Microsoft · AZ-140
Validates expertise in designing, implementing, managing, and maintaining Microsoft Azure Virtual Desktop experiences and remote apps for any device.
Practice Questions
517
≈ 10 practice exams
Duration
100 minutes
Passing Score
700/1000
Difficulty
SpecialtyLast Updated
Oct 2026
AZ-140 has four domains: plan and implement an Azure Virtual Desktop infrastructure (40-45%), plan and implement identity and security (15-20%), plan and implement user environments and apps (20-25%), and monitor and maintain the infrastructure (10-15%). The skills outline was revised on July 20, 2026 with minor changes; the percentages are unchanged, and the new wording names items such as RDP Multipath, Controlled Folder Access, and browser support.
The exam allows 100 minutes and needs 700 on a scaled 1-1000 score. Microsoft does not publish a question count for AZ-140 (most of its exams have roughly 40 to 60), and the price depends on the country where you sit it. It is available in seven languages, has no formal prerequisite, and may include interactive components. The credential stays valid for 12 months and can be renewed free through an open-book online assessment in the six months before it expires.
Use these 517 questions alongside a lab: build a host pool, configure FSLogix profile containers, manage session host images, set up Conditional Access and single sign-on, and read AVD Insights. Questions reward knowing which setting solves a specific user-experience or security requirement, not just what each feature is called.
Microsoft AZ-140 earns the Azure Virtual Desktop Specialty credential. It covers planning and implementing an Azure Virtual Desktop infrastructure (40-45%), identity and security (15-20%), user environments and apps (20-25%), and monitoring and maintenance (10-15%).
Microsoft revised the skills outline on July 20, 2026 with minor changes; the percentages stayed the same, and the guide now names items such as RDP Multipath, Controlled Folder Access, browser support, and Start VM on Connect.
This certification is designed for server or desktop administrators who specialize in virtual desktop infrastructure and are transitioning to or expanding within Azure-hosted environments. Ideal candidates include desktop virtualization engineers, systems administrators, and infrastructure architects who design and operate end-user computing solutions at scale for remote or hybrid workforces.
Candidates typically collaborate cross-functionally with Azure administrators, Azure architects, Azure security engineers, Microsoft 365 administrators, and Azure Local administrators. The certification is well-suited for professionals already holding the AZ-104 (Azure Administrator Associate) credential who want to deepen their specialty in virtual desktop delivery.
There are no formal prerequisites. Microsoft recommends experience with Azure compute, networking, identity, storage, and resiliency, and with managing end-user desktop environments through the Azure portal, templates, scripting, and the CLI. Familiarity with Active Directory Domain Services, Microsoft Entra ID, and FSLogix helps.
AZ-140 allows 100 minutes and needs 700 on a scaled 1-1000 score. Microsoft does not publish a question count for the exam (most of its exams have roughly 40 to 60), and the price depends on the country where you sit it. It is offered in seven languages and may include interactive components. The credential is valid for 12 months and renews free through an unproctored, open-book assessment on Microsoft Learn during the six months before it expires.
AZ-140 shows that you can deploy and operate Azure Virtual Desktop for remote and hybrid users. It fits Azure administrators, desktop and endpoint engineers, and architects who run virtual desktop platforms. The 12-month renewal keeps the credential tied to the current service.
5 sample questions with answers and explanations. The full bank has 517 questions, enough for 10 full-length practice exams.
Preview — answers shown1. The manager of a pooled host pool wants to use autoscale to be highly responsive to user demand. They want the scaling to be based on the number of available sessions, not just a fixed time schedule. What autoscale mode should they configure for the ramp-up phase?
Explanation
Autoscale offers two main modes for scaling. Schedule-based scaling turns VMs on or off at fixed times of the day. Load-based scaling, however, is dynamic. It monitors the number of available sessions in the host pool. If the number of available sessions drops below a threshold you define (meaning users are logging in and consuming capacity), the load-based algorithm will automatically start another VM to meet the increasing demand. This is the correct mode for reacting to real-time user load.
2. FlexiWork Corp wants to use smartcards for authentication with their Azure Virtual Desktop environment. Their IT team needs to understand the authentication protocols supported. Which protocol must be available for smartcard authentication to work properly?
Explanation
Smartcard and Windows Hello for Business authentication can only use Kerberos protocol for session host authentication, even though Azure Virtual Desktop supports both NTLM and Kerberos for regular authentication. To use Kerberos, the client needs to obtain Kerberos security tickets from a Key Distribution Center (KDC) service running on a domain controller, which requires direct network line of sight to the domain controller through corporate network, VPN connection, or KDC proxy server.
3. DataFlow Corp is configuring FSLogix ODFC containers and wants to include Teams data. They need to set the IncludeTeams registry value. What should this DWORD value be set to for enabling Teams inclusion?
Explanation
The IncludeTeams registry value should be set to 1 (DWORD) to enable Teams data inclusion in ODFC containers. This setting tells FSLogix to redirect Teams application data into the ODFC container, ensuring Teams settings, cache, and configuration roam with the user across different session hosts. Setting it to 0 would disable Teams inclusion, while values 2 and 3 are not valid options for this registry setting. This configuration is particularly important in multi-session environments where users need consistent Teams experience.
4. ConnectFast Corporation has implemented FSLogix and needs to verify their profile container configuration. A user has logged in and they want to confirm the profile redirection is working. What command should they run from C:\Program Files\FSLogix\Apps?
Explanation
The frx list-redirects command is used to verify that FSLogix profile redirection is working correctly. When run from the C:\Program Files\FSLogix\Apps directory, this command displays the current profile redirections that are active for the logged-in user. This verification step is crucial after configuration to ensure that user profiles are being properly redirected to the FSLogix containers rather than using local profiles. It provides immediate feedback on whether the FSLogix configuration is functioning as expected.
5. GlobalTech Industries is implementing Microsoft Defender for Endpoint onboarding using domain group policy. Where should they extract the onboarding package contents?
Explanation
When using domain group policy for Microsoft Defender for Endpoint onboarding, you should extract the contents of the WindowsDefenderATPOnboardingPackage.zip file to a shared, read-only location that's accessible to all devices requiring onboarding. This centralized approach ensures all session hosts can access the necessary files (OptionalParamsPolicy folder and the onboarding scripts) while maintaining security through read-only permissions and consistent access across the environment.
AZ-140 sits under the same Candidate Agreement as every Microsoft exam: unauthorized exam content is treated as misconduct, and Microsoft's standard response is to revoke your full certification history and ban you from future exams, not just invalidate the one result.
If you already hold other Microsoft certifications, or are stacking AZ-140 toward a specialty path, that math gets worse the more you have earned. CertCompanion's AZ-140 bank has 517 practice questions, 30 free, built around real Azure Virtual Desktop deployment and management scenarios.
Microsoft does not publish a count for AZ-140. It says most of its exams have roughly 40 to 60 questions, and the exam allows 100 minutes.
700 on a scaled 1-1000 score, not a percentage of questions answered correctly.
Infrastructure is 40-45%, identity and security 15-20%, user environments and apps 20-25%, and monitoring and maintenance 10-15%. The skills outline was last revised on July 20, 2026.
No. Microsoft lists no formal prerequisite, but recommends experience with Azure compute, networking, identity, storage, and resiliency.
Yes, after 12 months. You renew for free with an unproctored, open-book assessment on Microsoft Learn during the six months before expiry.
Microsoft prices the exam by the country or region where you sit it, so check the amount when you schedule on Microsoft Learn.
Microsoft Certified: Azure Administrator Associate (AZ-104)
AZ-104 · 757 questions
Microsoft Certified: Azure Security Engineer Associate (AZ-500)
AZ-500 · 469 questions
Microsoft 365 Certified: Endpoint Administrator Associate (MD-102)
MD-102 · 636 questions
Microsoft Certified: Identity and Access Administrator Associate (SC-300)
SC-300 · 489 questions
Microsoft Certified: Machine Learning Operations (MLOps) Engineer Associate (AI-300)
AI-300 · 583 questions
Microsoft Certified: SQL AI Developer Associate (DP-800)
DP-800 · 600 questions
$17.99
One-time access to this exam