Which RBAC Role for AVD Entra Joined Session Host Login?

Answer Correct answer: D — Assign the Virtual Machine User Login role to allow standard users to sign in while following the principle of least privilege.

You have an Azure Virtual Desktop deployment that contains a pooled host pool named Pool1. Pool1 contains four Microsoft Entra joined session hosts. Users report that when they attempt to sign in to a session host, they receive a message indicating that their account is not configured to sign in. You need to assign the users a role-based access control (RBAC) role to ensure that they can sign in to the session hosts. The solution must follow the principle of least privilege. Which role should you assign to the users?

  1. Desktop Virtualization Virtual Machine Contributor
  2. Virtual Machine Contributor
  3. Virtual Machine Administrator Login
  4. Virtual Machine User Login Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the specific RBAC roles required for Microsoft Entra joined VM logins, where the common trap is selecting a management role instead of a login role.

Assigning the correct RBAC role for Microsoft Entra joined Azure Virtual Desktop session hosts is critical for user access. This page establishes that the Virtual Machine User Login role provides the least privileged access required for standard users to sign in.

Choosing Virtual Machine Administrator Login (C) or Virtual Machine Contributor (B), which either grant excessive privileges or do not allow interactive login at all.

Community Discussion (6 comments)

soysoliscarlos 👍 1 Selected: D
D. Virtual Machine User Login I have been implementing this role in my AVD environments.
db7a78f 👍 1 Selected: D
Virtual Machine Contributor role (option B) would grant users more permissions than necessary, as it allows them to manage virtual machines, including creating and deleting them. This does not follow the principle of least privilege. The Virtual Machine User Login role (option D) is the correct choice because it provides the necessary permissions for users to log in to the session hosts without granting additional management capabilities.
jeff1988 👍 2 Selected: D
D. Virtual Machine User Login To ensure that users can sign in to the session hosts in your Azure Virtual Desktop deployment while following the principle of least privilege, you should assign them the Virtual Machine User Login role. This role allows users to log in to virtual machines as regular users without granting them additional permissions that are not necessary for their tasks.
Bonesurfer 👍 2
D The Virtual Machine User Login role is the appropriate choice because it grants users the permission to log in to a virtual machine as standard users. This role aligns with the principle of least privilege by only providing the necessary access for users to sign in, without granting additional permissions to manage or modify virtual machines.
Dungeon_Master 👍 3
Answer is D
Bonifacef 👍 4
I believe its D "Virtual Machine User Login"

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

The "Virtual Machine User Login" role is specifically designed to allow users to log in to an Azure virtual machine as a standard user. When session hosts are Microsoft Entra joined, users must have this role (or the Administrator Login variant) assigned at the VM, resource group, or subscription level to authenticate. Assigning this role adheres strictly to the principle of least privilege by granting only the necessary login permissions without any management capabilities.

Why the Other Options Are Wrong

"Desktop Virtualization Virtual Machine Contributor" (A) and "Virtual Machine Contributor" (B) are management roles that allow modifying VM configurations but do not grant interactive login permissions. "Virtual Machine Administrator Login" (C) grants local administrator privileges upon login, which violates the principle of least privilege for standard AVD users who only need standard user access to their session.

Community Comment Notes

The community consensus correctly identifies that the Virtual Machine User Login role is the least privileged option for standard user access. As jeff1988 noted, this role "allows users to log in to virtual machines as regular users without granting them additional permissions," and Bonesurfer confirmed it "aligns with the principle of least privilege by only providing the necessary access for users to sign in".

Official Reference

Exam Strategy

For Microsoft Entra joined VMs, remember that standard Azure RBAC management roles like Contributor do not grant login permissions. You must explicitly assign either the Virtual Machine User Login or Administrator Login role to enable Entra ID authentication.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide