
Explore planning and implementing Azure virtual desktops on the cloud, covering architecture, deployment strategies, security, monitoring, and optimization, with a hands-on project demonstration from end to end.
Use the Windows virtual desktop experience estimator to identify the Azure region with the lowest round-trip time, guiding deployment decisions based on minimum RTT.
Use the Azure calculator to configure and estimate costs for Azure products, such as virtual machines and storage, save and share estimates, customize settings, and export to Excel for budgeting.
Azure virtual desktop provides a cloud-based virtualization service for desktops and apps across devices, offering multi-session Windows 10, Azure AD security, and scalable, cost-efficient licensing.
Explore the difference between traditional VDI/RDS and Azure Windows virtual desktop, comparing infrastructure as a service with platform as a service and covering licensing, maintenance, and image management.
Explore the Windows virtual desktop design and architecture, detailing the three blocks, the managed control plane, and the end-to-end user connection workflow.
Explore how Azure Virtual Desktop divides responsibilities, with Microsoft managing web access, diagnostics, broker, gateway, and Azure infrastructure, while you configure desktops, remote apps, images, and policies.
Explore the Azure Virtual Desktop environment, with host pools of session hosts from a golden image, plus application groups for remote apps and desktops, and workspaces for access.
Learn how Windows 10 enterprise multi-session, a Windows virtual desktop feature, enables multiple concurrent interactive sessions on a single desktop session host in Azure, with hardware-based capacity and customizable images.
Identify prerequisites like an Azure subscription and Azure Active Directory synchronization, register the desktop virtualization resource provider, and plan domain join, region-aligned resources, and supported Windows Virtual Desktop images.
Explore cloud-only identity deployment options for Azure Virtual Desktop, including a domain controller in a hosted Azure VM and Azure AD Domain Services, plus a hybrid on-prem connection.
Explore compute deployment options: personal, a one-to-one option for heavy performance and always-on single state. The bold option, a pooled, multi-session setup for lighter workloads, offers cost savings.
Explore load balancing options: depth first and breadth first. Depth first saturates a session host to its max, while breadth first distributes users evenly for best user experience.
Explore FSLogix profile containers for Azure virtual desktop, comparing local versus remote profiles and three deployment options, with Azure files as the recommended solution.
Learn virtual machine sizing guidelines for Azure Virtual Desktop, including single-session and multi-session recommendations and workload types with CPU, memory, and storage specs from Microsoft documentation.
Review Microsoft’s Windows Virtual Desktop network guidelines and bandwidth by workload. Assess display resolution, region latency, and stress tests using the Windows Virtual Desktop Experience Estimator.
Explore Microsoft-supported remote desktop clients for Azure virtual desktop resources, including web, Windows, Mac, iOS, and Android. Subscribe to your workspace, then sign in to access resources.
Assess Azure virtual desktop cost and licensing, covering compute, storage, and networking, and use the Adjure calculator to estimate scenarios and licensing options.
Review Windows Virtual Desktop pricing scenarios with Azure, comparing personal and multi-session workloads, graphics and Office use cases, and learn to estimate costs using the Azure calculator.
Explore project setup for Azure Virtual Desktop demos: configure identity with a domain controller in Azure, implement FSLogix profile with Azure Files, and build host pools and remote apps.
Create and configure the required admin accounts to join virtual machines to your domain, including creating a domain admin user, assigning domain admin permissions, and preparing for hospital host creation.
Synchronize users from the domain controller to Azure Active Directory using Azure AD Connect, then view them in the Azure portal and enable WPT authentication.
Check the identity sync by reviewing the synchronization between the domain controller and Azure Active Directory, using built-in tools to edit rules and monitor status in the portal.
Create three Azure AD groups for Azure Virtual Desktop—pooled desktop users, personal desktop users, and remote apps users—and assign users to each group.
Explore Azure Active Directory Domain Services as a managed cloud identity option for Azure Virtual Desktop, with subnet requirements, admin group setup, and management via a dedicated management virtual machine.
Create an Azure storage account in east US within the profiles resource group using a unique name and standard locally redundant storage to support the user profile file share.
Create a 30 GB, transaction-optimized Azure file share in the storage account, noting identity-based access and domain controller integration are not configured and preparing to mount with the connect code.
Install and configure the AzFilesHybrid module to enable active directory authentication for the storage account by joining the domain, installing prerequisites, and importing the module.
Enable Active Directory authentication for the storage account by logging in as a domain admin on a domain-joined machine and registering the storage account with Active Directory.
Verify storage account authentication with Active Directory by checking in users and computers, using PowerShell to retrieve storage account details, and confirming the Azure portal domain is clouds local.
Configure Azure storage file share permissions with built-in roles—owner, contributor, and elevated contributor—then implement NTFS permissions on the domain controller and create profile reader, contributor, and elevated contributor groups.
Configure file share permissions by creating two domain groups, profile first contributor, and elevated contributor, and assign them to WPT users and admin, then apply roles in the Azure portal.
Mount the file share on the domain controller, configure ntfs permissions with the storage account key, and apply granular file-level access using groups alongside azure built-in rules.
Configure FSLogix containers and NTFS permissions by creating three domain folders—profiles, odac, micex—and granting elevated contributor, creator owner, and WPT users with full control.
Migrate on-premises user profiles to Azure storage with Azure file sync. Create storage account and file share, install and register file sync agent, configure server endpoint for Azure virtual desktop.
Create a new Azure virtual machine using a Windows 10 Enterprise multi-session image for pooled use, configure region, resource group, admin, licensing, and validation, then deploy.
Prepare a multi-session Azure Virtual Desktop image by installing apps, applying updates, and configuring FSLogix to use a file share for user profiles.
Generalize the prepared virtual machine using sysprep, run from an administrator command prompt, then shut down the VM to create an image for future use.
Create a managed Azure VM image from a stopped custom virtual machine by capturing, generalizing the Windows operating system, naming the image, and saving it to the existing resource group.
Explore how to use a shared image gallery to share custom virtual machine images across regions and subscriptions, with image definitions, versions, and global replication for scalable deployments.
Create a pooled host pool in Azure Virtual Desktop, select depth-first load balancing for cost efficiency, configure a customized image, domain join, and a new workspace.
Assign a friendly name to the pooled workspace and tailor connection options, session behavior, load balancing, and display settings for default desktop and its application groups in Azure Virtual Desktop.
Assign an Azure AD group to the pooled application group in Windows Virtual Desktop to grant users access to desktops and remote apps.
Explore the pooled Azure Virtual Desktop setup and connect end users to AVD with a remote desktop client. See multi-session access and user profiles stored on Azure file share.
Create a new application group and attach it to an existing hosting pool as a remote app, assign access to Bill and Bob, name it my treat apps, and create.
Add remote apps to the application group in Azure Virtual Desktop via start menu or file path, then assign apps like Paint and Word to the desktop users group.
Connect to remote apps by using a user to access an application group, launch PowerPoint and Paint, and verify active sessions across Windows, Linux, and Mac.
Create a personal host pool in the Windows Virtual Desktop service, using direct assignment, a private network, and domain-joined virtual machines for single-user, high-performance sessions.
Assign an Azure AD group to the personal application group to grant desktop access; test with users Mary and Jack and track changes in the WPT service.
Assign a security group to the personal desktop, configure direct VM assignment to individual users, and connect via remote desktop clients while monitoring active sessions in the management console.
Learn the difference in creating host pools for windows virtual desktop when using azure active directory domain services, and how to join machines with a domain administrator account.
Enable autoscaling in Azure Virtual Desktop host pools using a Microsoft script to start and stop session hosts by business hours and session demand, reducing costs.
Explore Azure virtual desktop security with a focus on identity and access management for Windows virtual desktops, and understand the shared responsibility between you and Microsoft.
Explore Azure Active Directory, a cloud-based identity and access management service that centralizes on-prem and cloud resources with single sign-on, plus free, premium P1, and premium P2 plans.
Master Azure role based access control (rbac) and how owner, contributor, and reader roles govern access across subscriptions, resource groups, and resources, including role assignments and inheritance.
Explore multifactor authentication for Azure Virtual Desktop, password plus something you have or are, using authenticator codes or biometrics, plus fraud alerts and one-time bypass.
Enable multifactor authentication for selected Azure Active Directory users, configure trusted IPs and fraud alerts, and use one-time bypass to balance security with login convenience.
Plan conditional access policies that leverage signals from Azure Active Directory to evaluate user, device, location, and app context, enforce policies, and make risk-based decisions, including what-if simulations.
Configure and test conditional access policies in the Azure portal, using Azure Active Directory to control access by risk, location, device, and apps, with what-if simulations and MFA.
Explore Azure Security Center and defender, examining cloud security posture management and cloud workloads protection, with hybrid security management, centralized policy, and actionable recommendations.
Enable Azure Defender and configure endpoint protection through the Security Center, review actionable recommendations, enable MFA, deploy required agents, and enable auto provisioning for comprehensive protection.
Configure device redirection in Windows Virtual Desktop to keep corporate data in the session by disabling or restricting USB, drives, audio, and clipboard redirection.
Explore three apps management options for Windows virtual desktops: golden image provisioning with team-specific images, a single image with logic's application masking, and M6 attach for per-user dynamic delivery.
Show how FSLogix application masking uses a single image with all apps and real-time entitlements, and outline a four-step deployment: create a ruleset, assign to an entity, and deploy.
Learn how MSIX app attach isolates applications from the operating system using container technology, delivering packaged apps with their own registry and data, assigned dynamically to Windows virtual desktop users.
Learn to deploy apps with MSIX app attach by preparing an image, uploading it to an Azure file share, then publishing to an app group with users.
Explore MSIX app attach deployment by creating an application group, assigning users, and selecting applications from the start menu or file path, then provisioning the MSIX package via file share.
Explore MSIX app attach deployment part 2 by creating the image on an admin machine, converting applications with the MSRA packaging tool, and generating the X file for Azure upload.
Discover the universal print service for Azure Virtual Desktop: a cloud-based solution integrated with Azure Active Directory, enabling single sign-on, connectors for non-compatible printers, and Microsoft 365 subscription requirements.
Learn to securely access Azure virtual desktop session hosts using Azure Bastion, enabling browser-based, private access without IPs, with steps to configure Bastion in the same virtual network.
Prepare a disaster recovery plan for Azure Virtual Desktop by covering VM replication, network, identities, and data replication with Azure Site Recovery for seamless secondary-region failover.
Discover how cloud cache for Azure Virtual Desktop uses a local cache to provide real-time profile replication, business continuity during connectivity loss, and seamless failover.
Explore Windows virtual desktop monitoring in the portal; diagnose session hosts not sending data to log analytics workspace. Provision and configure required services and diagnostic settings for monitoring.
Configure azure virtual desktop monitoring by enabling arm-based or azure resource management, designating a log analytics workspace, and collecting diagnostics, performance counters, and windows event logs with read access permissions.
Provision a log analytics workspace to store, retain, and query data from monitored Azure resources, enabling centralized monitoring and insights.
Configure the Log Analytics workspace to collect data from virtual machines by enabling the workspace and installing the inside solution that collects performance counters and metrics.
Configure diagnostic settings across Azure Virtual Desktop resources, selecting log categories such as management activities, connections log, host registration, checkpoints, and health status, and send data to your analytics workspace.
Learn to onboard session host vms into log analytics and azure monitor by installing agents, applying azure policy for scalable coverage, and configuring remediation and compliance.
Configure performance counters and event logs using the Windows Virtual Desktop Insights workbook to deploy a default template, enabling comprehensive monitoring of the Azure Virtual Desktop environment.
Discover how Azure Advisor for AVD delivers prioritized recommendations across cost, security, reliability, operational excellence, and performance, with export options and alerts to resolve issues before contacting Microsoft.
Learn how to design and architect an Azure Virtual Desktop solution in Microsoft Azure Cloud, including: the design, deployment scenarios, implementation and even the licensing and Cost Estimation. This course includes an A to Z Azure Virtual Desktop (previously known as Windows Virtual Desktop) project demonstration in Azure Cloud, so you can see how to implement an actual AVD solution from scratch starting from the identity setup and going through the personal and pooled Host pools, Users profiles, permissions, application groups, custom VM image creation, FSLogix, Security, Monitoring, App management and Virtual Desktops.
At the end of this course you will be able to design and implement Azure Virtual Desktop solutions as well as determining the cost of running this kind of solutions in Microsoft Azure Cloud.
This course covers all the topics needed to prepare you for the Microsoft specialty exam AZ-140: Configuring and Operating Microsoft Azure Virtual Desktop. Passing the exam will grant you the 'Microsoft Certified: Azure Virtual Desktop Specialty' certificate.
The AZ-140 exam measures the student ability to accomplish the following technical tasks: plan a Azure Virtual Desktop architecture; implement a Azure Virtual Desktop infrastructure; manage access and security; manage user environments and apps; and monitor and maintain a Azure Virtual Desktop infrastructure.