Courseiva

Azure SQL Managed Instance Windows Integrated Authentication without Storing Credentials

Your company develops a web application hosted on Azure App Service. The application uses Azure SQL Database and requires managed identities to access the database. You need to ensure that the application can authenticate to Azure SQL without storing credentials in code. Which authentication method should you implement?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Enable system-assigned managed identity on the App Service and grant it access to the SQL database.

Enabling a system-assigned managed identity on the Azure App Service creates an identity in Microsoft Entra ID tied to the app's lifecycle, and that identity can be granted access to Azure SQL Database (for example, by creating a contained database user with CREATE USER [app-name] FROM EXTERNAL PROVIDER and assigning db_datareader/db_datawriter roles), letting the app authenticate without storing any credentials in code. This is the recommended passwordless approach for App Service to Azure SQL. Option A still requires managing and referencing a client certificate, which is credential material rather than eliminating secrets. Option B uses a service principal with a client secret, which is exactly the stored credential the scenario wants to avoid. Option C only restricts network access via firewall rules and does not provide authentication or authorization to the database.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Store a client certificate in Azure Key Vault and reference it from the app.

    Why it's wrong here

    Although storing a client certificate in Key Vault centralizes secret storage, the certificate remains a secret that must be loaded into the App Service and presented during authentication. The app must still handle the certificate's private key, lifecycle, and rotation, and the certificate must be mapped to an Microsoft Entra ID application if used for SQL authentication. This approach does not eliminate credential management—it only relocates the certificate, so it still leaves the application with a deployable secret rather than using an identity.

  • ✗

    Use an Microsoft Entra ID service principal with a client secret.

    Why it's wrong here

    A service principal with a client secret is a static, symmetric credential that must be stored in configuration or environment variables, rotated periodically, and protected from leakage in logs or client code. The application must explicitly implement the OAuth 2.0 client-credentials flow, retrieve the secret, and call Microsoft Entra ID to obtain a token for the SQL database. Unlike a managed identity, this approach leaves the developer responsible for secret management and exposes a long-lived secret that can be misappropriated.

  • ✗

    Use Azure SQL database-level firewall rules with a static IP restriction.

    Why it's wrong here

    Database-level firewall rules with a static IP restriction only control which network endpoints can reach the SQL server; they do not authenticate the App Service or remove the need for SQL credentials. Azure App Service outbound IPs can vary (or require a Premium feature for a reserved static IP), and an IP rule is not an identity, so the application would still have to supply a username/password or AAD credential. This is a network control, not a credential-free authentication mechanism, and it can be bypassed or fail when IP ranges change.

  • ✓

    Enable system-assigned managed identity on the App Service and grant it access to the SQL database.

    Why this is correct

    A system-assigned managed identity gives the App Service a Microsoft Entra ID (Azure AD) identity that is automatically created with the app and requires no secrets to be stored in code or configuration. You enable Microsoft Entra authentication on the SQL logical server, then run `CREATE USER [<app-name>] FROM EXTERNAL PROVIDER` to map the identity to a database user and grant least-privilege roles like `db_datareader` and `db_datawriter`. The connection uses token-based authentication (for example, `Authentication=ActiveDirectoryManagedIdentity` in the connection string), eliminating credential storage and rotation.

About these practice questions

Courseiva writes every SC-100 question from scratch — 605 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SC-100 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SC-100 exam.