SC-100 · Question #51
Your company has a hybrid cloud infrastructure. The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the…
The correct answer is D. Deploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and. Azure Virtual Desktop (AVD) combined with Azure AD Conditional Access (and likely Microsoft Intune/Endpoint Manager) satisfies all requirements. AVD provides managed virtual desktops that temporary employees access via a browser or thin client-no personal device installs…
Question
Your company has a hybrid cloud infrastructure. The company plans to hire several temporary employees within a brief period. The temporary employees will need to access applications and data on the company' premises network. The company's security policy prevents the use of personal devices for accessing company data and applications. You need to recommend a solution to provide the temporary employee with access to company resources. The solution must be able to scale on demand. What should you include in the recommendation?
Options
- AMigrate the on-premises applications to cloud-based applications.
- BRedesign the VPN infrastructure by adopting a split tunnel configuration.
- CDeploy Microsoft Endpoint Manager and Azure Active Directory (Azure AD) Conditional Access.
- DDeploy Azure Virtual Desktop, Azure Active Directory (Azure AD) Conditional Access, and
How the community answered
(19 responses)- A5% (1)
- B11% (2)
- C5% (1)
- D79% (15)
Explanation
Azure Virtual Desktop (AVD) combined with Azure AD Conditional Access (and likely Microsoft Intune/Endpoint Manager) satisfies all requirements. AVD provides managed virtual desktops that temporary employees access via a browser or thin client-no personal device installs company data or applications, complying with the security policy. AVD scales on demand by adding session hosts. Conditional Access enforces access policies (MFA, compliant device, location) before granting access. Option A (migrating to cloud apps) doesn't address the on-premises data requirement. Option B (split tunnel VPN) still requires personal-device VPN clients, violating policy. Option C alone (Endpoint Manager + Conditional Access) enforces policy on existing devices but doesn't provide the virtual desktop mechanism needed to keep data off personal devices.
Topics
Community Discussion
No community discussion yet for this question.