You need to ensure every current and future virtual machine in resource group RG-AVD used for Azure Virtual Desktop session hosts has a system-assigned managed identity enabled and carries the tags Role=AVD and Environment=Prod. Enforcement must auto-remediate existing noncompliant VMs. What should you do?
Choose an answer
Tap an option to check your answer.
Correct answer: Assign built-in Azure Policy definitions that deploy a system-assigned managed identity on virtual machines (DeployIfNotExists) and append the required tags, then run remediation tasks on RG-AVD..
Why this is the answer
The correct answer is to assign built-in Azure Policy definitions and run remediation tasks. Azure Policy is designed for enforcing organizational standards and assessing compliance at scale. The DeployIfNotExists effect can automatically enable system-assigned managed identities and append required tags to non-compliant resources, including existing ones through remediation tasks. This ensures both current and future VMs meet the requirements. Using Azure Blueprints is not suitable because it focuses on deploying and managing environments, not continuous enforcement and auto-remediation of specific resource properties like managed identities or tags on existing resources. An Azure Automation runbook could add identities and tags, but it's a reactive, scheduled script and lacks the continuous enforcement and auto-remediation capabilities of Azure Policy. Relying on ARM templates and developer adherence is a manual, human-dependent process that doesn't guarantee compliance for existing resources or prevent future deviations.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed