πŸ”’ Guided

Pre-launch preview. Authorised access only.

Incorrect code

Guided by A Guide to Cloud
Explore AB-900 AI-901
Guided AZ-140 Domain 3
Domain 3 β€” Module 4 of 7 57%
21 of 28 overall

AZ-140 Study Guide

Domain 1: Plan and Implement an AVD Infrastructure

  • AVD Architecture: The Big Picture Free
  • Network Capacity and Design Free
  • RDP Shortpath, Multipath and QoS Free
  • Private Link and Network Troubleshooting Free
  • Storage Planning for User Data Free
  • File Shares and Azure NetApp Files Free
  • Host Pool Architecture: Personal vs Pooled Free
  • Sizing for Performance and Capacity Free
  • Creating Host Pools and Session Hosts Free
  • Session Host Licensing Free
  • Building Session Host Images Free
  • Image Lifecycle and Compute Gallery Free

Domain 2: Plan and Implement Identity and Security

  • Identity Scenarios for AVD
  • RBAC, Conditional Access and SSO
  • Defending AVD with Microsoft Defender
  • Network Security: NSGs, Firewall, Bastion
  • Threat Protection and Confidential VMs

Domain 3: Plan and Implement User Environments and Apps

  • FSLogix Profile Containers and ODFC
  • FSLogix Cloud Cache and Application Masking
  • AVD Clients: Choose and Deploy
  • User Experience and Session Settings
  • Application Groups and RemoteApp
  • Microsoft 365, Teams and OneDrive on AVD
  • App Attach: Dynamic Application Delivery

Domain 4: Monitor and Maintain an AVD Infrastructure

  • Monitoring AVD with Azure Monitor
  • Autoscaling and Session Management
  • Update Strategy and Backups
  • Disaster Recovery and Multi-Region

AZ-140 Study Guide

Domain 1: Plan and Implement an AVD Infrastructure

  • AVD Architecture: The Big Picture Free
  • Network Capacity and Design Free
  • RDP Shortpath, Multipath and QoS Free
  • Private Link and Network Troubleshooting Free
  • Storage Planning for User Data Free
  • File Shares and Azure NetApp Files Free
  • Host Pool Architecture: Personal vs Pooled Free
  • Sizing for Performance and Capacity Free
  • Creating Host Pools and Session Hosts Free
  • Session Host Licensing Free
  • Building Session Host Images Free
  • Image Lifecycle and Compute Gallery Free

Domain 2: Plan and Implement Identity and Security

  • Identity Scenarios for AVD
  • RBAC, Conditional Access and SSO
  • Defending AVD with Microsoft Defender
  • Network Security: NSGs, Firewall, Bastion
  • Threat Protection and Confidential VMs

Domain 3: Plan and Implement User Environments and Apps

  • FSLogix Profile Containers and ODFC
  • FSLogix Cloud Cache and Application Masking
  • AVD Clients: Choose and Deploy
  • User Experience and Session Settings
  • Application Groups and RemoteApp
  • Microsoft 365, Teams and OneDrive on AVD
  • App Attach: Dynamic Application Delivery

Domain 4: Monitor and Maintain an AVD Infrastructure

  • Monitoring AVD with Azure Monitor
  • Autoscaling and Session Management
  • Update Strategy and Backups
  • Disaster Recovery and Multi-Region
Domain 3: Plan and Implement User Environments and Apps Premium ⏱ ~16 min read

User Experience and Session Settings

AVD session experience is shaped by device redirection, multimedia optimisation, printing configuration, and session timeout policies. Learn how to fine-tune user experience through RDP properties, Intune policies, and Group Policy β€” balancing usability with security.

Device redirection β€” what goes where

β˜• Simple explanation

Think of redirection as building bridges between your physical device and your cloud desktop.

Your cloud desktop runs in Azure, but your keyboard, mouse, webcam, USB drive, and printer are physically at your desk. Redirection builds invisible bridges so your cloud desktop can use your local devices. Clipboard redirection lets you copy text from your local PC and paste it in the cloud desktop. Camera redirection lets your cloud desktop use the webcam plugged into your laptop.

Admins decide which bridges to build. Tight security means fewer bridges.

Device redirection allows local client devices (peripherals, drives, clipboard) to be accessible within the remote AVD session. Redirection is configured through RDP properties set on the host pool β€” these properties control what the RDP protocol allows between client and session host.

Each redirection type can be enabled, disabled, or partially restricted. The trade-off is always user experience vs security: more redirection means more convenience but increases the data exfiltration surface.

RDP properties on host pools

RDP properties are configured on the host pool in the Azure portal under Properties, or via PowerShell/CLI. They apply to all sessions in that host pool.

Key RDP properties

RDP PropertyValuesWhat It Controls
redirectclipboard0 (off) or 1 (on)Copy/paste between local and remote
drivestoredirect* (all), none, or specific drivesLocal drive mapping in session
camerastoredirect* (all) or noneWebcam access in session
audiocapturemode0 (off) or 1 (on)Microphone capture from local device
audiomode0 (play locally) or 1 (play remotely)Where audio plays
devicestoredirect* (all) or noneUSB and PnP device redirection
usbdevicestoredirectspecific VID:PID or noneSpecific USB device redirection
redirectprinters0 (off) or 1 (on)Local printer access in session
redirectcomports0 (off) or 1 (on)Serial/COM port redirection
redirectsmartcards0 (off) or 1 (on)Smart card reader redirection
redirectlocation0 (off) or 1 (on)GPS/location data redirection

πŸ›οΈ JC’s lockdown at Federal: β€œDirector Walsh’s mandate: no clipboard, no drives, no USB. If data is classified, it stays in the session. We only allow smart card redirection for PIV authentication and audio for Teams calls. The RDP properties took 5 minutes to configure on the host pool.”

Security vs usability spectrum

Security LevelClipboardDrivesUSBCameraMicrophonePrinter
Open (productivity focus)YesAllAllYesYesYes
Balanced (most enterprises)YesNoneNoneYesYesYes
Restricted (regulated)NoNoneNoneNoYesNo
Locked down (government/finance)NoNoneNoneNoNoNo
πŸ’‘ Exam tip: RDP properties override hierarchy

RDP properties set on the host pool in Azure are the primary control. However, Group Policy on session hosts can further restrict (but not expand) what is allowed. If the host pool allows clipboard and a GPO disables it, clipboard is disabled. The most restrictive setting wins.

The exam tests this β€” if a question shows both host pool RDP properties and GPO settings, apply the most restrictive of the two.

Multimedia redirection (MMR)

Multimedia redirection offloads video rendering from the session host to the client device. Without MMR, video streams are decoded on the session host, re-encoded as RDP graphics, and sent to the client β€” consuming significant CPU and bandwidth.

How MMR works

  1. User plays a video in a supported browser (Edge or Chrome) on the session host
  2. The MMR extension detects the video stream
  3. Instead of rendering on the session host, the raw video stream is sent directly to the client
  4. The client device decodes and renders the video locally
  5. Result: smooth video playback, lower session host CPU, reduced bandwidth

MMR requirements

  • Client: Windows App or Remote Desktop client
  • Session host: MMR host component installed, Edge or Chrome browser
  • Supported sites: YouTube, Vimeo, and other streaming sites (uses a browser extension)

🌐 Priya’s creative team: β€œBen’s team reviews video dailies in the browser. Without MMR, playback was choppy and buffered constantly β€” the session host was maxing out CPU trying to decode 4K video. After enabling multimedia redirection, the video renders on their MacBook Pro GPUs instead. Buttery smooth.”

Printing in AVD

Printing options

MethodHow It WorksProsCons
Local printer redirectionRedirects client’s local printers into the sessionSimple, no config neededRequires drivers on session host
Universal PrintCloud-based print service, no drivers neededNo drivers, cloud-managedRequires Universal Print licence
Direct network printingSession host prints to network printers directlyStandard enterprise printingRequires network connectivity

Universal Print β€” the modern approach

Universal Print eliminates printer drivers on session hosts:

  1. Printers are registered with the Universal Print cloud service
  2. Users discover printers through Entra ID β€” no driver installation needed
  3. Print jobs go from session host to Universal Print service to the printer
  4. Admins manage printers centrally in the Microsoft 365 admin centre

🎧 Mia’s printing fix: β€œPrinter drivers were our second biggest headache after profiles. Every clinic had different printers, different drivers, constant conflicts. Universal Print removed all of that β€” zero drivers on session hosts. Tom can print his patient handoffs from any clinic without a single support ticket.”

Managing user settings β€” Intune vs Group Policy

Intune vs Group Policy for AVD Management
AspectMicrosoft IntuneGroup Policy (GPO)
Identity requirementEntra ID joined or hybrid joinedAD DS joined (or hybrid)
Management scopeUser and device policiesComputer and user policies
AVD-specific templatesSettings catalogue with AVD policiesAdministrative templates (ADMX)
Delivery methodCloud-based, internet requiredDomain controller, on-premises
Update frequencyNear real-time (policy sync)Default: every 90 minutes + 30 min random
ReportingIntune compliance dashboardRSOP, gpresult
Best forCloud-native or hybrid Entra joined hostsTraditional AD-joined session hosts
Session timeout controlVia Settings Catalogue or configuration profilesVia GPO: Session Time Limits
Start menu / taskbarConfiguration profilesGPO preferences or ADMX templates

What you can configure

Setting CategoryExamples
Session timeoutsDisconnect after X minutes idle, logoff disconnected sessions after Y hours
Start menu and taskbarPin specific apps, hide Power button, restrict Settings access
Desktop experienceWallpaper, lock screen, theme restrictions
Application restrictionsAppLocker policies, WDAC policies
OneDriveSilent sign-in, Known Folder Move, Files On-Demand
Windows UpdateUpdate rings, maintenance windows, feature update deferrals

Session timeout properties

Session timeouts control what happens when users are idle or disconnected:

Timeout SettingWhat It DoesWhere to Configure
Idle session limitDisconnects session after X minutes of no inputGPO or Intune
Disconnected session limitLogs off disconnected sessions after X timeGPO or Intune
Active session limitDisconnects active sessions after X time (rarely used)GPO or Intune
Reconnection policyAllow reconnect from same client only or any clientHost pool RDP properties

Timeout strategy by workload

WorkloadIdle TimeoutDisconnected TimeoutWhy
Task workers (call centre)15 minutes1 hourFree up resources quickly
Knowledge workers30-60 minutes4 hoursBalance resources with user flow
Healthcare (clinical)10 minutes2 hoursHIPAA compliance, shared workstations
Developers120 minutes or never8 hoursLong-running builds, deep focus

🎧 Mia’s timeout tuning: β€œOur first timeout policy was 30 minutes idle. Nurses were furious β€” they’d step away to attend a patient for 20 minutes and lose their session. We changed to 10-minute disconnect (keeps session alive but frees the connection) with 2-hour logoff for disconnected sessions. Nurses reconnect instantly when they return.”

ℹ️ Deep dive: Disconnect vs logoff

Understanding the difference is critical for the exam:

  • Disconnect: The user’s session stays running on the session host (apps open, profile mounted), but the RDP connection is dropped. The user can reconnect and pick up exactly where they left off. Resources are still consumed on the session host.
  • Logoff: The session is fully terminated. Apps close, profile is saved and unmounted, VM resources are freed. The user starts a fresh session next time.

The exam often tests scenarios where you need to choose between these. Disconnect is user-friendly (fast reconnect) but uses resources. Logoff frees resources but the user loses their open work.

Question

Where are RDP properties for device redirection configured?

Click or press Enter to reveal answer

Answer

On the host pool in the Azure portal (Properties section), or via PowerShell/CLI. They apply to all sessions in that host pool. Group Policy can further restrict (but not expand) what the host pool allows.

Click to flip back

Question

What does multimedia redirection (MMR) do?

Click or press Enter to reveal answer

Answer

MMR offloads video rendering from the session host to the client device. Instead of the session host decoding video and re-encoding it as RDP graphics, the raw video stream is sent to the client for local rendering β€” reducing CPU usage and improving playback quality.

Click to flip back

Question

How does Universal Print help in AVD environments?

Click or press Enter to reveal answer

Answer

Universal Print eliminates the need for printer drivers on session hosts. Printers are registered with the Universal Print cloud service, and users discover them through Entra ID. Print jobs flow from the session host through the cloud service to the printer β€” no driver installation or conflicts.

Click to flip back

Question

What is the difference between disconnecting and logging off an AVD session?

Click or press Enter to reveal answer

Answer

Disconnect drops the RDP connection but keeps the session running (apps open, profile mounted, resources used). Logoff fully terminates the session (apps close, profile unmounted, resources freed). Users reconnect instantly after disconnect but start fresh after logoff.

Click to flip back

Knowledge Check

JC needs to prevent data exfiltration from classified desktops. Users must be able to use Teams for voice calls and smart cards for authentication. Which RDP properties should he configure?

Knowledge Check

Priya's creative team watches video dailies in the browser during their AVD sessions. Playback is choppy and session host CPU spikes to 90%. What should Priya enable?

Knowledge Check

Mia sets a 10-minute idle timeout that disconnects sessions. After disconnection, sessions are logged off after 2 hours. A nurse steps away for 15 minutes, then returns. What happens?

🎬 Video coming soon

User Experience and Session Settings


Next up: Application Groups and RemoteApp β€” learn the difference between desktop and RemoteApp application groups, and how to publish individual applications to users.

← Previous

AVD Clients: Choose and Deploy

Next β†’

Application Groups and RemoteApp

Guided

I learn, I simplify, I share.

A Guide to Cloud YouTube Feedback

© 2026 Sutheesh. All rights reserved.

Guided is an independent study resource and is not affiliated with, endorsed by, or officially connected to Microsoft. Microsoft, Azure, and related trademarks are property of Microsoft Corporation. Always verify information against Microsoft Learn.