Planning and implementing infrastructure
- Network: assessing capacity and latency, RDP Shortpath and multipath, QoS policies, Private Link, troubleshooting connection issues
- Storage for user data: FSLogix components, storage accounts, file shares, Azure NetApp Files
- Planning host pools and session hosts: resource groups, operating system, licensing model, architecture, sizing
- Creating host pools – via the portal and automated with PowerShell, Azure CLI, ARM templates and Bicep
- Managing images: creating manually or with Azure VM Image Builder, updating, planning the lifecycle, Azure Compute Gallery
Identity and security
- Identity scenarios: Active Directory Domain Services, Microsoft Entra ID, Entra Domain Services
- Role-based access control, Conditional Access policies, single sign-on
- Authentication: passwordless, smart card, multi-factor
- Securing session hosts with Microsoft Defender for Cloud, Defender Antivirus and Defender for Endpoint
- Network security with user-defined routes, network security groups and Azure Firewall; Azure Bastion and just-in-time access
- Confidential VMs and Trusted Launch
User environment and applications
- FSLogix: Profile Container, ODFC Container, Cloud Cache, Application Masking
- Selecting, distributing and troubleshooting clients; device and multimedia redirection, printing and Universal Print
- User settings via Intune policies or group policies, RDP properties, session time limits, Start VM on Connect
- Deploying applications: application groups, publishing RemoteApp, app attach
- Microsoft 365 Apps, OneDrive and Microsoft Teams in multi-user environments
Operations and maintenance
- Logging and analysis, Azure Monitor and AVD Insights, custom workbooks
- Optimising capacity and performance, autoscaling in host pools
- Managing active sessions and application groups
- Update strategy, disaster recovery, multi-region operations, backup and recovery of FSLogix profiles, personal desktops and images