Which Two Actions Enable a Private Endpoint for an AVD Host Pool?
You have an Azure Virtual Desktop deployment that contains a host pool named Pool1. Pool1 contains three session hosts. You need to implement a private endpoint connection for Pool. Which two actions should you perform? Each correct answer presents part of the solution. NOTE: Each correct selection is worth one point.
Community Votes
75% of anonymous learners picked answer CD. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests which resource provider registration pairs with which Private Link sub-resource for a host pool, and the trap is picking the feed sub-resource, which private-links a workspace instead of a pool.
Securing an Azure Virtual Desktop host pool with Azure Private Link takes two actions: reregistering the Microsoft.DesktopVirtualization resource provider for the subscription and creating a private endpoint that uses the connection sub-resource. This page confirms answer (C, D) and explains why the feed and global sub-resources belong to other AVD objects.
Most learners who miss this pick option E (feed sub-resource) because they assume every AVD private endpoint uses the same sub-resource; the feed sub-resource actually applies to an Azure Virtual Desktop workspace, not to a host pool.
Community Discussion (5 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A host pool is private-linked through the connection sub-resource, so option D is required; the connection sub-resource carries the RDP/session-brokering traffic to the individual Pool1 session hosts. Before the private endpoint can be created and resolved, the subscription must have the Microsoft.DesktopVirtualization resource provider registered, which is exactly what option C states. Both actions together satisfy the "private endpoint connection for Pool1" requirement, which is why the vote leaders and the Microsoft private-link setup article both land on C and D.Why the Other Options Are Wrong
Option A uses the global sub-resource, which does not exist for provisioning a host pool private endpoint in this scenario and is offered as a distractor alongside the real sub-resource names. Option B tells you to reregister Microsoft.VirtualMachineImages, a provider tied to image-building/VM image templates and unrelated to Private Link for Desktop Virtualization. Option E uses the feed sub-resource, which is the correct choice when you are privately connecting an Azure Virtual Desktop workspace feed, not a host pool, so it fails the "for Pool1" requirement stated in the question.Community Comment Notes
Support for C and D is strong: Roee1 states plainly that "a private endpoint for the pool need connection subresource" and links the Microsoft private-link setup page, and WILLYPUMPKIN concurs that the answers are C & D with the same reference. The dissenters are instructive but wrong on the sub-resource: jeff1988 chose CE and argued that the feed sub-resource "allows you to create a private endpoint specifically for the Azure Virtual Desktop feed," which describes workspace-level private link, while Bonesurfer floated AC around the global sub-resource for "session brokering and management functions." Those comments show exactly why the feed/global distractors are attractive — they sound plausible until you map sub-resource to AVD object.Official Reference
Exam Strategy
When AZ-140 asks which sub-resource a private endpoint should use, first identify the AVD object in the stem: host pool means connection, workspace means feed, and the global sub-resource is not part of a standard host pool private endpoint. Pairing the sub-resource with the provider registration (Microsoft.DesktopVirtualization) is almost always one of the two required actions.
Frequently Asked Questions
Why is the feed sub-resource wrong for a host pool private endpoint?
The feed sub-resource privately connects an Azure Virtual Desktop workspace so clients can reach the feed privately. For a host pool such as Pool1, the connection sub-resource is the one that carries session traffic.
Do I really need to reregister Microsoft.DesktopVirtualization before a private endpoint?
Yes. The subscription must have the Microsoft.DesktopVirtualization resource provider registered so the private endpoint and its DNS/approval flow can be created for the host pool.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →