Contoso Pharmaceuticals is a global research company with its main data center in North America and a large research facility in Europe. They are heavily regulated and must comply with data sovereignty laws, requiring European user data to remain within Europe. The company is adopting a cloud-first strategy and plans to migrate their on-premises VDI to Azure Virtual Desktop.Current Environment:
The company uses Active Directory Domain Services (AD DS) on-premises, which is synchronized to Microsoft Entra ID using Microsoft Entra Connect. A Site-to-Site VPN connects the on-premises data center to an Azure hub VNet in the North America region.Project Requirements:
- Deploy a pooled AVD host pool in both the East US and West Europe Azure regions.
- User profiles for North American users must be stored in East US, and profiles for European users must be stored in West Europe.
- The profile solution must be resilient to a single storage failure within a region.
- Users must be able to access their sessions even if the primary storage location in their region is unavailable.
- Administrative effort for managing the profile solution should be minimized.
Problem:
You are the lead Azure Virtual Desktop architect responsible for designing the user profile solution. You need to choose a technology and configuration that meets all of Contoso's requirements for data sovereignty, performance, and high availability.Which solution should you propose?
Show answer & explanation
Correct answer: C
This solution correctly addresses all requirements. Using two separate FSLogix configurations (e.g., via different GPOs applied to regional OUs) ensures data sovereignty. Within each region, using Cloud Cache with two separate local Azure Files shares provides high availability against a single storage location failure. If one share fails, Cloud Cache can read/write from the other, meeting the resiliency requirement. Using LRS for the individual shares is cost-effective as the redundancy is provided by Cloud Cache itself.
- Question 9Intermediate
Plan and implement an Azure Virtual Desktop infrastructure · Automate creation of Azure Virtual Desktop hosts and host pools by using PowerShell, Azure CLI, Azure Resource Manager templates (ARM templates), and Bicep files
You need to automate the deployment of a new Azure Virtual Desktop host pool using an Azure Resource Manager (ARM) template. The template needs to create the host pool, a workspace, and an application group. A critical requirement is to ensure that the application group is automatically associated with the newly created host pool. Which ARM template property should you use to link the application group resource to the host pool resource?
Show answer & explanation
Correct answer: B
In an ARM template for AVD, the
Microsoft.DesktopVirtualization/applicationgroupsresource has a property namedhostPoolArmPath. You must set the value of this property to the resource ID of the host pool you are creating within the same template. This creates the necessary association between the application group and the host pool. - Question 10AdvancedSelect 2
Plan and implement identity and security · Configure single sign-on
A company has an Azure Virtual Desktop deployment where session hosts are Microsoft Entra joined, and the environment has no Active Directory Domain Services. Users authenticate to Microsoft Entra ID when they connect. The company wants to enable single sign-on (SSO) so that users do not have to enter their credentials a second time to access the Windows session on the host. Which TWO of the following are required to enable Microsoft Entra SSO for Azure Virtual Desktop? (Select TWO)
Show answer & explanation
Correct answers: B, D
To enable single sign-on with Microsoft Entra authentication, you first allow Microsoft Entra authentication for RDP in the tenant by setting isRemoteDesktopProtocolEnabled to true on the Windows Cloud Login service principal (app ID 270efc09-cd0d-444b-a71f-39af4910ec45), so that Microsoft Entra ID can issue RDP access tokens for the session hosts. You then set the host pool RDP property 'Microsoft Entra single sign-on' (enablerdsaadauth:i:1). The session hosts must be Microsoft Entra joined or Microsoft Entra hybrid joined, but the user's local device doesn't need to be joined to Microsoft Entra ID or a domain, and Intune enrollment of the session hosts isn't required. A Kerberos server object is needed only for hybrid joined session hosts, or for Entra joined session hosts in an environment with Active Directory domain controllers (to reach on-premises resources).
To enable single sign-on with Microsoft Entra authentication, you first allow Microsoft Entra authentication for RDP in the tenant by setting isRemoteDesktopProtocolEnabled to true on the Windows Cloud Login service principal (app ID 270efc09-cd0d-444b-a71f-39af4910ec45), so that Microsoft Entra ID can issue RDP access tokens for the session hosts. You then set the host pool RDP property 'Microsoft Entra single sign-on' (enablerdsaadauth:i:1). The session hosts must be Microsoft Entra joined or Microsoft Entra hybrid joined, but the user's local device doesn't need to be joined to Microsoft Entra ID or a domain, and Intune enrollment of the session hosts isn't required. A Kerberos server object is needed only for hybrid joined session hosts, or for Entra joined session hosts in an environment with Active Directory domain controllers (to reach on-premises resources).
Ready for the real thing?
The full AZ-140 simulator has every exam-style question, timed mode, and instant scoring.