First Step for AVD Reauthentication in New Subscription

Answer Correct answer: B — Disable Security defaults to allow the creation of a Conditional Access policy for reauthentication.

You have a new Azure subscription that uses Azure Virtual Desktop. You need to ensure that users who connect to Azure Virtual Desktop sessions reauthenticate every six hours. What should you do first?

  1. Create a Conditional Access policy.
  2. Disable Security defaults. Correct Answer
  3. Configure an authentication methods policy.
  4. Configure multi-factor authentication (MFA).

Community Votes

A
60%
B
40%

60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests the prerequisite dependency between Conditional Access and Security Defaults in new Azure tenants, trapping learners who skip straight to creating the policy.

In a new Azure subscription, Entra ID Security Defaults are enabled by default, which blocks the creation of Conditional Access policies. This page establishes that disabling Security Defaults is the mandatory first step to configure custom sign-in frequency for Azure Virtual Desktop.

Choosing to create a Conditional Access policy because it directly controls sign-in frequency, while ignoring that Security Defaults must be disabled first in a new tenant.

Community Discussion (9 comments)

barxan1 👍 5
First of all we should disable security defaults, then we can create a condition access policy and only after that we can configure MFA
AITANA_MANAGEMENT 👍 1 Selected: B
It's a trick question, in my opinion. If you look closely, it asks what should be done first. Keep in mind that we don't know if the tenant has Entra ID P1, so we can't be sure if Conditional Access (CA) can be configured. However, what is universally true is that by default, all new tenants have Security Defaults enabled. So, the first step should be to disable Security Defaults, and the second step would be to configure Conditional Access.
hwoccurrence 👍 1 Selected: A
Conditional Access is what lets you set a custom sign‐in frequency (e.g., every six hours). Even though in a brand‐new tenant you often must disable Security Defaults first to create any custom Conditional Access policy, the exam (and Microsoft documentation) typically views “Create a Conditional Access policy” as your first major configuration step for sign‐in frequency. So while real‐world practice often includes disabling Security Defaults before advanced Conditional Access, the standard (and correct) exam answer to achieve six‐hour reauthentication is: A. Create a Conditional Access policy
brucespr 👍 1 Selected: B
If your tenant was created on or after October 22, 2019, security defaults might be enabled in your tenant. To protect all of our users, security defaults are being rolled out to all new tenants at creation. Organizations that choose to implement Conditional Access policies that replace security defaults must disable security defaults. https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
ClintC03 👍 2 Selected: B
Security Defaults are enabled on new Azure subscriptions by default and must be disabled before Conditional Access policies can be used. https://learn.microsoft.com/en-us/entra/fundamentals/security-defaults
jeff1988 👍 2 Selected: A
A. Create a Conditional Access policy. Conditional Access policies allow you to set the sign-in frequency, which can be configured to require reauthentication every six hours. This approach ensures that users are prompted to reauthenticate at the specified interval, enhancing security.
lopt0909 👍 1 Selected: A
create condition access policy first and then config MFA
Bonifacef 👍 1 Selected: D
Correct
Darkphoenix126 👍 2 Selected: A
Should be A

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

In a new Azure subscription, Entra ID Security Defaults are automatically enabled to provide baseline security. Security Defaults and Conditional Access policies are mutually exclusive; you cannot create a Conditional Access policy while Security Defaults are active. Therefore, before you can configure a six-hour sign-in frequency using Conditional Access, you must first disable Security Defaults.

Why the Other Options Are Wrong

Creating a Conditional Access policy (Option A) is the mechanism to set the six-hour reauthentication interval, but it will fail if Security Defaults are still enabled. Configuring an authentication methods policy (Option C) or MFA (Option D) does not control session sign-in frequency and does not address the prerequisite blocker of Security Defaults in a new tenant.

Community Comment Notes

Several community members pointed out this dependency, noting that "Security Defaults are enabled on new Azure subscriptions by default and must be disabled before Conditional Access policies can be used." Others recognized the wording trap, stating "It's a trick question... asks what should be done first" and emphasizing that disabling Security Defaults is universally required for new tenants before custom policies can be applied.

Official Reference

Exam Strategy

Pay close attention to keywords like "new Azure subscription" which imply default configurations. Remember that Security Defaults block Conditional Access, so disabling them is always the prerequisite step in new tenants before configuring custom sign-in frequencies.

Related Analysis

Practice All AZ-140 Questions

Access 64 questions with complete answers and detailed explanations.

View Full AZ-140 Practice Test →

← Back to AZ-140 Study Guide