How Do You Secure AVD Session Host Admin Access via the Azure Portal?

Answer Correct answer: B — Azure Bastion provides secure RDP/SSH to AVD session hosts directly through the Azure portal without public IPs or exposed management ports.

You have an Azure Virtual Desktop deployment. You need to secure administrative access to session hosts. The solution must require that administrators use the Azure portal to access the session hosts. What should you include in the solution?

  1. Azure Firewall
  2. Azure Bastion Correct Answer
  3. Conditional Access policies
  4. Microsoft Defender for Cloud

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests whether you can map the phrase 'access through the Azure portal' to Azure Bastion; the trap is choosing Conditional Access, which governs identity at sign-in rather than portal-based RDP/SSH connectivity to session hosts.

Securing administrative access to Azure Virtual Desktop session hosts while forcing administrators through the Azure portal requires Azure Bastion, which brokers RDP/SSH over TLS 443 without public IPs or exposed management ports. This page confirms why Bastion (B) — not Azure Firewall, Conditional Access, or Defender for Cloud — satisfies the AZ-140 requirement.

Learners often pick Conditional Access policies (C) because the question says 'secure administrative access' and CA is the default security reflex — but CA only controls authentication conditions, not the remote session transport that Bastion actually provides.

Community Discussion (6 comments)

JT24 👍 1 Selected: B
To secure administrative access to your Azure Virtual Desktop session hosts and ensure that administrators use the Azure portal to access them, you should include Azure Bastion in your solution. Azure Bastion provides secure and seamless RDP and SSH connectivity to your virtual machines directly through the Azure portal, without exposing them to the public internet
jeff1988 👍 1 Selected: B
B. Azure Bastion. Azure Bastion provides secure and seamless RDP and SSH connectivity to your virtual machines directly through the Azure portal. This eliminates the need for exposing your VMs to the public internet and enhances security by using the Azure portal for administrative access.
Bonesurfer 👍 1
Answer B Using Azure Bastion is the optimal choice for secure, Azure portal-based access to session hosts in an AVD deployment.
lopt0909 👍 1 Selected: B
Bastion is correct
DiegoCidA 👍 2
Must be Azure Bastion.
kam247 👍 1
I think the answer should be C. Azure Firewall would not be used to only secure administrators access to a session host.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Azure Bastion delivers RDP and SSH connectivity to virtual machines directly inside the Azure portal over TLS 443, so administrators never need public IPs, VPN clients, or open RDP/SSH ports on AVD session hosts. Because the question explicitly requires that administrators "use the Azure portal to access the session hosts," Bastion is the only listed service that literally brokers that portal-embedded session; it is deployed into the session hosts' virtual network (or a peered hub) and connects over private IPs. It also integrates with Azure AD sign-in and RBAC, so you can scope exactly which administrators may initiate a session. In short, Bastion satisfies both halves of the requirement — secure administrative access and portal-mediated connectivity.

Why the Other Options Are Wrong

Azure Firewall (A) is a traffic-filtering control for ingress/egress flows; it can restrict outbound traffic from session hosts but cannot grant or channel an administrator's RDP session through the portal. Conditional Access policies (C) evaluate user, device, and location signals at sign-in and can enforce MFA or compliant devices, but they protect identity — they do not create a portal-based RDP/SSH path to a session host. Microsoft Defender for Cloud (D) is a posture management and threat protection service (secure score, recommendations, alerts) and never provides administrative remote access. None of these three removes the need for a public IP or open RDP port the way Bastion does, so none meets the portal-access wording of the requirement.

Community Comment Notes

The community is effectively unanimous for Bastion. JT24 explains that Azure Bastion provides "RDP and SSH connectivity to your virtual machines directly through the Azure portal," and jeff1988 adds that it "eliminates the need for exposing your VMs to the public internet." Bonesurfer calls Bastion "the optimal choice for secure, Azure portal-based access to session hosts," while DiegoCidA simply states "Must be Azure Bastion." Even kam247, who initially leaned toward Conditional Access, concedes that "Azure Firewall would not be used to only secure administrators access to a session host," which neatly shows why the firewall distractor fails.

Official Reference

Exam Strategy

When an AZ-140 item says administrators must reach session hosts "through the Azure portal," treat that as a Bastion keyword — Bastion is the only Azure service that embeds RDP/SSH in the portal. If the requirement also mentions "no public IPs" or "no open RDP ports," it is confirming the same answer rather than pointing to a firewall or Conditional Access rule.

Frequently Asked Questions

Why isn't Conditional Access (C) enough to secure session host admin access?

Conditional Access only evaluates sign-in conditions such as MFA and device compliance; it does not provide the RDP/SSH channel to session hosts that portal-based administration requires.

Do Azure Bastion and AVD session hosts need public IP addresses?

No. Bastion connects over private IPs through the Azure portal, so session hosts can stay private with no public IPs and no inbound RDP/SSH ports open.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide