Which Users Support FSLogix Application Rule Sets on Entra Joined Hosts?

Answer Correct answer: B — Only User2, a member account synced from on-premises Active Directory, has the traditional AD SID that FSLogix application rule sets require.

You have a Microsoft Entra hybrid tenant that contains the users shown in the following table. You deploy Microsoft Entra joined Azure Virtual Desktop session hosts. Which users support the use of FSLogix application rule sets? - image

  1. User1 only
  2. User2 only Correct Answer
  3. User1 and User2 only.
  4. User1 and User3 only
  5. User1, User2, and User3

Community Votes

B
100%

100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests whether you know that FSLogix application rule sets are SID-based and therefore need on-premises AD-synced identities, not just any Entra ID object; the trap is assuming every 'member' user in the tenant qualifies.

FSLogix application rule sets (App Masking) rely on traditional Active Directory SIDs, so on Microsoft Entra joined Azure Virtual Desktop session hosts only accounts synced from on-premises AD can consume them. This page establishes why User2 — the hybrid-synced member — is the correct answer (B), while cloud-only members and guest accounts are not.

Picking option C or E by treating all three users as equivalent Entra identities, since the question never says which accounts have on-premises AD lineage — cloud-only members and B2B guests lack the traditional AD SID that app rule sets require.

Community Discussion (3 comments)

Moot2 👍 1 Selected: B
B User 2 is AD synced
barxan1 👍 1 Selected: B
Correct https://learn.microsoft.com/en-us/fslogix/concepts-fslogix-apps-rule-editor-rule-sets
jeff1988 👍 3 Selected: B
FSLogix application rule sets require users to have traditional Active Directory SIDs, which means they must be synced from an on-premises Active Directory and have line-of-sight to a domain controller. Given the information provided: User1 is a member but not synced from on-premises. User2 is a member and synced from on-premises. User3 is a guest and not synced from on-premises. Therefore, only User2 supports the use of FSLogix application rule sets.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

FSLogix application rule sets (App Masking) assign rules to users and groups by matching security identifiers, and those rules are evaluated against traditional Active Directory SIDs from an on-premises AD DS forest, not against cloud-only Entra object IDs. User2 is a member account that is synced from on-premises Active Directory via Microsoft Entra Connect, so it carries a real AD SID and can be resolved by a domain controller. User1 is a member but cloud-only, and User3 is a B2B guest, so neither has the on-premises SID lineage required. That makes B. User2 only the single correct option.

Why the Other Options Are Wrong

Option A wrongly includes User1, a cloud-only member whose identity exists only in Microsoft Entra ID and therefore has no traditional AD SID to match in a rule set. Options C and E both pull User1 or User3 into the supported set, which fails for the same SID reason — guest accounts are represented by a home-tenant object and never map to your on-premises AD SIDs. Option D swaps in User3 while still including User1, so it fails on both counts. Only option B scopes support to the one identity that is both a member and AD-synced.

Community Comment Notes

As jeff1988 explained, FSLogix application rule sets "require users to have traditional Active Directory SIDs," which means accounts must be synced from on-premises AD with line-of-sight to a domain controller — exactly the reasoning that leaves User2 as the sole eligible user. barxan1 confirmed the same conclusion and pointed to Microsoft's official rule sets documentation, and Moot2 summarized it in the phrase "User 2 is AD synced." The unanimous community alignment with option B matches the vendor behavior: identity source, not tenant membership, determines rule-set eligibility.

Review the FSLogix application rule sets requirement for traditional AD SIDs before the exam, since AZ-140 frequently tests App Masking on Entra joined host pools.

Official Reference

Exam Strategy

When an AZ-140 item shows a user table with Entra joined session hosts, immediately classify each identity by source (cloud-only member, AD-synced member, guest) before reading the options. SID-dependent FSLogix features such as application rule sets only work for AD-synced members, so eliminate answers that include cloud-only or guest accounts first.

Frequently Asked Questions

Why can't User1, a cloud-only Entra member, use FSLogix application rule sets?

Rule sets match on traditional Active Directory SIDs. A cloud-only member exists only in Microsoft Entra ID, so it has no on-premises AD SID for App Masking to evaluate, even though it is a valid member account.

Do B2B guest users like User3 get FSLogix application rule sets applied?

No. A guest identity is represented by its home-tenant object rather than a local on-premises AD SID, so application rule sets cannot resolve it on your Entra joined session hosts.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide