First Step for AVD Reauthentication in New Subscription
You have a new Azure subscription that uses Azure Virtual Desktop. You need to ensure that users who connect to Azure Virtual Desktop sessions reauthenticate every six hours. What should you do first?
Community Votes
60% of anonymous learners picked answer A. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
This question tests the prerequisite dependency between Conditional Access and Security Defaults in new Azure tenants, trapping learners who skip straight to creating the policy.
In a new Azure subscription, Entra ID Security Defaults are enabled by default, which blocks the creation of Conditional Access policies. This page establishes that disabling Security Defaults is the mandatory first step to configure custom sign-in frequency for Azure Virtual Desktop.
Choosing to create a Conditional Access policy because it directly controls sign-in frequency, while ignoring that Security Defaults must be disabled first in a new tenant.
Community Discussion (9 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
In a new Azure subscription, Entra ID Security Defaults are automatically enabled to provide baseline security. Security Defaults and Conditional Access policies are mutually exclusive; you cannot create a Conditional Access policy while Security Defaults are active. Therefore, before you can configure a six-hour sign-in frequency using Conditional Access, you must first disable Security Defaults.Why the Other Options Are Wrong
Creating a Conditional Access policy (Option A) is the mechanism to set the six-hour reauthentication interval, but it will fail if Security Defaults are still enabled. Configuring an authentication methods policy (Option C) or MFA (Option D) does not control session sign-in frequency and does not address the prerequisite blocker of Security Defaults in a new tenant.Community Comment Notes
Several community members pointed out this dependency, noting that "Security Defaults are enabled on new Azure subscriptions by default and must be disabled before Conditional Access policies can be used." Others recognized the wording trap, stating "It's a trick question... asks what should be done first" and emphasizing that disabling Security Defaults is universally required for new tenants before custom policies can be applied.Official Reference
Exam Strategy
Pay close attention to keywords like "new Azure subscription" which imply default configurations. Remember that Security Defaults block Conditional Access, so disabling them is always the prerequisite step in new tenants before configuring custom sign-in frequencies.
Related Analysis
Practice All AZ-140 Questions
Access 64 questions with complete answers and detailed explanations.
View Full AZ-140 Practice Test →