New session hosts show a Not Registered status. The environment uses custom DNS servers, outbound internet is restricted through a web proxy that performs TLS inspection, and you are not using Private Link. Which two checks or actions should you perform to resolve registration? (Select two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Allow the session hosts to reach the WindowsVirtualDesktop service over TCP 443 without SSL inspection., Configure the session hosts to use DNS servers that can resolve wvd.microsoft.com and related Azure endpoints..
Why this is the answer
The Azure Virtual Desktop (AVD) agent on session hosts needs to communicate with the AVD control plane over TCP 443. When a web proxy performs TLS inspection, it often breaks this communication, leading to a "Not Registered" status. Bypassing SSL inspection for the AVD service ensures the agent can establish a secure connection. Additionally, the AVD agent must resolve Azure endpoints like wvd.microsoft.com to register and function correctly. Custom DNS servers must be configured to successfully resolve these FQDNs. Opening inbound TCP 3389 is incorrect as AVD uses reverse connect, not direct inbound connections from the internet. Assigning static public IPs is unnecessary for outbound internet access and doesn't address registration issues. Azure Cosmos DB service endpoints are unrelated to AVD session host registration.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed