You must deploy session hosts to a subnet with no network line-of-sight to domain controllers. Users are cloud-only Microsoft Entra ID accounts. You want the VMs to join during provisioning without any on-premises dependencies. What should you configure during deployment?
Choose an answer
Tap an option to check your answer.
Correct answer: Choose Microsoft Entra ID as the domain to join and assign a user-assigned managed identity to the VMs during creation.
Why this is the answer
For cloud-only Microsoft Entra ID accounts and no line-of-sight to on-premises domain controllers, joining directly to Microsoft Entra ID is the correct approach. Assigning a user-assigned managed identity to the VMs during creation allows the Azure Virtual Desktop service to perform the Microsoft Entra join operation on behalf of the VMs securely and automatically, without requiring manual intervention or storing credentials. Choosing Active Directory is incorrect because there's no network connectivity to on-premises domain controllers. Skipping domain join and using a post-deployment script for hybrid-join is unnecessary and more complex when a direct Microsoft Entra join is available and preferred for cloud-only users. Deploying Azure AD DS is also unnecessary as the requirement specifies cloud-only Microsoft Entra ID accounts, not a need for traditional domain services.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed