Courseiva

DP-300 Implement a secure environment Practice Question

Which THREE actions are required to configure Microsoft Entra ID authentication for an Azure SQL Database? (Choose three.)

⚠ Common exam trap

A common mix-up: candidates confuse network-level firewall rules with authentication configuration, incorrectly assuming that a special firewall rule is needed for Entra ID traffic, when in fact only IP-based rules are required for network access.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a Microsoft Entra ID administrator for the Azure SQL Database server.

Option B is correct because every Azure SQL logical server must have a Microsoft Entra ID administrator provisioned (via the server's Microsoft Entra ID admin setting) before Entra authentication can be used; this admin acts as the security principal authorized to manage Entra logins and users on the server. Option C is correct because, after the Entra admin is set, you must create contained database users (for example, CREATE USER [name] FROM EXTERNAL PROVIDER) in each target database and grant them permissions, since Entra principals are not automatically mapped to database-level access. Option D is correct because the Entra identity used to authenticate must belong to the same tenant as the Azure SQL server (or be a supported guest/B2B identity), as cross-tenant authentication is not supported for Azure SQL Database. Option A is incorrect because no special firewall rule for the 'Microsoft Entra ID service' is required; Entra authentication uses the existing SQL firewall rules for client connectivity, not a service-specific rule. Option E is incorrect because SQL authentication does not need to be enabled as a fallback — Entra-only authentication is fully supported and SQL auth can even be disabled.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Configure a firewall rule to allow connections from the Microsoft Entra ID service.

    Why it's wrong here

    Microsoft Entra ID authentication flows over the existing SQL endpoint on port 1433; no dedicated Entra ID service range or firewall rule is needed. Firewall rules are the correct action when restricting which client IP addresses may reach the logical server, not for enabling directory-based authentication.

  • ✓

    Set a Microsoft Entra ID administrator for the Azure SQL Database server.

    Why this is correct

    Microsoft Entra ID authentication requires a Microsoft Entra administrator assigned at the server level, since that identity governs directory-based logins for every database on the server. Without this administrator, contained database users cannot be created or authenticated.

  • ✓

    Create contained database users in the database mapped to Microsoft Entra identities.

    Why this is correct

    Contained database users map Microsoft Entra identities directly into the database, granting authentication without a server-level login. This satisfies the requirement to configure Entra ID authentication, since each Entra principal needs a corresponding contained user before it can connect.

  • ✓

    Ensure that the Microsoft Entra identity used to connect is a member of the same Microsoft Entra ID tenant as the server.

    Why this is correct

    Microsoft Entra authentication requires the connecting identity to reside in the same tenant as the logical server, because the server validates tokens against that specific tenant's issuer. Cross-tenant identities cannot authenticate unless guest accounts are provisioned, so this membership constraint must hold before configuring the Entra admin.

  • ✗

    Ensure that SQL authentication is enabled as a fallback.

    Why it's wrong here

    Microsoft Entra ID authentication replaces SQL logins for the chosen principal; leaving SQL authentication enabled is neither required nor a fallback the configuration demands. SQL authentication remains the right choice for legacy applications that cannot present Entra ID tokens, but it is not part of this setup.

Go deeper

Related to this question

About these practice questions

One of 574 original DP-300 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.