nerdexam
Microsoft

AZ-140 · Question #149

Your network contains an on-premises Active Directory domain named contoso.com that syncs to an Azure Active Directory (Azure AD) tenant. You have an Azure Virtual Desktop host pool named Pool1 that…

The correct answer is D. Configure the session hosts as hybrid Azure AD-joined. Microsoft Endpoint Manager (Intune) can only manage devices that are registered or joined to Azure AD. The session hosts are currently only joined to the on-premises contoso.com domain (traditional domain join), making them invisible to MEM. Configuring Hybrid Azure AD Join (D)…

Submitted by helene.fr· Apr 18, 2026Plan and implement identity and security

Question

Your network contains an on-premises Active Directory domain named contoso.com that syncs to an Azure Active Directory (Azure AD) tenant. You have an Azure Virtual Desktop host pool named Pool1 that has the following settings:

  • Host pool name: Pool1
  • Host pool type: Personal
  • Number of VMs: 3

The session hosts have the following configurations:

  • Image used to create the virtual machines: Windows 10 Enterprise8
  • Virtual machines domain-joined to: On-premises contoso.com domain

You need to ensure that you can use Microsoft EndPoint Manager to manage security updates on the session hosts. What should you do?

Options

  • AChange Host pool type to Pooled and specify Load balancing algorithm as Depth-first.
  • BChange Host pool type to Pooled and specify Load balancing algorithm as Breadth-first.
  • CCreate Windows 10 Enterprise multi-session images.
  • DConfigure the session hosts as hybrid Azure AD-joined.

How the community answered

(29 responses)
  • A
    10% (3)
  • B
    3% (1)
  • C
    3% (1)
  • D
    83% (24)

Explanation

Microsoft Endpoint Manager (Intune) can only manage devices that are registered or joined to Azure AD. The session hosts are currently only joined to the on-premises contoso.com domain (traditional domain join), making them invisible to MEM. Configuring Hybrid Azure AD Join (D) enrolls the machines in both the on-premises domain and Azure AD simultaneously, which makes them appear in MEM and enables policy, update, and compliance management. Changing the host pool type (A, B) affects load balancing, not identity. Creating multi-session images (C) changes the OS type but doesn't resolve the Azure AD registration requirement.

Topics

#Azure Virtual Desktop#Microsoft Endpoint Manager#Hybrid Azure AD Join#Device Management

Community Discussion

No community discussion yet for this question.

Full AZ-140 Practice