nerdexam
MicrosoftMicrosoft

AZ-140 · Question #222

AZ-140 Question #222: Real Exam Question with Answer & Explanation

The correct answer is A: Windows Cloud Login. To enable Microsoft Entra authentication for RDP (which underpins SSO for Microsoft Entra joined AVD session hosts), you must modify the remoteDesktopSecurityConfiguration object on the service principal of the 'Windows Cloud Login' application in Microsoft Entra ID. This applica

Submitted by katya_ua· Apr 18, 2026Plan and implement identity and security

Question

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains two session hosts that are Microsoft Entra joined. You need to configure single sign-on (SSO) to connect to the session hosts. The solution must enable Microsoft Entra authentication for Remote Desktop Protocol (RDP) in the Microsoft Entra tenant. Which application requires that you modify the remoteDesktopSecurityConfiguration object?

Options

  • AWindows Cloud Login
  • BMicrosoft Azure Windows Virtual Machine Sign-in
  • CWindows 365
  • DAzure Virtual Desktop

Explanation

To enable Microsoft Entra authentication for RDP (which underpins SSO for Microsoft Entra joined AVD session hosts), you must modify the remoteDesktopSecurityConfiguration object on the service principal of the 'Windows Cloud Login' application in Microsoft Entra ID. This application (App ID: 270efc09-cd0d-444b-a71f-39af4910ec45) manages Windows cloud-based sign-in flows, including RDP authentication. Neither 'Azure Virtual Desktop' nor 'Windows 365' nor 'Microsoft Azure Windows Virtual Machine Sign-in' is the target for this specific configuration change.

Topics

#Azure Virtual Desktop#Single Sign-On#Microsoft Entra ID#RDP Authentication

Community Discussion

No community discussion yet for this question.

Full AZ-140 PracticeBrowse All AZ-140 Questions