QuestionQ99

Plan and implement identity and security

Your on-premises network contains an Active Directory Domain Services (AD DS) domain called contoso.com.

You have an Azure subscription linked to a Microsoft Entra tenant named contoso.onmicrosoft.com. Contoso.com synchronizes with contoso.onmicrosoft.com.

You have a partner company with a Microsoft Entra tenant named fabrikam.com.

Contoso.onmicrosoft.com contains the resources shown in the following table.

Question Image

You deploy an Azure Virtual Desktop host pool named Pool1. Pool1 has 10 session hosts joined to Contoso.com.

You assign Group1 to the application group in Pool1.

You need to identify the users who will be able to sign in to the session hosts in Pool1.

Which users should you identify?

  • A User1 only
  • B User1 and User2 only
  • C User1 and User3 only
  • D User1, User2, and User3
Explanation

An AD DS-joined Azure Virtual Desktop session host requires a corresponding AD DS user account for the Windows session sign-in. A synchronized hybrid identity satisfies that requirement, so User1 can sign in. Cloud-only identities are supported when session hosts are Microsoft Entra joined, and external identities likewise require Microsoft Entra-joined session hosts with additional configuration; neither condition applies here.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!