AZ-500 exam dumps

AZ-500 practice question 172 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 172

Select 2

Your organization wants to enable Microsoft Entra (formerly Azure AD) authentication for an existing Azure SQL Database to reduce reliance on SQL logins. You have been asked to configure the database so that corporate employees who are members of a specific Microsoft Entra group can connect using their Microsoft Entra credentials. Which of the following actions are required to enable Microsoft Entra database authentication for the Azure SQL Database? (Choose two.)

  1. A

    Assign a Microsoft Entra admin for the Azure SQL server hosting the database

  2. B

    Configure a server Managed Identity specifically for Microsoft Entra database authentication

  3. C

    Create a firewall rule dedicated to allowing only Microsoft Entra authentication

  4. D

    Create a contained database user mapped to a Microsoft Entra identity or group

Show answer and explanation

Correct answers: A, D

Explanation

To enable Microsoft Entra (Azure AD) database authentication for Azure SQL Database, you first configure a Microsoft Entra admin at the logical server level. Then, you create contained database users that map directly to the Microsoft Entra identities (users or groups). These steps allow authenticated Microsoft Entra principals to connect without SQL Server logins. For more details, see Microsoft documentation at https://learn.microsoft.com/azure/azure-sql/database/authentication-aad-overview.

  • A. Correct.

    Correct. You must designate a Microsoft Entra admin at the server level before you can grant Microsoft Entra users or groups access to the database. This is a prerequisite for enabling Microsoft Entra-based authentication.

  • B. Incorrect.

    Incorrect. Configuring a Managed Identity for the server is separate from enabling Microsoft Entra database authentication for users. While Managed Identities can be used in other scenarios (for example, for automation or service connections), they are not required for granting interactive Microsoft Entra database access.

  • C. Incorrect.

    Incorrect. You do not need a special firewall rule explicitly for Microsoft Entra authentication. Azure SQL Database firewall rules typically restrict allowed client IP addresses, but they do not differentiate between SQL logins and Microsoft Entra logins.

  • D. Correct.

    Correct. After setting a Microsoft Entra admin at the server level, you must create contained database users mapped to the relevant Microsoft Entra identities or groups. This step allows those identities to authenticate using Microsoft Entra credentials.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam