QuestionQ227
Plan and implement identity and securityCase study —
This case study is not timed separately. You may use as much of the exam time as needed to complete each case. However, this exam might include additional case studies and sections. You must manage your time so that you can complete every question on the exam within the allotted time.
To answer the questions in a case study, you must refer to the information provided in that case study. Case studies can include exhibits and other resources that provide additional details about the scenario described. Each question in this case study is independent of the others.
At the end of this case study, a review screen will appear. This screen lets you review and change your answers before moving to the next exam section. After you start a new section, you cannot return to this section.
To begin the case study —
To show the first question in this case study, select the Next button. Use the buttons in the left pane to review the case-study content before answering the questions. Selecting these buttons displays information such as business requirements, the existing environment, and problem statements. If the case study includes an All Information tab, the information shown there is identical to that shown on the later tabs. When you are ready to answer a question, select the Question button to return to it.
Overview —
Northwind Traders is a manufacturing company headquartered in New York City.
Existing Environment —
Identity Environment —
The on-premises network has an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain synchronizes with the Microsoft Entra tenant.
Virtual Machines —
The company has an on-premises Hyper-V virtual machine named VM1 with the following configuration:
- Generation: 1
- Disk size: 2 TB
- Disk format: VHDX
- Disk type: Dynamically expanding
Cloud Services —
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users, each assigned a Microsoft 365 E5 license.
The company also has an Azure subscription containing the resources shown in the following table.

Both subscriptions are linked to the Microsoft Entra tenant.
Requirements —
Planned Changes —
Northwind Traders identifies these planned changes:
- Deploy an Azure Virtual Desktop host pool containing 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
- Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
- Provide access to a custom app named App1 through the Azure Virtual Desktop deployment.
Performance Requirements —
Northwind Traders identifies the following performance requirements:
- Every Azure Virtual Desktop session host must support 15 user sessions.
- Each new user session must be assigned to one session host until that host reaches its maximum session limit.
Application Requirements —
Northwind Traders identifies the following application requirements:
- Microsoft OneDrive must open when users connect to an Azure Virtual Desktop RemoteApp session.
- App1 requires a desktop resolution of 1280 x 1024.
- Administrative effort must be minimized.
Disaster Recovery Requirements —
Northwind Traders identifies these disaster recovery requirements for the Azure Virtual Desktop deployment:
- Minimize outages when an Azure region fails.
- Minimize the recovery time objective (RTO).
- Minimize administrative effort during a failover.
Security Requirements —
Northwind Traders identifies the following security requirements:
- When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate using only their Microsoft Entra username and password.
- When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
- Every Azure Virtual Desktop session host deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
- The client version and operating system used to connect to the session hosts must be logged.
- The solution must adhere to the principle of least privilege.
Networking Requirements —
The Azure Virtual Desktop session hosts must be able to access resources on the on-premises network.
User Profile Requirements —
Northwind Traders identifies the following user profile requirements:
- Users must be able to access share1 by using their Microsoft Entra account.
- Azure Virtual Desktop user profiles must be managed by using FSLogix.
- All user profiles must be stored in share1.
Which two actions should you take to meet the Defender for Endpoint security requirements? Each correct answer provides a complete solution.
NOTE: Each correct selection is worth one point.
- A Add a Defender for Endpoint onboarding script to VM1 and run the script at first startup.
- B Use a Group Policy Object (GPO) to run an on boarding script from a shared location.
- C Create an app attach image for the Azure Virtual Desktop deployment.
- D Run a Defender for Endpoint onboarding script on VM1 before generalizing the VM1 source image.
Community Discussion