Onboard AVD Session Hosts to Defender for Endpoint

Answer Correct answer: B — Add a Defender for Endpoint onboarding script to Image1, and then run the script at first start.

You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. You plan to create a Windows 10 image named Image1 to deploy new session hosts to Pool1. You need to ensure that all the new session hosts deployed by using Image1 are onboarded to Microsoft Defender for Endpoint. What should you do?

  1. Run a Defender for Endpoint onboarding script on Image1, and then run sysprep.
  2. Add a Defender for Endpoint onboarding script to image1, and then run the script at first start. Correct Answer
  3. Create an MSIX package for Pool1.
  4. Create an automation task for Pool1.

Community Votes

B
71%
A
29%

71% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests onboarding Microsoft Defender for Endpoint to AVD golden images; the common trap is running the script before sysprep, which causes duplicate sensor IDs.

When creating an Azure Virtual Desktop golden image, Microsoft Defender for Endpoint must be onboarded correctly to avoid sensor ID conflicts. This page establishes that the onboarding script should be added to the image and executed at first start.

Option A is the most common wrong answer because running the script before sysprep shares the same sensor ID across all deployed session hosts, breaking proper Defender tracking.

Community Discussion (6 comments)

Dahkoht 👍 1 Selected: B
GPT's updated explanation on why it's not A, A. Run a Defender for Endpoint onboarding script on Image1, and then run sysprep. ❌ • Wrong because sysprep resets system-specific configurations, and Defender for Endpoint needs unique identifiers.
Roee1 👍 1 Selected: A
Acording to my knowlege and my friend chat gpt A is the correct answer
WILLYPUMPKIN 👍 2 Selected: B
Answer is B Microsoft recommends adding the Microsoft Defender for Endpoint onboarding script to the AVD golden image. This way, you can be sure that this onboarding script runs immediately at first boot. It's executed as a startup script at first boot on all the AVD machines that are provisioned from the AVD golden image. The placement and configuration of the VDI onboarding startup script on the AVD golden image configures it as a startup script that runs when the AVD starts. It's NOT recommended to onboard the actual AVD golden image. https://learn.microsoft.com/en-us/defender-endpoint/onboard-windows-multi-session-device
sKostas 👍 2 Selected: B
The following article clearly states that you should add the script in the image and run in at the first boot. I believe B is the right answer. https://learn.microsoft.com/en-us/defender-endpoint/onboard-windows-multi-session-device
jeff1988 👍 1 Selected: A
A. Run a Defender for Endpoint onboarding script on Image1, and then run sysprep. This method ensures that the onboarding script is included in the image and executed when the virtual machines are first started, effectively onboarding them to Microsoft Defender for Endpoint
Bonesurfer 👍 2
Correct https://learn.microsoft.com/en-us/defender-endpoint/onboard-windows-multi-session-device

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Option B is correct because Microsoft's official documentation for onboarding Virtual Desktop Infrastructure (VDI) endpoints explicitly recommends adding the onboarding script to the golden image and configuring it to run at first boot. This ensures each newly provisioned session host generates a unique sensor ID in Microsoft Defender for Endpoint, maintaining proper isolation and tracking.

Why the Other Options Are Wrong

Option A is incorrect because running the onboarding script before sysprep causes all session hosts deployed from that image to share the same Defender sensor ID, leading to reporting conflicts. Option C is irrelevant because MSIX app attach is used for application delivery, not for endpoint security agent onboarding. Option D is incorrect because an automation task does not handle the specific VDI onboarding requirements needed to generate unique sensor identifiers for Defender for Endpoint.

Community Comment Notes

Several commenters pointed to the official Microsoft documentation, with sKostas noting the article "clearly states that you should add the script in the image and run in at the first boot." Dahkoht also highlighted why A is wrong, explaining that "sysprep resets system-specific configurations, and Defender for Endpoint needs unique identifiers."

Official Reference

Exam Strategy

For AVD image management questions involving agents or security tools, always consider how sysprep affects unique identifiers. If an agent requires a unique machine identity, its installation or onboarding script must run after sysprep completes, typically at first startup.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide