QuestionQ69
Plan and implement identity and securityYou have an on-premises root certification authority (CA) named AdatumCA.
You have an Azure subscription containing an Azure Virtual Desktop deployment. The subscription is linked to a Microsoft Entra tenant that contains the users shown in the following table.

All users have permission to connect to the Azure Virtual Desktop deployment and have certificates issued by AdatumCA installed on their devices.
You create a Conditional Access policy named CAPolicy1 with these settings:
- Assignments
- Users: Group 1
- Target resources: Azure Virtual Desktop
- Access controls
- Grant: Require multifactor authentication
- Enable policy: On
The certificate-based authentication method policy's Enable and Target settings are shown in the following exhibit.

The certificate-based authentication method policy's Configure settings are shown in the following exhibit.

For each of the following statements, select Yes if the statement is true. Otherwise, select No.
| Statements | Yes | No |
|---|---|---|
| User1 can authenticate to Azure Virtual Desktop session hosts without providing a password. | ||
| When connecting to an Azure Virtual Desktop session host, User2 can authenticate by using a certificate or a smart card. | ||
| When connecting to an Azure Virtual Desktop session host, User3 must use a certificate to authenticate. |
Community Discussion