Users running RemoteApp App1 can launch arbitrary executables from the Save As dialog on session hosts. To restrict users so they can run only published applications, what should you implement?
Choose an answer
Tap an option to check your answer.
Correct answer: Configure an AppLocker policy on the session hosts..
Why this is the answer
AppLocker is a security feature in Windows that allows administrators to control which applications users can run. By configuring an AppLocker policy on the session hosts, you can create rules to explicitly allow only the published applications to execute, thereby preventing users from launching arbitrary executables through methods like the "Save As" dialog. Conditional Access policies in Azure AD control access to resources based on conditions like user, device, or location, but they don't restrict what applications can run within a session. Modifying Access control (IAM) settings on the host pool manages who can administer the host pool, not what applications users can run on the session hosts. RDP Properties of the host pool configure RDP client settings and redirection, not application execution restrictions.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed