Your Azure Virtual Desktop host pool is on a virtual network connected to on-premises via site-to-site VPN. To ensure only on-premises users can access the managed AVD resources with minimal administrative effort, what should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: A conditional access policy.
Why this is the answer
A conditional access policy is the correct choice because it allows you to enforce access controls based on conditions such as user location (e.g., on-premises IP ranges). This directly addresses the requirement to restrict access to on-premises users with minimal administrative effort, as it integrates with Azure Active Directory (now Microsoft Entra ID) for user authentication. An Azure Firewall rule would control network traffic but doesn't inherently verify user identity or location in the same granular way for AVD session host access. A Network Security Group (NSG) rule operates at the network interface or subnet level, controlling inbound/outbound traffic based on IP addresses and ports, but doesn't provide user-centric access control. A user-defined route (UDR) influences traffic forwarding paths and is unrelated to access control based on user location.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed