Microsoft AZ-140: Security, Compliance and Endpoint Protection — Study Guide

Part of the Microsoft Azure Virtual Desktop Specialty AZ-140 — Study Guide. Practice with verified answers in the Microsoft exam hub, or take timed practice tests on ExamRoll.io.

Overview

Azure Virtual Desktop (AVD) environments process corporate identities, data, and applications at scale, so security, compliance, and endpoint protection must be engineered in from image design through runtime operations and evidence collection. The key pillars are standardized onboarding to Microsoft Defender for Endpoint, posture and workload protection with Microsoft Defender for Cloud, platform hardening with encryption and trusted launch, configuration and least privilege via Microsoft Intune and Windows LAPS, governance with Azure Policy, secret and key management in Azure Key Vault, rigorous data protection, and auditable logging for investigations and attestations.

Endpoint Threat Protection with Microsoft Defender

Microsoft Defender for Endpoint (MDE) is fully supported on Windows 10/11 Enterprise multi-session and on Windows Server session hosts. Use it for endpoint detection and response (EDR), attack surface reduction (ASR), automated investigation, and threat intelligence.

Platform Hardening: Disk Encryption and Trusted Launch

Harden every session host at the virtualization layer and at rest.

Configuration, Baselines, and Least Privilege

Standardize configuration and minimize administrative blast radius.

Governance, Data Protection, and Compliance Evidence

Govern the environment end-to-end and maintain audit-ready evidence.

Practical Problem Scenario

Siemens AG must host confidential engineering applications in AVD for contractors across Europe while meeting strict data-handling and audit requirements. Key challenges include preventing data exfiltration, proving encryption and baseline compliance, onboarding EDR to multi-session hosts, and rotating local admin credentials without persistent standing access.

  1. Enforce trusted launch and encryption

    • Create a Disk Encryption Set with a Key Vault–backed CMK and require it via Azure Policy on all session host disks. Deploy Gen2 VMs with trusted launch (secure boot and vTPM) to enable measured boot and protect BitLocker keys.
    • Why: Trusted launch hardens the boot chain, while CMK ensures Siemens controls key lifecycles and can demonstrate crypto governance.
  2. Onboard Microsoft Defender for Endpoint

    • Use Intune to deploy the MDE onboarding profile and Defender Endpoint Security policies to Windows 11 Enterprise multi-session hosts. For any Windows Server utilities, enable Defender for Servers Plan 2 in Defender for Cloud for automatic MDE provisioning.
    • Why: Intune provides repeatable onboarding for client multi-session, and Plan 2 supplies EDR and advanced threat detection on any server components.
  3. Apply security baselines and ASR rules

    • Assign the Windows security baseline via Intune’s Settings Catalog, tuned for engineering apps. Enable key ASR rules and EDR in block mode with exclusions tested against CAD tools.
    • Why: Baselines standardize hardened configurations; ASR reduces exploit and macro abuse without custom signatures.
  4. Configure FSLogix and antivirus exclusions

    • Store profiles on Azure Files secured with AD-based authentication, private endpoints, and NTFS ACLs. Push Defender AV exclusions for FSLogix binaries, mount points, and VHD(X) extensions, plus SMB signing and encryption.
    • Why: Preserves logon performance and reduces I/O contention while keeping data encrypted in transit and at rest.
  5. Implement least privilege with LAPS and PIM

    • Configure Windows LAPS via Intune to rotate per-VM local admin passwords and restrict local Administrators membership through Intune policy. Use Entra Privileged Identity Management for JIT elevation to manage AVD resources and JIT VM access for any management ports.
    • Why: Eliminates standing credentials and narrows the attack surface from lateral movement or credential theft.
  6. Control data egress in sessions

    • Set AVD RDP properties to disable drive and device redirection for contractor host pools, allow clipboard as read-only, enable screen capture protection and watermarking. Use Purview DLP for Microsoft 365 Apps to prevent sensitive data exfiltration.
    • Why: Combines in-session controls with content-aware policies to stop leakage through common channels.
  7. Govern with Azure Policy and Guest Configuration

    • Assign policies requiring trusted launch, prohibiting public IPs, mandating diagnostics to Log Analytics, and restricting images to approved Shared Image Gallery definitions. Use Guest Configuration to audit BitLocker, Defender status, and local group membership.
    • Why: Ensures every host remains compliant and produces machine-verifiable evidence.
  8. Centralize logs and detection

    • Route AVD diagnostics, Windows Security, and MDE alerts to Microsoft Sentinel. Author analytics for suspicious engineering-tool child processes and anomalous data transfer. Store ADE/BitLocker key events and Policy compliance results for 1-year retention.
    • Why: Provides end-to-end visibility and long-term, queryable evidence to satisfy audits and accelerate incident response.

This approach gives Siemens hardened session hosts with provable encryption and baseline compliance, enterprise-grade EDR across client and server components, strict least-privilege controls, governed secrets and certificates, and comprehensive logging for both security operations and regulatory attestations.


Applications and End-User Experience · All domains · Monitoring

Practice these questions → · Timed practice on ExamRoll.io →

Pass the whole exam — not just this question

You found this answer. Get every verified question and explanation in one place, and save hours of prep. Free to start.

Pass your exam →

Browse Microsoft →

Related guides

All-in-one access

One subscription. Every exam.

Every plan unlocks unlimited answer search, practice tests, AI explanations, and the full resource library — in 20+ languages.

Monthly
24.87
Just €0.83/day
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

Best value
12 months
179.87
Just €0.49/daySave 40%
Everything included:
  • Unlimited answer search
  • Unlimited practice tests
  • AI-powered explanations
  • Full resource library
  • 20+ languages
  • Weekly content updates
  • Rewards & referrals
  • Priority support
Start free trial

No credit card required*

✓ Free plan included · ✓ Cancel anytime · ✓ All plans unlock the full product