DP-300 Managed Identity Practice Question
Which of the following are valid methods to authenticate to Azure SQL Database using Microsoft Entra ID? (Select all that apply.)
⚠ Common exam trap
Candidates may think all four listed methods are valid for direct authentication to Azure SQL Database, but only managed identity and integrated authentication are directly supported without additional token acquisition steps.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Microsoft Entra ID managed identity
Microsoft Entra ID offers several authentication methods for Azure SQL Database. Managed identity (A) and integrated authentication (C) are directly supported without additional token acquisition steps. Certificate-based authentication (D) and password authentication (E) require an intermediate application or client library to obtain an Entra ID token, and are not considered direct authentication methods for Azure SQL Database. AD FS tokens (B) are not directly accepted; Entra ID must issue the token after authentication.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Microsoft Entra ID managed identity
Why this is correct
Microsoft Entra ID managed identity is a valid authentication method for Azure SQL Database because it enables an Azure resource (such as an App Service or VM) to acquire an Entra ID access token using its own system-assigned or user-assigned identity, without any explicit credentials stored in code or configuration. The resource's identity is provisioned as a contained database user or server-level login in SQL, and the token is presented to the database via the connection string, making it ideal for automated and background workloads. This method eliminates the overhead of managing secrets or rotating passwords, as the identity lifecycle is fully managed by Azure.
- ✗
Active Directory Federation Services (AD FS) token
Why it's wrong here
Incorrect. AD FS is a federation service; it does not directly issue tokens to Azure SQL Database. Entra ID issues tokens after authentication, and AD FS is one of many possible identity providers, but it is not a direct authentication method for Azure SQL Database.
- ✓
Microsoft Entra ID integrated authentication
Why this is correct
Microsoft Entra ID integrated authentication leverages the current Windows user context to obtain an Entra ID token through the Microsoft Authentication Library (MSAL), using Kerberos or NTLM as the underlying protocol without requiring a separate interactive login. The client application, such as SQL Server Management Studio or a .NET application, transparently requests a token for the SQL audit endpoint and passes it to Azure SQL Database, enabling seamless single sign-on for users already authenticated to their Windows domain. This method is best suited for interactive or user-driven scenarios on domain-joined machines, but it does not work for unattended services because it depends on the user's live Windows logon session.
- ✗
Microsoft Entra ID certificate-based authentication
Why it's wrong here
Incorrect. Certificate-based authentication is a method to authenticate to Entra ID, but it is not directly used for Azure SQL Database logins. A client application must first obtain an Entra ID token using the certificate, then present it to Azure SQL Database.
- ✗
Microsoft Entra ID password authentication
Why it's wrong here
Incorrect. Password authentication is a method to authenticate to Entra ID, but Azure SQL Database does not accept passwords directly. A user must first obtain an Entra ID token via a client application using password authentication, then present the token.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
Courseiva writes every DP-300 question from scratch — 574 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.