Your security team blocks all unsolicited inbound traffic to session hosts and plans to deny general internet egress. Users must connect to Azure Virtual Desktop without exposing RDP on the public internet. Which two configurations enable connectivity while honoring these constraints? (Select two answers.)
Choose an answer
Tap an option to check your answer.
Correct answer: Allow outbound TCP 443 to the WindowsVirtualDesktop service tag and deny inbound 3389 on session hosts., Enable Private Link for Azure Virtual Desktop and configure private DNS so session hosts resolve the AVD service to private IPs..
Why this is the answer
The core requirement is to prevent public RDP exposure and deny general internet egress while allowing AVD connectivity. Allowing outbound TCP 443 to the WindowsVirtualDesktop service tag is crucial. AVD session hosts initiate outbound connections over 443 to the AVD control plane. Denying inbound 3389 prevents public RDP exposure. Enabling Private Link for AVD and configuring private DNS allows session hosts to communicate with the AVD control plane over a private endpoint within your virtual network, eliminating the need for general internet egress for AVD service communication. Assigning public IPs and opening inbound 3389, even from a corporate WAN, exposes RDP publicly. Azure Bastion is for administrative access to VMs, not for end-user AVD connections. RDP Shortpath optimizes RDP traffic but doesn't address the fundamental connectivity or egress requirements without outbound internet.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed