Exam AZ-140 Topic 2 Question 138 Discussion
Actual exam question for Microsoft's AZ-140 exam
Question #: 138
Topic #: 2
Question #: 138
Topic #: 2
Case Study 3 - Northwind Traders
Overview
Northwind Traders is a manufacturing company based in New York City.
Existing Environment
Identity Environment
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
- Generation: 1
- Disk size: 2 TB
- Disk format: VHDX
- Disk type: Dynamically expanding
Cloud Services
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.

Both subscriptions are linked to the Microsoft Entra tenant.
Requirements
Planned Changes
Northwind Traders identifies the following planned changes:
- Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
- Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
- The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements
Northwind Traders identifies the following performance requirements:
- Each Azure Virtual Desktop session host must support 15 user sessions.
- Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements
Northwind Traders identifies the following application requirements:
- Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
- App1 requires a desktop resolution of 1280 x 1024.
- Administrative effort must be minimized.
Disaster Recovery Requirements
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
- Minimize outages if an Azure region fails.
- Minimize the recovery time objective (RTO).
- Minimize administrative effort in the event of a failover.
Security Requirements
Northwind Traders identifies the following security requirements:
- When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
- When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
- All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
- The client version and operating system used to connect to the session hosts must be logged.
- The solution must follow the principle of least privilege.
Networking Requirements
The Azure Virtual Desktop session hosts must be able to access the resources on the on- premises network.
User Profile Requirements
Northwind Traders identifies the following user profile requirements:
- Users must be able to access share1 by using their Microsoft Entra account.
- Azure Virtual Desktop user profiles must be managed by using FSLogix.
- All user profiles must be stored in share1.
Which two actions should you perform to meet the security requirements for Defender for Endpoint? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Overview
Northwind Traders is a manufacturing company based in New York City.
Existing Environment
Identity Environment
The on-premises network contains an Active Directory Domain Services (AD DS) domain named northwindtraders.com.
Northwind Traders has a Microsoft Entra tenant and a Microsoft Entra Domain Services managed domain. The northwindtraders.com domain syncs with the Microsoft Entra tenant.
Virtual Machines
The company has an on-premises Hyper-V virtual machine named VM1 that has the following configurations:
- Generation: 1
- Disk size: 2 TB
- Disk format: VHDX
- Disk type: Dynamically expanding
Cloud Services
Northwind Traders has a Microsoft 365 E5 subscription. The subscription contains 500 users that are assigned Microsoft 365 E5 licenses.
The company has an Azure subscription that contains the resources shown in the following table.

Both subscriptions are linked to the Microsoft Entra tenant.
Requirements
Planned Changes
Northwind Traders identifies the following planned changes:
- Deploy an Azure Virtual Desktop host pool that will contain 10 session hosts joined to the Microsoft Entra Domain Services managed domain.
- Configure VM1 as the source image for the Azure Virtual Desktop deployment and upload the image to Azure.
- The Azure Virtual Desktop deployment will provide access to a custom app named App1.
Performance Requirements
Northwind Traders identifies the following performance requirements:
- Each Azure Virtual Desktop session host must support 15 user sessions.
- Each new user session must be assigned to a single session host until the maximum session limit is reached for that host.
Application Requirements
Northwind Traders identifies the following application requirements:
- Microsoft OneDrive must launch when users connect to a RemoteApp session in Azure Virtual Desktop.
- App1 requires a desktop resolution of 1280 x 1024.
- Administrative effort must be minimized.
Disaster Recovery Requirements
Northwind Traders identifies the following disaster recovery requirements for the Azure Virtual Desktop deployment:
- Minimize outages if an Azure region fails.
- Minimize the recovery time objective (RTO).
- Minimize administrative effort in the event of a failover.
Security Requirements
Northwind Traders identifies the following security requirements:
- When users sign in to the Azure Virtual Desktop deployment by using the Azure Virtual Desktop client, they must authenticate by using their Microsoft Entra username and password only.
- When users sign in to the Azure Virtual Desktop deployment by using a web browser, they must authenticate by using the Microsoft Authenticator app.
- All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
- The client version and operating system used to connect to the session hosts must be logged.
- The solution must follow the principle of least privilege.
Networking Requirements
The Azure Virtual Desktop session hosts must be able to access the resources on the on- premises network.
User Profile Requirements
Northwind Traders identifies the following user profile requirements:
- Users must be able to access share1 by using their Microsoft Entra account.
- Azure Virtual Desktop user profiles must be managed by using FSLogix.
- All user profiles must be stored in share1.
Which two actions should you perform to meet the security requirements for Defender for Endpoint? Each correct answer presents a complete solution.
NOTE: Each correct selection is worth one point.
Suggested Answer: B,D Vote an answer
Scenario:
Security Requirements
*-> All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
(The Azure Virtual Desktop deployment will provide access to a custom app named App1.)
[D] Need to generalize VM1 and use as a source image.
[B] It's possible to onboard Azure Virtual Desktop (AVD) session hosts to Microsoft Defender for Endpoint using a Group Policy Object (GPO) and a script stored in a shared location. This method leverages the GPO's ability to deploy scripts to devices and ensures a consistent onboarding process for your AVD infrastructure.
Reference:
https://learn.microsoft.com/en-us/defender-endpoint/configure-endpoints-gp
https://learn.microsoft.com/en-us/defender-endpoint/configure-endpoints-script
Security Requirements
*-> All the Azure Virtual Desktop session hosts deployed by using the VM1 source image must be onboarded to Microsoft Defender for Endpoint.
(The Azure Virtual Desktop deployment will provide access to a custom app named App1.)
[D] Need to generalize VM1 and use as a source image.
[B] It's possible to onboard Azure Virtual Desktop (AVD) session hosts to Microsoft Defender for Endpoint using a Group Policy Object (GPO) and a script stored in a shared location. This method leverages the GPO's ability to deploy scripts to devices and ensures a consistent onboarding process for your AVD infrastructure.
Reference:
https://learn.microsoft.com/en-us/defender-endpoint/configure-endpoints-gp
https://learn.microsoft.com/en-us/defender-endpoint/configure-endpoints-script
by Helen at Oct 02, 2026, 07:16 AM
0
0
0
10
Comments
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Report Comment
Commenting
You can sign-up / login (it's free).