Onboard AVD Session Hosts to Defender for Endpoint
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. You plan to create a Windows 10 image named Image1 to deploy new session hosts to Pool1. You need to ensure that all the new session hosts deployed by using Image1 are onboarded to Microsoft Defender for Endpoint. What should you do?
Community Votes
71% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests onboarding Microsoft Defender for Endpoint to AVD golden images; the common trap is running the script before sysprep, which causes duplicate sensor IDs.
When creating an Azure Virtual Desktop golden image, Microsoft Defender for Endpoint must be onboarded correctly to avoid sensor ID conflicts. This page establishes that the onboarding script should be added to the image and executed at first start.
Option A is the most common wrong answer because running the script before sysprep shares the same sensor ID across all deployed session hosts, breaking proper Defender tracking.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Option B is correct because Microsoft's official documentation for onboarding Virtual Desktop Infrastructure (VDI) endpoints explicitly recommends adding the onboarding script to the golden image and configuring it to run at first boot. This ensures each newly provisioned session host generates a unique sensor ID in Microsoft Defender for Endpoint, maintaining proper isolation and tracking.Why the Other Options Are Wrong
Option A is incorrect because running the onboarding script before sysprep causes all session hosts deployed from that image to share the same Defender sensor ID, leading to reporting conflicts. Option C is irrelevant because MSIX app attach is used for application delivery, not for endpoint security agent onboarding. Option D is incorrect because an automation task does not handle the specific VDI onboarding requirements needed to generate unique sensor identifiers for Defender for Endpoint.Community Comment Notes
Several commenters pointed to the official Microsoft documentation, with sKostas noting the article "clearly states that you should add the script in the image and run in at the first boot." Dahkoht also highlighted why A is wrong, explaining that "sysprep resets system-specific configurations, and Defender for Endpoint needs unique identifiers."Official Reference
Exam Strategy
For AVD image management questions involving agents or security tools, always consider how sysprep affects unique identifiers. If an agent requires a unique machine identity, its installation or onboarding script must run after sysprep completes, typically at first startup.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →