This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Why should a route table on an Azure Virtual Desktop session-host subnet include a WindowsVirtualDesktop service-tag route with Internet as the next hop?
To provide direct access to the Azure Virtual Desktop gateway and broker and avoid disconnections during firewall scale-in.
To send all session-host internet traffic directly to the internet.
To make application rules in the Firewall Policy unnecessary.
Which deployment matches the hub-and-spoke design used to protect the Azure Virtual Desktop session hosts?
Deploy Azure Firewall with a Firewall Policy in a hub virtual network, and peer it with the session-host virtual network.
Deploy Azure Firewall in the session-host subnet, and assign a public IP address to each session host.
Deploy separate firewalls on each session host, and manage them without a Firewall Policy.
Why should the session-host virtual network use the Azure Firewall private IP address as its DNS server when Firewall Policy contains FQDN network rules?
So the session hosts and Azure Firewall use the same DNS responses when the firewall evaluates FQDN network rules.
So all Azure Virtual Desktop gateway and broker traffic is inspected by the firewall.
So application rules can filter non-HTTP protocols without a network rule.
Which rule configuration allows required Azure Virtual Desktop web endpoints while keeping other outbound destinations denied?
Use application rules for the WindowsVirtualDesktop FQDN tag and the required supporting and certificate-validation FQDNs.
Use only a WindowsVirtualDesktop service-tag route with Internet as the next hop.
Use a NAT rule to translate inbound traffic to each session host.
You must answer all questions before checking your work.
Was this page helpful?
Need help with this topic?
Want to try using Ask Learn to clarify or guide you through this topic?