AZ-140 Cheat Sheet 2026: Quick Reference
Every domain condensed to a table, plus the identity-scenario decision and FSLogix container-type reference the exam tests directly.
Exam Snapshot
The domain weights, terminology, and reference links here come straight from Microsoft's official AZ-140 exam page. We re-check them against our audited 500-question AZ-140 practice bank so nothing drifts out of date.
1. Plan and Implement AVD Infrastructure (40-45%)
| Concept | Area | Quick note |
|---|---|---|
| RDP Shortpath / Multipath / QoS | Networking | Optimizing the remote session network path |
| Azure Private Link | Networking | Private connectivity to Azure Virtual Desktop |
| FSLogix storage, storage accounts, file shares, Azure NetApp Files | Storage | User data storage options — pick by scale and performance need |
| Host pool architecture planning | Host pools | Pooled vs. personal, sizing decisions |
| OS & licensing model recommendation | Host pools | Matching OS and licensing to requirements |
| Host pool/session host creation | Implementation | Portal, PowerShell, Azure CLI, ARM templates, or Bicep |
| Licensing config for session hosts | Implementation | User eligibility and RDS CAL requirements |
| Session host image creation | Images | Manual build or Azure VM Image Builder |
| Image lifecycle management & updates | Images | Keeping images current over time |
| Azure Compute Gallery | Images | Image storage and distribution across regions |
2. Plan and Implement Identity and Security (15-20%)
| Concept | Area | Quick note |
|---|---|---|
| Identity scenario selection | Identity | AD DS, Entra ID, or Entra Domain Services — see decision table below |
| Azure RBAC for AVD | Identity | Role assignment scope for AVD resources |
| Conditional Access policies | Identity | Access-control enforcement for AVD connections |
| Authentication options | Identity | Passwordless, smart card, and multifactor authentication |
| Microsoft Entra SSO | Identity | Single sign-on configuration |
| Microsoft Defender for Cloud | Security | Overall session host security posture |
| Defender Antivirus / Defender for Endpoint | Security | Two distinct endpoint-level protection layers |
| UDRs, NSGs, Azure Firewall | Security | Network security layers, each at a different level |
| Azure Bastion / just-in-time access | Security | Secure admin access to session hosts |
| Confidential VMs / Trusted Launch | Security | Hardware-level security features |
3. Plan and Implement User Environments and Apps (20-25%)
| Concept | Area | Quick note |
|---|---|---|
| FSLogix container types | User environments | Profile, ODFC, or Cloud Cache — see reference table below |
| App masking | User environments | Hiding specific apps from specific users |
| Client choice & deployment | User experience | Matching the AVD client to the device |
| Device & multimedia redirection | User experience | Local resource redirection into the session |
| Printing & Universal Print | User experience | Print configuration for AVD sessions |
| RDP properties & session timeout | User experience | Host pool-level session tuning |
| Start VM on Connect | User experience | On-demand VM power-on when a user connects |
| Application groups & RemoteApp | Apps | Publishing individual apps vs. a full desktop |
| App attach | Apps | Dynamic app delivery without installing into the base image |
| M365 Apps, OneDrive, Teams on AVD | Apps | Multisession-specific configuration needs |
4. Monitor and Maintain AVD Infrastructure (10-15%)
| Concept | Area | Quick note |
|---|---|---|
| Log collection & Azure Monitor | Monitoring | Central AVD telemetry |
| AVD Insights workbooks | Monitoring | Prebuilt dashboards, customizable |
| Autoscaling | Monitoring | Cost and capacity optimization for host pools |
| Active session & app group monitoring | Monitoring | Ongoing operational visibility |
| Update strategy for session hosts | Maintenance | Keeping hosts patched on a defined cadence |
| Disaster recovery & multi-region planning | Maintenance | Resiliency planning beyond a single region |
| Backup strategy | Maintenance | Covers FSLogix profiles, personal desktops, and images |
Identity Scenario Quick Decision
| Scenario | Use this |
|---|---|
| Fully on-premises AD, no cloud directory dependency desired for session hosts | Active Directory Domain Services (AD DS) |
| Cloud-only environment, no on-premises AD at all | Microsoft Entra ID (Entra-joined session hosts) |
| Need a managed domain-like service without deploying or maintaining domain controllers | Microsoft Entra Domain Services |
FSLogix Container Type Quick Reference
| Container type | Use for |
|---|---|
| Profile Container | The full user profile — the default, most common choice |
| ODFC Container | Splitting Office/OneDrive data separately from the profile, for granular control at scale |
| Cloud Cache | Adding redundancy by writing profile data to multiple storage locations |
Common Mistake: Defaulting to Profile Container at Scale
Profile Container is the right default for most host pools, and that's exactly why it's a trap in larger-scale scenario questions. Once a host pool grows into the hundreds of users, or Office/OneDrive data alone becomes large enough to slow logon times, sticking with a single Profile Container stops being the best answer — that's when ODFC Container earns its place, splitting Office and OneDrive data out for more granular control. Cloud Cache solves a different problem entirely: it's about redundancy, writing profile data to more than one storage location so a single storage outage doesn't strand every user. Mixing these up — picking ODFC when the question is really about redundancy, or Cloud Cache when it's really about splitting large data sets — is one of the more common ways candidates lose points on Domain 3.
AZ-140 Exam-Day Questions
How is this cheat sheet different from the AZ-140 study guide?
The study guide explains each domain in narrative form with a 6-week plan. This page is tables only, for a final scan before the exam.
What's the difference between FSLogix Profile Containers, ODFC, and Cloud Cache?
Profile Container holds the full profile and is the default. ODFC splits Office/OneDrive data out for granular control at scale. Cloud Cache adds redundancy by writing to multiple storage locations.
What's the fastest way to review right before the exam?
Scan the four domain tables plus the identity-scenario and FSLogix container-type tables — both distinctions show up repeatedly.
Can I print this AZ-140 cheat sheet?
Yes — every table here is plain HTML, so a browser print or "print to PDF" renders cleanly.
MSCertQuiz sells practice-exam access for AZ-140 and other Microsoft certifications; this cheat sheet is written by the same team that builds those questions.
More AZ-140 Resources
The 6-week plan behind this quick reference.
Scenario questions with detailed explanations.
A general Azure administration complement to this AVD specialty exam.
Full exam details and the complete 500-question practice bank.
Reviewed the cheat sheet? Now drill it.
Start with 40 free AZ-140 questions covering every domain above.
Start Free AZ-140 Practice