Microsoft AZ-140: Skills and Scope
AZ-140 validates the Microsoft Certified: Azure Virtual Desktop Specialty role. The AZ-140 exam was updated on July 20, 2026 and currently measures planning and implementation of Azure Virtual Desktop infrastructure, identity and security, user environments and apps, and monitoring and maintenance.
The role is broader than desktop configuration. Candidates need to combine compute, networking, identity, storage, resiliency, FSLogix, application delivery, automation, security, client experience, and monitoring into a virtual desktop service that remains usable at scale.
The largest current domain covers Azure Virtual Desktop infrastructure. Candidates should understand host pools, session hosts, operating-system choices, subscription and resource organization, licensing, capacity, performance, images, and automation.
Build a small host pool and document every design assumption: pooled or personal, breadth-first or depth-first balancing where relevant, image source, session-host size, expected concurrency, update approach, and what happens when one host is unavailable.
Include image and capacity assumptions in the same design. A large standardized image can simplify operations but slow deployment, while many specialized images increase maintenance. Capacity should account for peak sessions, maintenance, startup time, and the effect of draining a host.
Document which decisions can be changed easily later and which require disruptive migration. Host-pool design, identity model, profile storage, and region placement can create long-lived constraints, so those choices deserve more analysis than a minor client setting.
Azure Virtual Desktop networking includes capacity planning, session-host connectivity, RDP Shortpath, RDP Multipath, QoS, Private Link, and troubleshooting. A user may report “the desktop is slow” even when compute is healthy because the path, latency, packet loss, or DNS is wrong.
The broader AZ-104 exam is useful background for networking and Azure administration. AZ-140 candidates should be able to diagnose the platform dependencies rather than treating AVD as a self-contained product.
Test Shortpath or optimized connectivity where your lab supports it, and compare the session path with the default relay path. The important skill is understanding which network route the RDP traffic actually uses and which firewalls, NAT devices, or policies can affect it.
Capacity planning should include user location. A host pool placed far from users may have plenty of compute while still delivering poor experience because latency dominates the session. Region choice is therefore both a compute and network design decision.
FSLogix profile containers allow user profiles to follow sessions across multi-session hosts. Practice storage selection, profile containers, ODFC containers, Cloud Cache, application masking, and what happens when the profile path is slow or unavailable.
A good lab tests logon with a healthy profile, a locked or unavailable profile, and a new session host. The user experience should help you distinguish profile problems from session-host, identity, or application problems.
Measure profile behavior under load. Login may work for one user while storage latency becomes unacceptable with many concurrent sessions. The profile system is part of the performance architecture, not just a configuration checkbox.
Keep user data and machine state conceptually separate. A pooled host should be replaceable without losing the user environment. This is why profile containers, application configuration, and persistent data locations need intentional design.
The current study guide includes Active Directory Domain Services, Microsoft Entra ID, Microsoft Entra Domain Services, RBAC, Conditional Access, MFA, passwordless options, smart cards, and single sign-on.
The article on Microsoft Entra ID and Azure RBAC is useful because authentication and Azure authorization are separate controls. A user may authenticate correctly and still lack permission to an AVD resource or application.
AZ-140 expects candidates to understand Defender for Cloud, Defender Antivirus, Defender for Endpoint, NSGs, Azure Firewall, Bastion or just-in-time access, application control, Controlled Folder Access, and secure VM capabilities such as Trusted Launch.
Do not apply every security feature blindly. Identify the threat and user workflow first. Administrative access, user-session protection, endpoint detection, network isolation, and application-control problems each have different enforcement points.
Session-host images need a repeatable build, storage, update, and deployment process. Practice manual images, Azure VM Image Builder, Azure Compute Gallery, image changes, and how new session hosts are created from the current approved version.
Treat image updates like application releases. Test, version, stage, deploy to a subset, monitor, and maintain a rollback option. A single bad image can affect many users quickly, which makes lifecycle discipline more important than one successful build.
Create a golden-image checklist covering OS updates, agents, Microsoft 365 Apps, security tooling, optimization, validation, and version tags. Then deploy a small canary host pool before broad rollout.
Track image lineage so operators can answer which users were on which version during an incident. This makes rollback and root-cause analysis far easier than treating every session host as an individually maintained server.
The exam includes application groups, RemoteApp, Microsoft 365 Apps, OneDrive, Teams, browsers, App attach, user settings, printing, redirection, and client selection. Candidates need to think about how users consume applications rather than only how hosts are provisioned.
The existing Azure Virtual Desktop provides useful context. Hands-on practice should go further by publishing an application, assigning users, testing redirection, and diagnosing one app-specific failure.
Use App attach or another controlled application method to separate image lifecycle from application lifecycle. Then update the application without rebuilding the base image. This demonstrates why administrators may choose dynamic delivery for frequently changing applications.
Test Microsoft 365 Apps and Teams in multi-session conditions because user profile, caching, media optimization, and update behavior can differ from a normal single-user PC. AVD expertise includes those operational differences.
Azure Monitor and AVD Insights help administrators evaluate capacity, active sessions, host health, user experience, and operational trends. Practice collecting relevant logs and deciding which signals indicate a user problem versus normal load variation.
Autoscaling should be tied to capacity and business hours rather than enabled without thought. Define minimum availability, expected peak users, startup time, cost goals, and how the system behaves when demand appears outside the normal schedule.
Use synthetic or repeatable user actions to compare performance before and after scaling changes. CPU utilization alone may not reflect sign-in delay, profile load time, or application responsiveness.
Autoscaling rules should also account for maintenance and update windows. A host that is supposed to drain for patching should not be automatically returned to service because a simplistic rule sees high demand.
The current blueprint includes backup and restore for FSLogix profiles, personal desktops, and images, plus multi-Region planning. A recovery plan should identify which components are stateful and what the user loses if each one is unavailable.
Run a tabletop exercise: a region or storage dependency becomes unavailable. Decide how users reconnect, where profiles come from, which images are available, how DNS or networking changes, and what operations team validates before declaring recovery complete.
Include personal desktops separately from pooled desktops in the recovery design. A pooled host can often be recreated from image and policy, while a personal desktop may contain state or ownership assumptions that require a different backup strategy.
Perform at least one restore test for a profile or desktop component. A backup that has never been restored is only an assumption about recoverability.
Include communication and support ownership in the recovery plan. Users need to know when they can reconnect, help-desk teams need a status they can trust, and administrators need a clear decision point for returning to the primary environment. Recovery is an operational process, not only a technical failover.
Architectural depth should support, not replace, AVD operations.
The AZ-305 exam is an adjacent architecture role. AZ-140 candidates benefit from understanding design tradeoffs, but their certification is operational: plan, deliver, manage, secure, and monitor the virtual desktop experience.
The Microsoft certification inventory can help you see related Azure roles. For AZ-140, keep the study plan centered on the user session from identity and network through host, profile, app, monitoring, and recovery.
A useful final lab is to hand the environment to another administrator with only your runbook. If they can add capacity, replace an image, restore a profile, investigate a failed sign-in, and identify the current host-pool state, the design is becoming operable.
That operational handoff is the real scope of AZ-140: not just building virtual desktops, but delivering a repeatable service that survives normal changes, user growth, and component failure.
Before the exam, walk through one complete user journey from authentication to session assignment, profile load, application access, monitoring, sign-out, and later recovery. If you can identify the responsible Azure service and likely evidence at every step, the individual objectives stop feeling like separate topics.
User experience is the final test of the infrastructure.
Keep the user journey visible during every troubleshooting decision.
The best AZ-140 preparation ends with a service you can operate, support, and recover—not merely a host pool you managed to create.