You need to automatically grant Azure Virtual Desktop access to any new employee whose department attribute equals Finance. The application group is named Finance-Apps. You want to avoid manual user assignments. Which two configurations should you implement? (Each correct answer presents part of the solution. Choose two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Create a dynamic Microsoft Entra security group with a membership rule that evaluates user.department equals "Finance"., Assign the dynamic security group to the Finance-Apps application group using the Desktop Virtualization User role..
Why this is the answer
To automatically grant access based on a user attribute like department, you need a dynamic Microsoft Entra security group. This group's membership rule (user.department equals "Finance") will automatically add or remove users as their department attribute changes, eliminating manual assignments. Then, assign this dynamic security group directly to the Finance-Apps application group. The Desktop Virtualization User role provides the necessary permissions for users to access applications within that application group. Assigning to the host pool or making the group a co-owner of the workspace are incorrect as they don't directly grant application access. A dynamic device group is irrelevant for user access.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed