How Do You Secure AVD Session Host Admin Access via the Azure Portal?
You have an Azure Virtual Desktop deployment. You need to secure administrative access to session hosts. The solution must require that administrators use the Azure portal to access the session hosts. What should you include in the solution?
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The exam tests whether you can map the phrase 'access through the Azure portal' to Azure Bastion; the trap is choosing Conditional Access, which governs identity at sign-in rather than portal-based RDP/SSH connectivity to session hosts.
Securing administrative access to Azure Virtual Desktop session hosts while forcing administrators through the Azure portal requires Azure Bastion, which brokers RDP/SSH over TLS 443 without public IPs or exposed management ports. This page confirms why Bastion (B) — not Azure Firewall, Conditional Access, or Defender for Cloud — satisfies the AZ-140 requirement.
Learners often pick Conditional Access policies (C) because the question says 'secure administrative access' and CA is the default security reflex — but CA only controls authentication conditions, not the remote session transport that Bastion actually provides.
Community Discussion (6 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
Azure Bastion delivers RDP and SSH connectivity to virtual machines directly inside the Azure portal over TLS 443, so administrators never need public IPs, VPN clients, or open RDP/SSH ports on AVD session hosts. Because the question explicitly requires that administrators "use the Azure portal to access the session hosts," Bastion is the only listed service that literally brokers that portal-embedded session; it is deployed into the session hosts' virtual network (or a peered hub) and connects over private IPs. It also integrates with Azure AD sign-in and RBAC, so you can scope exactly which administrators may initiate a session. In short, Bastion satisfies both halves of the requirement — secure administrative access and portal-mediated connectivity.Why the Other Options Are Wrong
Azure Firewall (A) is a traffic-filtering control for ingress/egress flows; it can restrict outbound traffic from session hosts but cannot grant or channel an administrator's RDP session through the portal. Conditional Access policies (C) evaluate user, device, and location signals at sign-in and can enforce MFA or compliant devices, but they protect identity — they do not create a portal-based RDP/SSH path to a session host. Microsoft Defender for Cloud (D) is a posture management and threat protection service (secure score, recommendations, alerts) and never provides administrative remote access. None of these three removes the need for a public IP or open RDP port the way Bastion does, so none meets the portal-access wording of the requirement.Community Comment Notes
The community is effectively unanimous for Bastion. JT24 explains that Azure Bastion provides "RDP and SSH connectivity to your virtual machines directly through the Azure portal," and jeff1988 adds that it "eliminates the need for exposing your VMs to the public internet." Bonesurfer calls Bastion "the optimal choice for secure, Azure portal-based access to session hosts," while DiegoCidA simply states "Must be Azure Bastion." Even kam247, who initially leaned toward Conditional Access, concedes that "Azure Firewall would not be used to only secure administrators access to a session host," which neatly shows why the firewall distractor fails.Official Reference
Exam Strategy
When an AZ-140 item says administrators must reach session hosts "through the Azure portal," treat that as a Bastion keyword — Bastion is the only Azure service that embeds RDP/SSH in the portal. If the requirement also mentions "no public IPs" or "no open RDP ports," it is confirming the same answer rather than pointing to a firewall or Conditional Access rule.
Frequently Asked Questions
Why isn't Conditional Access (C) enough to secure session host admin access?
Conditional Access only evaluates sign-in conditions such as MFA and device compliance; it does not provide the RDP/SSH channel to session hosts that portal-based administration requires.
Do Azure Bastion and AVD session hosts need public IP addresses?
No. Bastion connects over private IPs through the Azure portal, so session hosts can stay private with no public IPs and no inbound RDP/SSH ports open.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →