{"id":26735,"date":"2026-10-06T10:10:38","date_gmt":"2026-10-06T10:10:38","guid":{"rendered":"https:\/\/www.examlabs.com\/certification\/?p=26735"},"modified":"2026-10-06T10:10:38","modified_gmt":"2026-10-06T10:10:38","slug":"microsoft-az-140-exam-scope-and-skills","status":"publish","type":"post","link":"https:\/\/www.examlabs.com\/certification\/microsoft-az-140-exam-scope-and-skills\/","title":{"rendered":"Microsoft AZ-140: Exam Scope and Skills"},"content":{"rendered":"<p>AZ-140 remains Microsoft&#8217;s live Azure Virtual Desktop specialty exam in October 2026. The current English skills measured are the July 20, 2026 version. The <a href=\"https:\/\/www.examlabs.com\/az-140-exam-dumps\">AZ-140<\/a> blueprint is weighted 40\u201345% Plan and implement an Azure Virtual Desktop infrastructure, 15\u201320% Plan and implement identity and security, 20\u201325% Plan and implement user environments and apps, and 10\u201315% Monitor and maintain an Azure Virtual Desktop infrastructure. Microsoft requires a score of 700 or greater to pass.<\/p>\n<p>The audience profile is a server or desktop administrator who designs, implements, manages, and maintains Azure Virtual Desktop experiences and remote apps. Candidates are expected to work across compute, networking, identity, storage, and resiliency while collaborating with Azure, Microsoft 365, security, and Azure Local specialists.<\/p>\n<h3>Infrastructure planning is the largest area at 40\u201345%<\/h3>\n<p>The largest domain covers networking, storage for user data, host-pool architecture, session-host deployment, and session-host image lifecycle. The administrator must think beyond a single VM and design an AVD service that can scale, recover, and provide acceptable user experience.<\/p>\n<p>An <a href=\"https:\/\/www.examlabs.com\/certification\/az-140-study-guide-understanding-and-planning-azure-virtual-desktop-architecture\">Azure Virtual Desktop architecture<\/a> model should therefore begin with users, regions, identity, network path, host pools, images, storage, and capacity.<\/p>\n<h3>Networking includes modern RDP optimization<\/h3>\n<p>The current guide includes network-capacity assessment, session-host network design, RDP Shortpath, RDP Multipath, QoS, Azure Private Link for AVD, and network-connectivity troubleshooting. These topics reflect that desktop experience depends heavily on latency and network path.<\/p>\n<p>A secure and well-sized host pool can still feel unusable if media or interactive traffic crosses an inefficient path.<\/p>\n<h3>User-data storage is closely tied to FSLogix<\/h3>\n<p>Candidates should plan storage for AVD user data and implement storage for FSLogix components through storage accounts, file shares, and Azure NetApp Files where appropriate. Performance, availability, identity, backup, and geographic placement all affect profile behavior.<\/p>\n<p>Profile-storage choice is therefore both a user-experience and resiliency decision.<\/p>\n<h3>Host pools and session hosts are core operational objects<\/h3>\n<p>The guide includes resource-group\/subscription\/management-group recommendations, operating-system and licensing choices, host-pool architecture, performance and VM-capacity design, portal-based creation, automation through PowerShell\/CLI\/ARM\/Bicep, and host-pool\/session-host settings.<\/p>\n<p>A <a href=\"https:\/\/www.examlabs.com\/certification\/az-140-complete-prep-guide-managing-microsoft-azure-virtual-desktop\">complete AVD preparation<\/a> path should include both pooled and personal desktop concepts and why each fits different user requirements.<\/p>\n<h3>Image lifecycle is explicitly in scope<\/h3>\n<p>Candidates should create or modify images manually or through Azure VM Image Builder, apply OS\/application updates, use custom images for session hosts, and plan image storage such as Azure Compute Gallery. Image management is what turns a working desktop into a maintainable fleet.<\/p>\n<p>Golden-image drift can create inconsistent application and security behavior across a host pool.<\/p>\n<h3>Identity and security represent 15\u201320%<\/h3>\n<p>The domain covers AD DS, Microsoft Entra ID, and Entra Domain Services identity scenarios; Azure RBAC; Conditional Access; passwordless, smart-card, and MFA options; rights assignments; Entra single sign-on; Defender for Cloud; Defender Antivirus; Defender for Endpoint; UDRs, NSGs, Azure Firewall; Bastion\/JIT; App Control for Business; Controlled Folder Access; confidential VMs; and Trusted Launch.<\/p>\n<p>An <a href=\"https:\/\/www.examlabs.com\/certification\/strengthening-endpoint-security-with-microsoft-defender-for-endpoint\">endpoint-security<\/a> model matters because session hosts are multi-user compute resources with both user and enterprise-data exposure.<\/p>\n<h3>User environments and apps are 20\u201325%<\/h3>\n<p>This area covers FSLogix Profile Containers, ODFC containers, Cloud Cache, application masking, client choice and deployment, device and multimedia redirection, printing\/Universal Print, Intune or Group Policy settings, RDP properties, session timeouts, Start VM on Connect, and personal-desktop assignment.<\/p>\n<p>The administrator is responsible for both the infrastructure and the user&#8217;s desktop experience.<\/p>\n<h3>Application delivery includes RemoteApp and App attach<\/h3>\n<p>The current blueprint includes choosing app-deployment methods, application groups, user assignments, RemoteApp, Microsoft 365 Apps, OneDrive in multisession environments, Teams with the Remote Desktop WebRTC Redirector Service, browsers, dynamic application delivery through App attach, and App attach packaging.<\/p>\n<p>App delivery should be planned with image maintenance and user-profile behavior so updates do not require rebuilding every host manually.<\/p>\n<h3>Monitoring and maintenance make up 10\u201315%<\/h3>\n<p>The final domain covers log collection, Azure Monitor, AVD Insights workbooks, session-host capacity\/performance optimization, autoscaling, active-session and application-group management, update strategy, disaster recovery, multi-region design, and backup\/restore for FSLogix profiles, personal desktops, and images.<\/p>\n<p>An <a href=\"https:\/\/www.examlabs.com\/certification\/what-is-azure-monitoring-a-complete-guide\">Azure Monitor<\/a> foundation is useful because capacity and user experience should be managed from evidence rather than waiting for user complaints.<\/p>\n<h3>Current AZ-140 is an end-to-end virtual-desktop operations exam<\/h3>\n<p>The exam expects candidates to connect networking, identity, host capacity, image management, FSLogix, application delivery, security, monitoring, and recovery. AVD is not simply &#8220;Windows VMs in Azure&#8221;; it is a managed desktop service whose user experience depends on all of those layers working together.<\/p>\n<p>The July 2026 guide also makes licensing part of host-pool planning. Windows client and Windows Server session hosts do not have identical eligibility requirements, and a design can be technically correct while still using the wrong licensing model for the user population. The administrator should validate entitlement before scaling the deployment.<\/p>\n<p>Resource-group, subscription, and management-group placement appears in the blueprint because AVD resources often span networking, host pools, storage, images, monitoring, and security. Organizing those resources intentionally improves delegation, policy, cost management, and lifecycle operations.<\/p>\n<p>RDP Shortpath deserves separate attention because it can create a more direct UDP-based path between client and session host, reducing reliance on the managed gateway path in supported scenarios. RDP Multipath adds resilience and traffic-path options where supported. Candidates should understand the purpose and dependencies rather than memorize packet diagrams.<\/p>\n<p>QoS belongs beside Shortpath because real-time interactive traffic competes with other network use. Marking and prioritization can help voice, video, or desktop responsiveness when the path is congested. QoS is only useful when network devices along the path honor the intended policy.<\/p>\n<p>Azure Private Link for AVD changes how users or administrators reach supported AVD service endpoints, reducing public-network exposure in selected designs. The administrator still needs DNS, routing, identity, and session-host connectivity to be correct; Private Link does not solve every network-security requirement by itself.<\/p>\n<p>FSLogix profile performance is tightly linked to storage latency and throughput. Large profiles, antivirus scanning, poor SMB performance, or underprovisioned file services can increase sign-in time even when host CPU and memory look healthy. The exam expects candidates to see profile storage as part of the desktop performance path.<\/p>\n<p>Azure Files and Azure NetApp Files provide different performance and cost profiles. The administrator should choose based on profile scale, latency, throughput, protocol and operational requirements rather than assuming the premium service is always necessary.<\/p>\n<p>Host-pool load balancing also affects user experience. Breadth-first distribution can spread sessions across more hosts, while depth-first behavior can pack sessions onto fewer hosts to reduce cost. The right strategy depends on workload density, startup time, and cost\/performance goals.<\/p>\n<p>Automation matters because session hosts are often replaced or scaled frequently. PowerShell, Azure CLI, ARM, and Bicep can make host-pool creation repeatable, but automation should include validation, naming, identity, network placement, image version, and monitoring so every host joins the same operational standard.<\/p>\n<p>Azure VM Image Builder can automate image creation from controlled sources and steps, while Azure Compute Gallery distributes versioned images across regions. Together they support a more professional image lifecycle than manually patching a running host and capturing it without documentation.<\/p>\n<p>Image updates should also include application compatibility testing. A security patch, Teams optimization change, OneDrive update, or browser version can affect multi-user behavior. Staged image rollout helps contain regressions before every host in a pool is replaced.<\/p>\n<p>Entra single sign-on reduces repeated authentication prompts between the client and session host in supported configurations. It should be studied alongside the chosen identity scenario and Conditional Access because authentication design affects both user experience and security.<\/p>\n<p>Rights assignments on session hosts still matter even when Azure RBAC is correct. RBAC controls Azure resource administration; Windows local\/group rights determine what the signed-in user or administrator can do inside the operating system. The two authorization layers should be kept distinct.<\/p>\n<p>Defender for Cloud can assess session-host posture, while Defender for Endpoint provides endpoint detection and response. The administrator should know when a problem is a missing security configuration versus observed suspicious behavior. A recommendation and an incident should not produce the same operational response.<\/p>\n<p>App Control for Business and Controlled Folder Access are examples of host-level protection that can be particularly important in pooled multi-user environments. Strong allowlisting can reduce malware risk, but policy must be tested against the applications users need to run.<\/p>\n<p>Trusted Launch and confidential VM capabilities add platform-level protection for session hosts. Their suitability depends on VM size, image, security requirements, and operational compatibility. The blueprint signals that AVD administrators need modern compute-security awareness, not only desktop-policy skills.<\/p>\n<p>ODFC containers can separate Microsoft 365 cached data from the main profile container, while Cloud Cache can replicate profile data across storage locations for selected resilience scenarios. The administrator should understand the availability and performance trade-offs before enabling more complexity.<\/p>\n<p>Application masking is another FSLogix capability in scope. It can hide applications from selected users without maintaining completely separate images. This can simplify image management, but app entitlement and testing still need clear ownership.<\/p>\n<p>Device redirection should be treated as a user-experience and security decision. Clipboard, drives, USB-related features, cameras, microphones, and printers can improve productivity while creating data-exfiltration or support concerns. Policies should follow business need instead of enabling every redirection by default.<\/p>\n<p>Multimedia redirection and the Teams WebRTC redirector exist because high-bandwidth media can perform poorly when everything is rendered inside the session host. Offloading supported media to the endpoint can improve quality and reduce host load, but client and policy compatibility are required.<\/p>\n<p>App attach separates application packages from the base session-host image, which can accelerate app delivery and reduce image rebuild frequency. The administrator should still validate package creation, storage access, app registration, user assignment, and compatibility with the chosen host pool.<\/p>\n<p>Autoscaling plans should reflect time-of-day demand, minimum available capacity, ramp-up\/ramp-down behavior, and drain mode. Aggressive shutdown can reduce cost but create login delays or disconnect risk if the schedule ignores real user behavior.<\/p>\n<p>Disaster recovery should include control-plane configuration as well as user data. In a regional outage, having profile backups but no prepared network, image, host-pool, or identity path in another region will not restore the service quickly. Recovery plans should be tested as an end-to-end desktop experience.<\/p>\n<p>Within the broader <a href=\"https:\/\/www.examlabs.com\/microsoft-certification-exams\">Microsoft certification<\/a> path, AZ-140 validates that integrated specialty role. Final review should stay aligned to the July 20, 2026 guide rather than older AVD architectures that omit RDP Multipath, App attach changes, or current security options.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>AZ-140 remains Microsoft&#8217;s live Azure Virtual Desktop specialty exam in October 2026. The current English skills measured are the July 20, 2026 version. The AZ-140 blueprint is weighted 40\u201345% Plan and implement an Azure Virtual Desktop infrastructure, 15\u201320% Plan and implement identity and security, 20\u201325% Plan and implement user environments and apps, and 10\u201315% Monitor [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1648,1647],"tags":[],"_links":{"self":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26735"}],"collection":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/comments?post=26735"}],"version-history":[{"count":1,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26735\/revisions"}],"predecessor-version":[{"id":26736,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/posts\/26735\/revisions\/26736"}],"wp:attachment":[{"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/media?parent=26735"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/categories?post=26735"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.examlabs.com\/certification\/wp-json\/wp\/v2\/tags?post=26735"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}