Courseiva

DP-300 Implement a secure environment Practice Question

You are the administrator for an Azure SQL Database. The security team requires that all authentication to the database use Microsoft Entra ID (formerly Azure AD) and that multi-factor authentication (MFA) be enforced. You need to configure the database to meet this requirement. What should you do first?

⚠ Common exam trap

The trap here is jumping to Conditional Access policies or contained users without first establishing the Microsoft Entra ID admin, which is the prerequisite for Entra ID authentication.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Set a Microsoft Entra ID admin for the Azure SQL logical server.

The first step to enable Microsoft Entra ID authentication for Azure SQL Database is to set a Microsoft Entra ID admin on the logical server. This admin can then manage Entra ID identities and create contained database users. MFA enforcement is achieved through Conditional Access policies in Microsoft Entra ID, but those policies only apply once Entra ID authentication is enabled. Therefore, setting the Entra ID admin is the prerequisite.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Enable Microsoft Entra ID authentication in the Azure SQL Database firewall settings.

    Why it's wrong here

    There is no such setting as enabling Microsoft Entra ID authentication in firewall settings. Firewall settings control network access, not authentication methods. Entra ID authentication is enabled by configuring an Entra ID admin on the logical server. This option misidentifies where the configuration is made.

  • ✗

    Configure a Conditional Access policy to require MFA for all users.

    Why it's wrong here

    A Conditional Access policy is used to enforce MFA, but it requires that Microsoft Entra ID authentication is already enabled for Azure SQL Database. Without setting an Entra ID admin, the database cannot use Entra ID authentication, so the policy would have no effect. Thus, this is not the first step.

  • ✓

    Set a Microsoft Entra ID admin for the Azure SQL logical server.

    Why this is correct

    To enable Microsoft Entra ID authentication for Azure SQL Database, you must first assign a Microsoft Entra ID admin at the server level. This admin can then create contained database users mapped to Microsoft Entra identities. Once set, clients can authenticate using Microsoft Entra ID, and MFA can be enforced through Conditional Access policies. This is the foundational step for Entra ID authentication.

  • ✗

    Create a contained database user for each Microsoft Entra ID user.

    Why it's wrong here

    Creating contained database users is a subsequent step after setting the Microsoft Entra ID admin. Without a server-level Entra ID admin, you cannot create Entra ID-based contained users. Therefore, this is not the first action. It is necessary but not sufficient on its own to enforce MFA, which is handled via Conditional Access.

Go deeper

Related to this question

About these practice questions

This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Microsoft exam blueprint

This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.