You enabled Private Link for Azure Virtual Desktop by creating private endpoints in a hub virtual network. Session hosts reside in a spoke virtual network and use on‑premises DNS servers via a site‑to‑site VPN. Session hosts fail to register. What should you configure to ensure the session hosts resolve the Azure Virtual Desktop service to private IPs? (Select two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a Private DNS zone named privatelink.wvd.microsoft.com in Azure and link it to the hub and spoke virtual networks., On the on‑premises DNS servers, add a conditional forwarder for privatelink.wvd.microsoft.com to the Azure DNS Private Resolver inbound endpoint..
Why this is the answer
When using Private Link for Azure Virtual Desktop, session hosts need to resolve the private FQDNs (e.g., privatelink.wvd.microsoft.com) to the private IP addresses of the private endpoints. 1. Create a Private DNS zone named privatelink.wvd.microsoft.com in Azure and link it to the hub and spoke virtual networks: This step is crucial because it provides the authoritative DNS resolution for the private FQDNs within your Azure environment. Linking it to both the hub (where private endpoints are) and spoke (where session hosts are) ensures that VMs in both networks can query this zone. 2. On the on-premises DNS servers, add a conditional forwarder for privatelink.wvd.microsoft.com to the Azure DNS Private Resolver inbound endpoint: Since session hosts use on-premises DNS servers, these servers need a way to resolve the Azure Private Link FQDNs. A conditional forwarder tells the on-premises DNS servers to send queries for privatelink.wvd.microsoft.com to the Azure DNS Private Resolver, which can then query the linked Private DNS zone. Incorrect options: Adding an Azure Firewall DNAT rule is for network address translation, not DNS resolution. Creating a service endpoint for Microsoft.Web is irrelevant to Azure Virtual Desktop Private Link DNS. Pointing session hosts to 8.8.8.8 (Google Public DNS) would prevent resolution of private IP addresses for Azure resources.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed