Protect your Azure Virtual Desktop deployment by using Azure Firewall
Beginner
Administrator
Azure
Azure Firewall
Azure Virtual Desktop
In this module, you'll deploy Azure Firewall with a Firewall Policy, configure default and service-tag routes, and allow the endpoints that Azure Virtual Desktop session hosts require.
Learning objectives
By the end of this module, you'll be able to:
- Deploy Azure Firewall with a Firewall Policy in a hub-and-spoke network.
- Configure Azure Firewall DNS proxy for FQDN network rules.
- Configure outbound routes for an Azure Virtual Desktop session-host subnet.
- Create policy rules that allow required Azure Virtual Desktop traffic.
Prerequisites
- An Azure account with an active subscription
- Permissions to create resource groups, Azure Virtual Desktop resources and session hosts, virtual networks, a public IP address, Azure Firewall and Firewall Policy resources, and route tables
- Permission to join a session host to Microsoft Entra ID
- Access to Azure Cloud Shell
- Knowledge of networking concepts, like virtual networks, virtual network peering, subnets, and IP addressing
- Familiarity with network security concepts, like network security groups, firewalls, service tags, and user-defined routes
Get started with Azure
Choose the Azure account that's right for you. Pay as you go or try Azure free for up to 30 days. Sign up.