Azure Firewall TLS Inspection for AVD Host Pool Outbound Traffic

Design and implement Azure Firewall and Azure Firewall Manager
Answer Correct answer: C, E — Configure an Azure Key Vault for the CA certificate and a Microsoft Entra enterprise app (managed identity) to let Azure Firewall access it.

You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an Azure Virtual Desktop host pool named Pool1. You need to implement Azure Firewall and TLS inspection for all the outbound traffic from Pool1. Which two resources should you configure? Each correct answer present part of the solution. NOTE: Each correct answer is worth one point.

  1. an Azure Private DNS zone
  2. a private endpoint
  3. an Azure key vault Correct Answer
  4. an Azure NAT gateway
  5. a Microsoft Entra enterprise app Correct Answer

Community Insight

Tests the two resources for Azure Firewall TLS inspection—Key Vault and managed identity (enterprise app)—and the trap is forgetting the identity or adding a NAT gateway for outbound SNAT.

Azure Firewall Premium TLS inspection for an Azure Virtual Desktop host pool requires both an Azure Key Vault to store the CA certificate and a Microsoft Entra enterprise app (managed identity) to grant the firewall access to the key vault. This page confirms the correct answer is C and E, not the incomplete single-answer key.

Most candidates select only Azure Key Vault (C) or add an Azure NAT gateway (D) for outbound traffic, but TLS inspection specifically needs Key Vault and the firewall's managed identity, which appears as an enterprise app in Microsoft Entra.

Community Discussion (4 comments)

KarlosRC 👍 9 Selected: C
https://www.keytos.io/docs/azure-pki/azure-certificate-management/how-to-issue-tls-certificates-for-azure-firewall/
PL5423232909 👍 1 Selected: C
Correct.
manhattan 👍 3 Selected: C
it should be correct https://techcommunity.microsoft.com/blog/azurenetworksecurityblog/building-a-poc-for-tls-inspection-in-azure-firewall/3676723 ransport Layer Security (TLS) Inspection feature of Azure Firewall Premium by using the Certification Auto-Generation mechanism, which automatically creates the following three resources for you: Managed Identity Key Vault Self-signed Root CA certificate
maciek8131 👍 2 Selected: CD
I think that we need NAT for that if that's outbound

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

TLS inspection in Azure Firewall Premium requires a certificate stored in Azure Key Vault. The firewall's managed identity must be granted access to the Key Vault to retrieve the certificate, and this managed identity is represented as an enterprise application in Microsoft Entra ID. Therefore, both C (Azure Key Vault) and E (Microsoft Entra enterprise app) must be configured. The question explicitly states "Which two resources?" confirming a multi-select scenario where each answer presents part of the solution.

Why the Other Options Are Wrong

A private DNS zone (A) is used for name resolution, not for TLS inspection. A private endpoint (B) provides private connectivity to PaaS services but is not required for Azure Firewall to read a certificate from Key Vault. An Azure NAT gateway (D) handles outbound SNAT but does not participate in TLS decryption or certificate management. These options distract from the two essential resources needed for the certificate-based TLS inspection workflow.

Community Comment Notes

Several comments confirm Azure Key Vault as essential: as KarlosRC linked to a guide for issuing TLS certificates for Azure Firewall, and as manhattan pointed to a Microsoft Tech Community blog describing the auto-generation of managed identity, Key Vault, and a self-signed root CA certificate. maciek8131 suggested adding NAT gateway for outbound traffic, but that conflates SNAT with TLS inspection. The consensus for C is correct, but the second resource (managed identity as enterprise app) is often overlooked.

Official Reference

Exam Strategy

When a question asks for two resources, never settle for a single answer even if the suggested key is one letter. For Azure Firewall Premium features, always think certificate (Key Vault) plus identity (managed identity/enterprise app).

Frequently Asked Questions

Why is an Azure NAT gateway not required for TLS inspection?

Azure Firewall provides its own SNAT for outbound traffic; a NAT gateway is used for outbound connectivity when not routing through a firewall, not for TLS decryption.

Why does TLS inspection need a Microsoft Entra enterprise app?

The firewall's managed identity is represented as an enterprise application; granting it access to the Key Vault certificate is required for TLS inspection.

Related Analysis

Practice All AZ-700 Questions

Access 100 questions with complete answers and detailed explanations.

View Full AZ-700 Practice Test →

← Back to AZ-700 Study Guide