A security architect must prevent Azure Virtual Desktop (AVD) session hosts from initiating outbound connections to malicious domains. What is the most effective control?
-
A
Apply NSG rules blocking all outbound traffic on port 443
-
B
Route session host internet traffic through Azure Firewall with DNS proxy and FQDN-based application rules
-
C
Use Azure AD Conditional Access to restrict session host token issuance
-
D
Enable Microsoft Defender Antivirus on session hosts only