AZ-500 exam dumps

AZ-500 practice question 173 of 273

Microsoft Azure Security Technologies. Associate level, Microsoft. Free question with the correct answer and a full explanation.

AZ-500 Question 173

Select 2

You work as a security engineer for an organization that wants to enable Microsoft Entra (Azure AD) authentication for an Azure SQL Database to comply with multi-factor authentication requirements. Currently, the database only uses SQL authentication. Which two of the following steps must you perform to enable Microsoft Entra database authentication?

  1. A

    Configure an Azure AD admin at the Azure SQL server level

  2. B

    Enable a 'Microsoft sign-in' checkbox at the logical server settings

  3. C

    Create database-level firewall rules for the Azure AD domain controllers

  4. D

    Create a new user in Azure SQL Database using 'FROM EXTERNAL PROVIDER'

  5. E

    Reset all existing SQL-based user passwords to enforce reauthentication

Show answer and explanation

Correct answers: A, D

Explanation

To enable Microsoft Entra (Azure AD) authentication in Azure SQL Database, you must designate an Azure AD admin at the server level and then provision Azure AD users in the database. Once configured, Azure AD accounts can be granted necessary permissions, and multi-factor authentication policies enforced in Azure AD will also apply to database connections. For more information, refer to the Microsoft documentation on configuring Azure Active Directory authentication for Azure SQL Database.

  • A. Correct.

    Option 1 is correct. You must first configure an Azure AD admin at the Azure SQL server level, which grants the administrator the ability to manage Azure AD logins. This is a key step in enabling Azure AD authentication.

  • B. Incorrect.

    Option 2 is incorrect. There is no specific 'Microsoft sign-in' checkbox required for this process. Azure AD authentication is enabled through server-level configuration, not by toggling a single checkbox in the portal.

  • C. Incorrect.

    Option 3 is incorrect. You don't need to create database-level firewall rules for Azure AD domain controllers. Instead, you use standard Azure SQL Database firewall rules. Azure AD domain controllers do not require separate, specialized firewall rules for this.

  • D. Correct.

    Option 4 is correct. After setting the Azure AD admin, you need to create or map Azure AD user accounts in your Azure SQL Database using the 'FROM EXTERNAL PROVIDER' syntax to enable them to authenticate via Azure AD.

  • E. Incorrect.

    Option 5 is incorrect. Resetting passwords for existing SQL logins is not required to enable Azure AD authentication. Azure AD uses a different authentication flow, which is unaffected by local SQL password resets.

Timed practice exam

Take a AZ-500 practice test under exam conditions

70 questions in 100 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam