You can connect an Azure Virtual Desktop to an on-premises network using a virtual private network (VPN), or use Azure ExpressRoute to extend the on- premises network into the Azure cloud over a private connection. * Azure AD: Azure Virtual Desktop uses Azure AD for identity and access management. Azure AD integration applies Azure AD security features like conditional access, multi-factor authentication, and the Intelligent Security Graph, and helps maintain app compatibility in domain-joined VMs. * Azure Virtual Desktop, enable Microsoft Defender for Cloud. We recommend enabling Microsoft Defender for Cloud's enhanced security features to: Manage vulnerabilities. Assess compliance with common frameworks like PCI. * Microsoft Defender for Cloud Apps, formerly known as Microsoft Cloud App Security, is a comprehensive solution for security and compliance teams enabling users in the organization, local and remote, to safely adopt business applications without compromising productivity. Reference: https://docs.microsoft.com/en-us/azure/architecture/example-scenario/wvd/windows-virtual- desktop https://docs.microsoft.com/en-us/azure/virtual-desktop/security-guide https://techcommunity.microsoft.com/t5/security-compliance-and-identity/announcing-microsoft- defender-for-cloud-apps/ba-p/2835842