Your company runs Azure Virtual Desktop with pooled Windows 11 Enterprise multi-session session hosts across three subscriptions. Security requires all existing and newly created session hosts to be onboarded to Microsoft Defender for Endpoint automatically at deployment time without modifying the golden image or running post-logon scripts. What should you configure?
Choose an answer
Tap an option to check your answer.
Correct answer: In Microsoft Defender for Cloud, enable auto-provisioning of the Microsoft Defender for Endpoint sensor for the subscriptions..
Why this is the answer
Enabling auto-provisioning of the Microsoft Defender for Endpoint sensor in Microsoft Defender for Cloud is the correct solution. This feature automatically deploys the Defender for Endpoint agent to all new and existing supported VMs within the specified subscriptions, including Azure Virtual Desktop session hosts, without requiring modifications to the golden image or post-logon scripts. Assigning an onboarding package in Microsoft Intune is incorrect because Intune is primarily for device management and may not seamlessly integrate with Azure Virtual Desktop session host deployment for automatic onboarding without additional configuration. Installing the Azure Monitor agent and connecting to Log Analytics is for monitoring and logging, not for onboarding to Defender for Endpoint. Creating a Group Policy Object would require modifying the golden image or running scripts, which the requirement explicitly forbids.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed