Memory hook: Service login, host login, data access.
Must remember
- Select a supported identity model using AD DS, Microsoft Entra ID or Entra Domain Services. Session-host join, user identity and profile-storage authentication must be compatible.
- Azure RBAC controls AVD resource administration; application-group assignment grants published-resource access; guest OS and storage permissions govern later actions. One grant does not imply all the others.
- Conditional Access, MFA/passwordless methods and Entra SSO protect supported connection flows. Test policies with pilot users and retain emergency administrative access.
- Use Defender for Cloud/Servers, Defender Antivirus and Defender for Endpoint according to the required protection. Onboarding and policy assignment are necessary before assuming endpoint telemetry exists.
- NSGs, UDRs and Azure Firewall constrain network paths. Bastion or JIT access can protect administrator entry; do not confuse administrative connectivity with end-user AVD transport.
- Use supported Trusted Launch/confidential VM options, application control and Controlled Folder Access where suitable. Test policy compatibility with multi-session applications and profile containers.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| A desktop is published but the user cannot open it | Check app-group assignment, identity policy, host join and sign-in rights separately. |
| Admins need occasional host access | Bastion/JIT or another approved restricted management path. |
Traps
- Being an AVD administrator does not automatically assign a desktop to that administrator.
- A compliant identity does not guarantee a healthy profile or application.
Active recall
1. What does Entra SSO simplify?
Supported authentication between AVD access and the session host without repeated credentials.
2. Why stage Conditional Access?
Mis-scoped policies can lock out legitimate users and administrators.
3. What is Trusted Launch intended to strengthen?
Supported boot integrity and platform security features.
4. Why onboard Defender for Endpoint explicitly?
Protection and telemetry depend on supported installation/onboarding and policy.
5. Which boundary should use least privilege?
Every boundary: Azure management, published resources, host OS and user data.