Azure Firewall TLS Inspection for AVD Host Pool Outbound Traffic
You have an Azure subscription that contains a virtual network named VNet1. VNet1 contains an Azure Virtual Desktop host pool named Pool1. You need to implement Azure Firewall and TLS inspection for all the outbound traffic from Pool1. Which two resources should you configure? Each correct answer present part of the solution. NOTE: Each correct answer is worth one point.
Community Insight
Tests the two resources for Azure Firewall TLS inspection—Key Vault and managed identity (enterprise app)—and the trap is forgetting the identity or adding a NAT gateway for outbound SNAT.
Azure Firewall Premium TLS inspection for an Azure Virtual Desktop host pool requires both an Azure Key Vault to store the CA certificate and a Microsoft Entra enterprise app (managed identity) to grant the firewall access to the key vault. This page confirms the correct answer is C and E, not the incomplete single-answer key.
Most candidates select only Azure Key Vault (C) or add an Azure NAT gateway (D) for outbound traffic, but TLS inspection specifically needs Key Vault and the firewall's managed identity, which appears as an enterprise app in Microsoft Entra.
Community Discussion (4 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
TLS inspection in Azure Firewall Premium requires a certificate stored in Azure Key Vault. The firewall's managed identity must be granted access to the Key Vault to retrieve the certificate, and this managed identity is represented as an enterprise application in Microsoft Entra ID. Therefore, both C (Azure Key Vault) and E (Microsoft Entra enterprise app) must be configured. The question explicitly states "Which two resources?" confirming a multi-select scenario where each answer presents part of the solution.Why the Other Options Are Wrong
A private DNS zone (A) is used for name resolution, not for TLS inspection. A private endpoint (B) provides private connectivity to PaaS services but is not required for Azure Firewall to read a certificate from Key Vault. An Azure NAT gateway (D) handles outbound SNAT but does not participate in TLS decryption or certificate management. These options distract from the two essential resources needed for the certificate-based TLS inspection workflow.Community Comment Notes
Several comments confirm Azure Key Vault as essential: as KarlosRC linked to a guide for issuing TLS certificates for Azure Firewall, and as manhattan pointed to a Microsoft Tech Community blog describing the auto-generation of managed identity, Key Vault, and a self-signed root CA certificate. maciek8131 suggested adding NAT gateway for outbound traffic, but that conflates SNAT with TLS inspection. The consensus for C is correct, but the second resource (managed identity as enterprise app) is often overlooked.Official Reference
Exam Strategy
When a question asks for two resources, never settle for a single answer even if the suggested key is one letter. For Azure Firewall Premium features, always think certificate (Key Vault) plus identity (managed identity/enterprise app).
Frequently Asked Questions
Why is an Azure NAT gateway not required for TLS inspection?
Azure Firewall provides its own SNAT for outbound traffic; a NAT gateway is used for outbound connectivity when not routing through a firewall, not for TLS decryption.
Why does TLS inspection need a Microsoft Entra enterprise app?
The firewall's managed identity is represented as an enterprise application; granting it access to the Key Vault certificate is required for TLS inspection.
Related Analysis
Practice All AZ-700 Questions
Access 100 questions with complete answers and detailed explanations.
View Full AZ-700 Practice Test →