A host pool contains ten session host VMs. You need to grant a pilot user group access to those VMs. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Create a role assignment..
Why this is the answer
To grant users access to Azure Virtual Desktop session hosts, you must create a role assignment. This links a security principal (the pilot user group), a role definition (like "Desktop Virtualization User"), and a scope (the host pool or application group). The "Desktop Virtualization User" role specifically allows users to connect to session hosts within a host pool. Creating a role definition is incorrect because existing built-in roles are sufficient for this purpose; you don't need to define a new one. Adding users to the Remote Desktop Users group on the VMs is incorrect because Azure Virtual Desktop manages user access through Azure RBAC, not directly through local VM groups. While the Remote Desktop Users group is involved in the underlying RDP connection, the AVD service handles the authorization layer. Adding users to the local Administrators group is incorrect and a security risk, as it grants excessive permissions beyond just connecting to the desktop.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed