AZ-140 — Frequently Asked Questions

Community-vetted answers to 26 common questions about this exam.

Questions from real practice questions

Each Q&A comes from a specific community question — follow the link for its full analysis.

AVD Per-user Access Pricing for External Users

Access groups grant permission but do not provide the necessary license for authentication and billing under per-user pricing.

No, Microsoft 365 F3 licenses allow guest users to access AVD resources without needing Azure AD Premium P1 or P2.

Which Two Actions Enable a Private Endpoint for an AVD Host Pool?

The feed sub-resource privately connects an Azure Virtual Desktop workspace so clients can reach the feed privately. For a host pool such as Pool1, the connection sub-resource is the one that carries session traffic.

Yes. The subscription must have the Microsoft.DesktopVirtualization resource provider registered so the private endpoint and its DNS/approval flow can be created for the host pool.

Adding Server2 to an AVD Host Pool: Which Two Actions?

Option B applies to Azure Arc-enabled servers or Azure Local session hosts. A standard Windows Server VM added to an AVD host pool needs the AVD agent and a host pool registration token.

New-AzWvdHostPool creates a new host pool, but Pool1 already exists. Adding Server2 requires registering it as a session host, not provisioning another host pool.

Which Storage Accounts Can Pool1 Use for FSLogix Containers?

Storage4 is a StorageV2 account in West US, while Pool1 is in East US. FSLogix Profile and Office Containers are latency-sensitive and should use Azure Files in the same region as the session hosts.

No. BlobBlockStorage supports only blob storage, not SMB file shares, and FSLogix Profile/Office Containers require an SMB Azure Files share.

Does the Owner Role Let Admin1 Assign Scaling1 to Pool1?

That role manages host pools and scaling plans, but lacks Microsoft.Authorization/roleAssignments/write, which the autoscale flow needs to grant the AVD service principal rights over the session host VMs.

Yes. User Access Administrator includes roleAssignments/write at subscription scope, so it can perform the role assignment that assigning Scaling1 to Pool1 requires, just like Owner.

Does User Access Administrator Let Admin1 Assign Scaling1 to Pool1?

User Access Administrator only manages role assignments; assigning a scaling plan is a Microsoft.DesktopVirtualization operation allowed by Desktop Virtualization Contributor, already held by Admin1.

Yes. Desktop Virtualization Contributor at subscription scope includes Microsoft.DesktopVirtualization actions, so Admin1 can already assign Scaling1 to Pool1.

Which Storage Accounts Can Host FSLogix Profile Containers?

FSLogix profiles are VHDX files mounted over SMB, and page blobs and block blobs do not expose an SMB file share, so they cannot host profile containers.

Yes. Microsoft lists standard file shares as valid for light workloads, while premium file shares are recommended for medium, heavy and power workloads.

How Should You Reference User1 in FSLogix Per-User Registry Settings?

FSLogix applies per-user settings through a SID-keyed registry subkey on the session host; a pre-Windows 2000 or UPN logon name can change and is not the mapping key.

Yes. Because the SID stays constant even when the UPN or SAM logon name is edited, FSLogix continues to match the per-user settings to the same account.

Does Session Time Limits Meet the AVD Auto Sign-Out Goal?

"Set time limit for disconnected sessions" ends the session once the limit expires, which signs the user out. Adding "End session when time limits are reached" ensures termination instead of a lingering disconnected session.

It works and meets the goal, but local policy must be applied to each session host and is lost on reimage. Domain GPO or Intune is preferable for fleets, though that does not change the answer here.

How Do You Secure AVD Session Host Admin Access via the Azure Portal?

Conditional Access only evaluates sign-in conditions such as MFA and device compliance; it does not provide the RDP/SSH channel to session hosts that portal-based administration requires.

No. Bastion connects over private IPs through the Azure portal, so session hosts can stay private with no public IPs and no inbound RDP/SSH ports open.

Which Users Support FSLogix Application Rule Sets on Entra Joined Hosts?

Rule sets match on traditional Active Directory SIDs. A cloud-only member exists only in Microsoft Entra ID, so it has no on-premises AD SID for App Masking to evaluate, even though it is a valid member account.

No. A guest identity is represented by its home-tenant object rather than a local on-premises AD SID, so application rule sets cannot resolve it on your Entra joined session hosts.

Azure VM Upload Requirements: VHD and Fixed Disk

While some legacy tools may allow it, Azure primarily supports Generation 2 VMs for upload. However, this specific exam question focuses on disk conversion actions (A and C) as the primary solution.

VHDX is supported by Azure, but the question options force a choice between VHD and other formats. Converting to VHD is a valid path, whereas keeping it as VHDX might require additional steps not listed.

Assigning Scaling Plan Permissions in Azure Virtual Desktop

The service principal requires permissions to manage the power state and resources of session host VMs, which the Owner role provides at the subscription level.

Admin1 has this role, but the question focuses on enabling the service principal's capabilities for autoscaling, which requires additional permissions.

Ready to practice?

Access 64 AZ-140 questions with instant feedback and detailed explanations.

View AZ-140 Practice Questions →

← Back to AZ-140 Configuring and Operating Microsoft Azure Virtual Desktop Study Guide