certslothcertsloth
← AZ-140 overview

Azure Virtual Desktop Specialty / STUDY TOOLS

AZ-140 quick review

Memory hook: Pool groups hosts; workspace publishes; profile survives.

Reviewed 10 October 2026. Read this once, then answer the last-pass checks without looking.

Must remember by domain

Domain Rapid revision
Infrastructure Host pools group session hosts; application groups publish Desktop or RemoteApp resources; workspaces expose assigned groups. Pooled hosts share users; personal desktops assign individuals. Breadth-first spreads sessions; depth-first packs hosts toward limits to consolidate capacity. Validate OS/licensing and concurrency, memory and profile IO.
Network Service-mediated reverse connections avoid public inbound RDP on each host. Shortpath uses supported direct UDP paths; Multipath and QoS have prerequisites. Private Link requires correct client/host access paths and DNS. Bastion/JIT is administrator access, not the normal end-user transport.
Images and storage Golden image → validate/generalize → version in Compute Gallery → deploy hosts → roll out in rings. Image Builder automates supported builds. Existing hosts do not automatically inherit a new image. FSLogix profiles use VHD/VHDX containers on compatible shares; share permission and filesystem ACLs both matter.
Identity/security Match host join (AD DS/Entra/Domain Services), user authentication and profile-storage identity. AVD RBAC, application-group assignment, OS login and file access are different permissions. Conditional Access/MFA/SSO apply to supported flows; verify the actual connection path. Onboard endpoint protection and test application-control policies.
User environment/apps Profile Container preserves user state; ODFC targets supported Office data; Cloud Cache supports multiple profile providers with operational tradeoffs. App masking changes visibility; App attach delivers supported packages separately from the image. Neither grants software licensing. Configure Teams/media, OneDrive, Office activation, redirection, print, timeout and client policies for multi-session support.
Operations/recovery AVD Insights needs diagnostics and host collection. Monitor login/profile attach time, agent health, connection success and capacity. Scaling plans coordinate schedules, load-balancing and session limits; drain hosts before maintenance. Start VM on Connect starts eligible capacity but is not a full autoscale policy. DR needs profiles, images, identity, network and alternate-region hosts.

Diagnose in order

User assignment/license → identity/Conditional Access → host agent and availability → network transport → profile attachment/ACLs/locks → app launch and media optimization. A fast host with slow profile storage still gives a slow logon. Protect active sessions during draining; test restored profiles without mounting conflicting writable copies.

Last-pass self-check

1. Breadth-first versus depth-first?

Spread sessions for balance versus pack hosts toward limits for consolidation.

2. Can workspace publication replace application-group assignment?

No. The user still needs the published-resource assignment and compatible identity/access.

3. What should remain after replacing a pooled host?

The independently stored and protected user profile/data.

4. Image updated: are running hosts patched?

Not automatically. Roll out/reimage/update hosts through the maintenance process.

5. Does global AVD control-plane availability protect a single-region host fleet?

No. Session hosts, profile storage and dependencies need their own regional recovery design.

Sources

Every topic at a glance

Open any topic to revisit its essential facts, decisions and exam traps. Use the full topic for active recall and supporting references.

01 · AVD architecture and network paths

Memory hook: Workspace publishes; pool groups; host runs.

Must remember

  • A host pool groups session hosts; application groups publish desktops or RemoteApps; a workspace exposes assigned application groups to users. Assignments and user access must align across these objects.
  • Pooled hosts serve multiple users with breadth-first or depth-first distribution; personal hosts assign a desktop to an individual. Choose supported client/server OS and licensing for the use case, including multi-session eligibility.
  • Breadth-first distributes new sessions across available hosts to balance load. Depth-first consolidates sessions toward configured host limits, which can leave other hosts available to stop under a coordinated scaling policy. Neither mode overrides drain state, session limits or the need for enough real memory/application capacity. Reconnection to an existing session differs from allocating a new session.
  • AVD uses service-mediated reverse connectivity rather than requiring public inbound RDP on every host. RDP Shortpath and supported Multipath improve transport when network conditions and prerequisites allow.
  • Plan latency, bandwidth, DNS, required service endpoints, NSGs, UDRs and firewall access. Private Link changes supported access paths and DNS requirements; test client and host connectivity separately.
  • Choose region, VM size, host count, quotas and resource organization from concurrency and application demands. GPU, memory or per-user workload may dominate sizing.
  • Deploy through portal, PowerShell, CLI or ARM/Bicep, using a controlled host registration and image process. A host appearing in a pool still needs a healthy agent, identity join and working applications.

Choose under exam pressure

Requirement Choice and reason
Many task workers with similar apps A pooled host pool with sized capacity and profile separation.
One user requires a persistent dedicated desktop A personal host pool with explicit assignment.

Traps

  • A workspace is not the VM running the desktop.
  • Opening public TCP 3389 is not the standard requirement for user AVD access.

Practise this topic

02 · Images, profile storage and FSLogix

Memory hook: Replace the host; preserve the profile.

Must remember

  • Maintain a versioned golden image with required OS updates, applications and agents. Azure VM Image Builder automates supported builds; Azure Compute Gallery distributes image versions to target regions.
  • Generalize and validate images according to the supported process. Keep production release rings and rollback versions; an image update does not automatically patch all existing hosts.
  • FSLogix Profile Containers attach a user profile stored in a VHD/VHDX on supported shared storage. ODFC containers can isolate Office-related data for applicable scenarios; application masking controls visibility, not licensing.
  • Choose Azure Files or Azure NetApp Files from performance, identity, protocol, availability and cost requirements. Configure both share-level access and filesystem permissions correctly.
  • Cloud Cache supports multiple profile storage locations with local caching and its own performance/failure considerations. It is not permission-free replication or a replacement for tested backups.
  • Monitor profile attach time, capacity, IOPS, locks and concurrent access. Keep profiles separate from disposable session-host disks and test restores without corrupting active user state.

Choose under exam pressure

Requirement Choice and reason
Users lose settings when moving between pooled hosts Implement correctly permissioned FSLogix profile containers.
Need consistent host replacements across regions Versioned images in Azure Compute Gallery with tested regional availability.

Traps

  • A user can pass AVD sign-in and still fail profile storage authentication.
  • Copying an actively mounted profile is not automatically a consistent backup.

Practise this topic

03 · Identity and session-host security

Memory hook: Service login, host login, data access.

Must remember

  • Select a supported identity model using AD DS, Microsoft Entra ID or Entra Domain Services. Session-host join, user identity and profile-storage authentication must be compatible.
  • Azure RBAC controls AVD resource administration; application-group assignment grants published-resource access; guest OS and storage permissions govern later actions. One grant does not imply all the others.
  • Conditional Access, MFA/passwordless methods and Entra SSO protect supported connection flows. Test policies with pilot users and retain emergency administrative access.
  • Use Defender for Cloud/Servers, Defender Antivirus and Defender for Endpoint according to the required protection. Onboarding and policy assignment are necessary before assuming endpoint telemetry exists.
  • NSGs, UDRs and Azure Firewall constrain network paths. Bastion or JIT access can protect administrator entry; do not confuse administrative connectivity with end-user AVD transport.
  • Use supported Trusted Launch/confidential VM options, application control and Controlled Folder Access where suitable. Test policy compatibility with multi-session applications and profile containers.

Choose under exam pressure

Requirement Choice and reason
A desktop is published but the user cannot open it Check app-group assignment, identity policy, host join and sign-in rights separately.
Admins need occasional host access Bastion/JIT or another approved restricted management path.

Traps

  • Being an AVD administrator does not automatically assign a desktop to that administrator.
  • A compliant identity does not guarantee a healthy profile or application.

Practise this topic

04 · Applications and user experience

Memory hook: Publish the right app; redirect only what is needed.

Must remember

  • Choose desktop versus RemoteApp delivery according to the user workflow. Create application groups, publish applications and assign users deliberately; verify the executable and dependencies on each eligible host.
  • Install applications in the image, deploy with management tooling or use supported App attach packages. App attach separates supported application packaging from the base image but still needs package compatibility and access.
  • Microsoft 365 Apps, OneDrive and Teams require supported multi-session configuration. Use the current Teams optimization/media components for the client and session-host combination rather than assuming any desktop installer is sufficient.
  • Client choice affects features and transport. Configure device, clipboard, drive, printer and multimedia redirection according to security and usability requirements; Universal Print solves a different layer from arbitrary local printer redirection.
  • Use Intune or Group Policy for supported user/session settings. Host-pool RDP properties, session timeouts and personal-desktop assignment influence experience and resource use.
  • Start VM on Connect starts an eligible host when needed; it does not replace a complete capacity/scaling strategy. Test the experience with actual client versions and realistic profiles.

Choose under exam pressure

Requirement Choice and reason
One application is required without a full desktop Publish a RemoteApp through an assigned application group.
Sensitive desktops must not export local files Restrict appropriate redirection paths and test the actual client behavior.

Traps

  • An app installed on one host is not available on every pooled host.
  • Start VM on Connect does not guarantee unlimited immediate capacity.

Practise this topic

05 · Monitoring, scaling and recovery

Memory hook: Measure logon, manage capacity, recover profiles.

Must remember

  • AVD Insights uses Azure Monitor/Log Analytics with required diagnostics and host data collection. Inspect connection success, logon duration, profile attach, host utilization and application responsiveness.
  • Scaling plans schedule and adjust supported host-pool capacity. Coordinate breadth/depth-first behavior, session limits, drain mode and user notifications; do not remove hosts with unhandled active sessions.
  • Optimize from peak concurrency and application demand. Low average CPU does not prove spare memory, disk or profile-storage performance.
  • Patch images and hosts through staged rollout, drain and replacement/update procedures. Preserve a tested prior image and verify user applications after each change.
  • DR includes alternate-region host capacity, replicated/available images, profile/data recovery, identity, DNS and assignments. A globally managed control plane does not make a single-region session-host fleet region-resilient.
  • Back up profiles, personal desktop data and required images/configuration with suitable policies. Test restore and user reconnection against the RPO/RTO.

Choose under exam pressure

Requirement Choice and reason
Morning logons are slow Correlate host capacity, profile storage, identity and logon telemetry.
Reduce overnight cost A tested scaling plan that respects active sessions and minimum required capacity.

Traps

  • A session-host backup alone does not protect profiles stored elsewhere.
  • Deallocating hosts saves compute but retained disks and storage still incur cost.

Practise this topic

Search across every published topic.