AZ-140 · Question #90
You have been assigned the responsibility to set up conditional access for the latest launch of Azure Virtual Desktop (AVD). Environment Details: - Site 1: Range for public IP addresses 13.107.128.0/2
The correct answer is A. Yes. Option A is correct because including Browser, Mobile Apps, and Desktop Clients in the Conditional Access policy ensures MFA enforcement is applied across all connection methods to Azure Virtual Desktop - web browser access, native desktop clients, and mobile apps alike. Without
Question
You have been assigned the responsibility to set up conditional access for the latest launch of Azure Virtual Desktop (AVD). Environment Details:
- Site 1: Range for public IP addresses 13.107.128.0/22
- Site 2: Range for public IP addresses 52.238.78.88/32
Requirements:
- Azure Virtual Desktop users receive a Multi-Factor Authentication (MFA) prompt from outside
the organization’s network
- Azure administrators receive an MFA prompt every time they log in
- All users and admins receive an MFA Prompt 2 hours after the last login
- Recommended Solution:
Add browser, Mobile Apps, and Desktop Clients to the Conditional Access Policy. Will configuring the recommended solution help in meeting the requirements?
Options
- AYes
- BNo
How the community answered
(46 responses)- A72% (33)
- B28% (13)
Explanation
Option A is correct because including Browser, Mobile Apps, and Desktop Clients in the Conditional Access policy ensures MFA enforcement is applied across all connection methods to Azure Virtual Desktop - web browser access, native desktop clients, and mobile apps alike. Without specifying all client app types, users could potentially bypass MFA requirements by connecting through an unguarded client path. Covering all three client app types closes those gaps, directly satisfying the requirements for location-based MFA (using the named IP ranges), admin sign-in MFA, and the 2-hour sign-in frequency control.
Option B is incorrect because it assumes the solution is insufficient - but this recommendation is precisely how Microsoft designs comprehensive AVD Conditional Access coverage, and omitting any client type would leave enforcement holes that this solution explicitly prevents.
Memory tip: Think of client app types as "entry doors" into AVD. If you only lock the front door (browser) but leave the side doors (mobile/desktop) unlocked, attackers walk right in - always lock all doors in your Conditional Access policy.
Topics
Community Discussion
No community discussion yet for this question.