DP-300 Plan and implement data platform resources Practice Question
Which TWO actions are required to enable Microsoft Entra ID authentication for an Azure SQL Database?
⚠ Common exam trap
Candidates often select only the admin assignment or mistakenly choose Microsoft Entra ID Only mode. Enabling Microsoft Entra ID authentication requires both assigning an Entra ID admin and then creating contained database users mapped to Entra ID identities. Microsoft Entra ID Only mode is an optional hardening step.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Create contained database users mapped to Microsoft Entra ID identities
To enable Microsoft Entra ID authentication for an Azure SQL Database, you must first assign a Microsoft Entra ID user or group as the Azure SQL Database admin (Option B). After the admin is assigned, you create contained database users mapped to Microsoft Entra ID identities in the database (Option A) so those identities can authenticate. Setting the database's authentication mode to 'Microsoft Entra ID Only Authentication' (Option C) is optional and enforces that only Microsoft Entra ID identities can connect; it is not required to enable Microsoft Entra ID authentication. Azure SQL Managed Instance (Option D) and registering an application in Microsoft Entra ID (Option E) are not required.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Create contained database users mapped to Microsoft Entra ID identities
Why this is correct
This is for granting access, not enabling authentication.
- ✓
Assign a Microsoft Entra ID user or group as the Azure SQL Database admin
Why this is correct
Assigning a Microsoft Entra ID user or group as the SQL Database admin is required to enable Microsoft Entra ID authentication. This step establishes the administrative identity that can manage authentication and users.
- ✗
Set the database's authentication mode to 'Microsoft Entra ID Only Authentication'
Why it's wrong here
Setting the authentication mode to 'Microsoft Entra ID Only Authentication' is optional. It enforces that only Microsoft Entra ID identities can connect, but it is not a requirement to enable Microsoft Entra ID authentication. The authentication mode can remain as 'SQL and Microsoft Entra ID authentication'.
- ✗
Deploy the database in Azure SQL Managed Instance
Why it's wrong here
Not required; any Azure SQL deployment supports Entra ID.
- ✗
Register the application in Microsoft Entra ID
Why it's wrong here
Not required for basic authentication.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Managed Instance
Azure SQL Managed Instance is a fully managed cloud database service that gives you nearly all the features of Microsoft SQL Server on your own server, without you having to manage the hardware or operating system.
Key term
Azure SQL Authentication
Azure SQL Authentication is the process of verifying a user's identity to access an Azure SQL database using either a username and password (SQL Authentication) or a Microsoft Entra ID (formerly Azure AD) identity.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.