nerdexam
Microsoft

AZ-140 · Question #36

You network contains an on-premises Active Directory domain. The domain contains a universal security group named WVDusers. You have a hybrid Azure Active Directory (Azure AD) tenant. WVDusers syncs…

The correct answer is D. Assign WVDusers to an application group. In Azure Virtual Desktop, access to a host pool is controlled through application groups. Users or groups must be assigned to an application group (either a Desktop application group or RemoteApp application group) to establish sessions. Assigning WVDusers to the application…

Submitted by weili_xi· Apr 18, 2026Plan and implement an Azure Virtual Desktop infrastructure

Question

You network contains an on-premises Active Directory domain. The domain contains a universal security group named WVDusers. You have a hybrid Azure Active Directory (Azure AD) tenant. WVDusers syncs to Azure AD. You have a Azure Virtual Desktop host pool that contains four Windows 10 Enterprise multi- session hosts. You need to ensure that only the members of WVDusers can establish Azure Virtual Desktop sessions to the host pool. What should you do?

Options

  • AAssign WVDusers to an Azure role scoped to each host pool.
  • BOn each session host, add WVDusers to the local Remote Desktop Users group.
  • CAssign WVDusers to an Azure role scoped to the session hosts.
  • DAssign WVDusers to an application group.

How the community answered

(26 responses)
  • A
    4% (1)
  • B
    4% (1)
  • D
    92% (24)

Explanation

In Azure Virtual Desktop, access to a host pool is controlled through application groups. Users or groups must be assigned to an application group (either a Desktop application group or RemoteApp application group) to establish sessions. Assigning WVDusers to the application group associated with the host pool grants only those members access. Option A (Azure role scoped to the host pool) grants management-plane permissions (e.g., to administer the pool), not session access. Option B (local Remote Desktop Users group on each host) is a low-level host-based approach that bypasses AVD's access control model and requires manual configuration on each VM. Option C (Azure role scoped to session hosts) again grants resource management rights, not session access rights. Application group assignment is the correct, supported AVD mechanism.

Topics

#Azure Virtual Desktop#Application Groups#User Access#Access Control

Community Discussion

No community discussion yet for this question.

Full AZ-140 Practice