Which Users Support FSLogix Application Rule Sets on Entra Joined Hosts?
You have a Microsoft Entra hybrid tenant that contains the users shown in the following table. You deploy Microsoft Entra joined Azure Virtual Desktop session hosts. Which users support the use of FSLogix application rule sets? - 
Community Votes
100% of anonymous learners picked answer B. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests whether you know that FSLogix application rule sets are SID-based and therefore need on-premises AD-synced identities, not just any Entra ID object; the trap is assuming every 'member' user in the tenant qualifies.
FSLogix application rule sets (App Masking) rely on traditional Active Directory SIDs, so on Microsoft Entra joined Azure Virtual Desktop session hosts only accounts synced from on-premises AD can consume them. This page establishes why User2 — the hybrid-synced member — is the correct answer (B), while cloud-only members and guest accounts are not.
Picking option C or E by treating all three users as equivalent Entra identities, since the question never says which accounts have on-premises AD lineage — cloud-only members and B2B guests lack the traditional AD SID that app rule sets require.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
FSLogix application rule sets (App Masking) assign rules to users and groups by matching security identifiers, and those rules are evaluated against traditional Active Directory SIDs from an on-premises AD DS forest, not against cloud-only Entra object IDs. User2 is a member account that is synced from on-premises Active Directory via Microsoft Entra Connect, so it carries a real AD SID and can be resolved by a domain controller. User1 is a member but cloud-only, and User3 is a B2B guest, so neither has the on-premises SID lineage required. That makes B. User2 only the single correct option.Why the Other Options Are Wrong
Option A wrongly includes User1, a cloud-only member whose identity exists only in Microsoft Entra ID and therefore has no traditional AD SID to match in a rule set. Options C and E both pull User1 or User3 into the supported set, which fails for the same SID reason — guest accounts are represented by a home-tenant object and never map to your on-premises AD SIDs. Option D swaps in User3 while still including User1, so it fails on both counts. Only option B scopes support to the one identity that is both a member and AD-synced.Community Comment Notes
As jeff1988 explained, FSLogix application rule sets "require users to have traditional Active Directory SIDs," which means accounts must be synced from on-premises AD with line-of-sight to a domain controller — exactly the reasoning that leaves User2 as the sole eligible user. barxan1 confirmed the same conclusion and pointed to Microsoft's official rule sets documentation, and Moot2 summarized it in the phrase "User 2 is AD synced." The unanimous community alignment with option B matches the vendor behavior: identity source, not tenant membership, determines rule-set eligibility.Review the FSLogix application rule sets requirement for traditional AD SIDs before the exam, since AZ-140 frequently tests App Masking on Entra joined host pools.
Official Reference
Exam Strategy
When an AZ-140 item shows a user table with Entra joined session hosts, immediately classify each identity by source (cloud-only member, AD-synced member, guest) before reading the options. SID-dependent FSLogix features such as application rule sets only work for AD-synced members, so eliminate answers that include cloud-only or guest accounts first.
Frequently Asked Questions
Why can't User1, a cloud-only Entra member, use FSLogix application rule sets?
Rule sets match on traditional Active Directory SIDs. A cloud-only member exists only in Microsoft Entra ID, so it has no on-premises AD SID for App Masking to evaluate, even though it is a valid member account.
Do B2B guest users like User3 get FSLogix application rule sets applied?
No. A guest identity is represented by its home-tenant object rather than a local on-premises AD SID, so application rule sets cannot resolve it on your Entra joined session hosts.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →