Protect your Azure Virtual Desktop deployment by using Azure Firewall

Beginner
Administrator
Azure
Azure Firewall
Azure Virtual Desktop

In this module, you'll deploy Azure Firewall with a Firewall Policy, configure default and service-tag routes, and allow the endpoints that Azure Virtual Desktop session hosts require.

Learning objectives

By the end of this module, you'll be able to:

  • Deploy Azure Firewall with a Firewall Policy in a hub-and-spoke network.
  • Configure Azure Firewall DNS proxy for FQDN network rules.
  • Configure outbound routes for an Azure Virtual Desktop session-host subnet.
  • Create policy rules that allow required Azure Virtual Desktop traffic.

Prerequisites

  • An Azure account with an active subscription
  • Permissions to create resource groups, Azure Virtual Desktop resources and session hosts, virtual networks, a public IP address, Azure Firewall and Firewall Policy resources, and route tables
  • Permission to join a session host to Microsoft Entra ID
  • Access to Azure Cloud Shell
  • Knowledge of networking concepts, like virtual networks, virtual network peering, subnets, and IP addressing
  • Familiarity with network security concepts, like network security groups, firewalls, service tags, and user-defined routes

Get started with Azure

Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.