Which TWO actions are required to enable Microsoft Entra ID authentication for Azure SQL Database?
Microsoft Entra ID authentication requires a directory administrator designated on the logical server, since that identity governs token issuance and directory-based logins. Without this server-level administrator, Azure SQL Database cannot validate Microsoft Entra ID tokens, so the remaining configuration steps have no authority to authenticate against.
Why this answer
Setting a Microsoft Entra ID administrator for the logical server (Option A) is required because it establishes the Entra ID tenant as an identity provider for the Azure SQL Database logical server, enabling token-based authentication. Creating a contained database user mapped to an Entra ID identity (Option D) is required because Azure SQL Database uses contained database users for authentication, where the user is authenticated directly against the database without requiring a login in the master database. These two actions together allow Entra ID users to authenticate to the database using their cloud identities.
Exam trap
The trap here is that candidates confuse the on-premises SQL Server requirement of enabling 'contained database authentication' with Azure SQL Database, which always has this enabled, and they mistakenly think creating logins in master is necessary for Entra ID users when contained database users are the correct approach.