DP-300 Configure and manage automation of tasks Practice Question
You are the database administrator for a logistics company that uses Azure SQL Database. A nightly Azure Automation runbook must trigger a stored procedure in the database after each successful run. The runbook authenticates to Azure using a system-assigned managed identity for the Automation account. You need to grant the managed identity the least-privilege permissions required to execute the stored procedure. Which two actions should you perform? (Choose two.)
⚠ Common exam trap
The trap here is assuming an Azure RBAC role such as Contributor on the logical server grants T-SQL execution rights, when management-plane roles never provide data-plane permissions.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Run GRANT EXECUTE ON OBJECT::dbo.usp_ProcessShipments TO [automation-account-name] in the target database.
Managed identities for Azure Automation require a contained database user mapped via FROM EXTERNAL PROVIDER before permissions can be granted. Once that user exists, the least-privilege permission for running a single stored procedure is EXECUTE on that object. Together these two actions let the runbook invoke the procedure without over-provisioning rights or introducing stored credentials.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Store the database administrator password in an Automation variable and use SQL authentication in the runbook.
Why it's wrong here
Using SQL authentication with a stored password introduces secret management overhead and contradicts the intent to use the managed identity. It also violates least-privilege principles because the administrator login has far more rights than needed. The scenario specifically established a managed identity, so this manual credential approach is inappropriate.
- ✗
Create a database user for the managed identity and add it to the db_owner fixed database role.
Why it's wrong here
Granting db_owner gives the managed identity full control over the database, far exceeding the permission needed to run a single stored procedure. Least privilege requires only EXECUTE on that procedure. This approach would work functionally but fails the stated least-privilege requirement, making it an incorrect choice for this scenario.
- ✗
Assign the managed identity the Contributor role on the Azure SQL logical server resource.
Why it's wrong here
Azure RBAC roles such as Contributor control the management plane, not the data plane. They do not grant permission to execute T-SQL stored procedures inside the database. The runbook needs a database principal with EXECUTE permission, so this role assignment is irrelevant and does not satisfy the requirement.
- ✓
Run GRANT EXECUTE ON OBJECT::dbo.usp_ProcessShipments TO [automation-account-name] in the target database.
Why this is correct
After the contained database user exists for the managed identity, the minimal data-plane permission needed to run the stored procedure is EXECUTE on that specific object. This grants exactly the required capability without broader rights, satisfying least privilege for the Automation runbook scenario described.
- ✓
Connect to the database as a Microsoft Entra administrator and run CREATE USER [automation-account-name] FROM EXTERNAL PROVIDER.
Why this is correct
Because the Automation account uses a system-assigned managed identity, you must create a contained database user mapped to that identity before any permissions can be assigned. Only a Microsoft Entra administrator (or a user with sufficient permission) can execute CREATE USER FROM EXTERNAL PROVIDER for an Entra service principal, so this step is mandatory and correct.
Go deeper
Related to this question
Learn chapter
Deploying and Configuring Azure SQL Managed Instance
Key term
Azure SQL Performance Tuning
Azure SQL Performance Tuning is the process of optimizing the speed and efficiency of queries and database operations in Microsoft Azure SQL Database or SQL Managed Instance to reduce latency and improve throughput.
About these practice questions
This DP-300 question is part of Courseiva's 574-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Microsoft exam blueprint
This DP-300 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the DP-300 exam.