Question 1
A financial services company is deploying a pooled Azure Virtual Desktop host pool for its traders. A key requirement is that all RDP traffic between the clients and session hosts must be encrypted and must not traverse the public internet at any stage, including the connection through the Azure Virtual Desktop service. The company has an ExpressRoute connection (private peering) between their on-premises network and the Azure virtual network where the session hosts reside. Which configuration should be implemented to meet these requirements?
Answer and explanation
Correct answer: D
With Private Link, a private endpoint for the host pool's connection sub-resource lets both clients and session hosts reach the Azure Virtual Desktop service over private routes. Clients on the on-premises network reach that private endpoint over ExpressRoute or VPN, so remote session traffic stays on the Microsoft network instead of the public internet. RDP is always encrypted with TLS (TLS 1.2 minimum to the service). RDP Shortpath for managed networks alone isn't enough: every connection starts with a TCP reverse-connect transport through the Azure Virtual Desktop gateway's public endpoints and falls back to it if UDP fails. You can combine Shortpath with Private Link by using the host pool's UDP opt-in. Shortpath for public networks uses the internet, and forcing client traffic through a VPN gateway doesn't make the service endpoints private.