QuestionQ123

Plan and implement identity and security

Your network includes an on-premises Active Directory domain named contoso.com that synchronizes with an Azure Active Directory (Azure AD) tenant.

You have an Azure Virtual Desktop host pool named Pool1 with these settings:

  • Host pool name: Pool1
  • Host pool type: Personal
  • Load balancing algorithm: Breadth-first

Number of VMs: 3 -

Question Image

The session hosts have the following configurations:

  • Image used to create the virtual machines: Windows 10 Enterprise
  • Virtual machines domain-joined to: On-premises contoso.com domain

You need to ensure that Microsoft EndPoint Manager can be used to manage security updates on the session hosts.

What should you do?

  • A Create Windows 10 Enterprise multi-session images
  • B Configure the session hosts as hybrid Azure AD-joined
  • C Change Host pool type to Pooled
  • D Change Load balancing algorithm to Depth-first
Explanation

Microsoft Intune, included in Microsoft Endpoint Manager, manages Azure Virtual Desktop session hosts that are Microsoft Entra joined or Microsoft Entra hybrid joined. Session hosts joined to an on-premises AD DS domain require Microsoft Entra hybrid join to be managed by Intune, including for security update management.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!