FSLogix Application Masking for AVD Pooled Host Pools
You have an Azure Virtual Desktop deployment that contains a pooled host pool named Pool1. Pool1 contains five session hosts. You plan to deploy two apps named App1 and App2. The solution must meet the following requirements: • All the session hosts must contain both apps. • All users must connect to a full desktop session. • Only users in the sales department must be able to use App1. • Only users in the research department must be able to use App2. You need to ensure that the users in each department can see only their assigned app when they connect to Pool1. What should you use?
Community Votes
100% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the ability to restrict application visibility within a full desktop AVD session, where the common trap is choosing RemoteApp which only provides remote apps, not a full desktop.
FSLogix application masking controls application visibility based on user group membership within a full desktop session. This page establishes that FSLogix application masking is the correct solution for hiding specific installed apps from unauthorized users in an Azure Virtual Desktop pooled host pool.
Choosing RemoteApp application groups because it restricts app access, but it violates the requirement for users to connect to a full desktop session.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
FSLogix application masking dynamically hides or shows installed applications based on the user's Active Directory group membership. In this scenario, both App1 and App2 are installed on all session hosts, but application masking rules ensure that only the sales department sees App1 and only the research department sees App2. This perfectly satisfies the requirement to provide a full desktop session while restricting application visibility.Why the Other Options Are Wrong
RemoteApp application groups and RemoteApp streaming are incorrect because they publish individual applications rather than a full desktop session, directly violating a stated requirement. MSIX app attach is used to deliver applications dynamically to session hosts without installing them permanently, but it does not provide the granular, group-based visibility restriction needed to hide installed apps within a full desktop.Community Comment Notes
The community unanimously agrees that FSLogix application masking is required here because the users must connect to a full desktop session. As Bonesurfer noted, "RemoteApp application groups are typically used to publish specific applications directly to users rather than providing a full desktop session." Joelpincol also pointed out that "They are using full desktop - Should be A (FSLogix masking)".Official Reference
Exam Strategy
When a question specifies users must connect to a full desktop session while having restricted app visibility, eliminate RemoteApp options immediately. Look for FSLogix application masking as the mechanism that filters installed apps by group policy within that desktop.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →