Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A financial institution is migrating its legacy database to Azure SQL Database. Due to stringent regulatory requirements, all access to the database must be authenticated using Azure Active Directory (Azure AD) and enforce multi-factor authentication (MFA) for all users, including administrators. Which authentication method should be configured for the Azure SQL Database?

  1. AAzure Active Directory authentication with Managed Identity
  2. BSQL Authentication with username and password
  3. CAzure Active Directory-only authentication
  4. DWindows Authentication (Kerberos)
Show answer & explanation

Correct answer: C. Azure Active Directory-only authentication

Azure Active Directory-only authentication for Azure SQL Database mandates that all users, including administrators, authenticate using Azure AD identities. This inherently supports MFA enforcement through Azure AD Conditional Access policies.

Why the other options are wrong

  • A. Azure Active Directory authentication with Managed Identity is primarily for Azure services to authenticate to SQL Database, not for human users or administrators.
  • B. SQL Authentication does not support Azure AD identities or MFA enforcement.
  • D. Windows Authentication is not directly supported for Azure SQL Database for human users; it's typically for on-premises SQL Server integrated with AD.

Azure AD-only Authentication for Azure SQL

A configuration option for Azure SQL Database that enforces all connections to use Azure Active Directory identities for authentication, enabling MFA and centralized identity management.

  • Mandates Azure AD identities for all users and administrators.
  • Enables MFA enforcement via Azure AD Conditional Access.
  • Centralizes identity management with Azure AD.

Memory trick: Azure AD-only: Your SQL database's bouncer, only letting AD identities with MFA in.

More Secure data and applications questions