Microsoft Certified: Azure Security Engineer AssociateSecure data and applicationsEasy

A financial institution is migrating its legacy database to Azure SQL Database. Due to strict compliance policies, all connections to the database must exclusively use Azure Active Directory (AAD) authentication, and local SQL authentication (username/password) must be completely disabled. How can this be enforced for the Azure SQL Database server?

  1. ARemove all SQL logins from the 'master' database.
  2. BSet 'Azure Active Directory-only authentication' to 'Enabled' on the SQL server.
  3. CConfigure firewall rules to block SQL authentication ports.
  4. DImplement Azure Private Link for the SQL Database.
Show answer & explanation

Correct answer: B. Set 'Azure Active Directory-only authentication' to 'Enabled' on the SQL server.

Azure SQL Database servers have a specific setting called 'Azure Active Directory-only authentication' which, when enabled, completely disables SQL authentication and mandates that all connections must use Azure AD identities. This directly meets the requirement to exclusively use AAD authentication and disable local SQL authentication.

Why the other options are wrong

  • A. While removing SQL logins is a good practice, the 'Azure Active Directory-only authentication' setting provides a server-level enforcement mechanism that prevents new SQL logins or existing ones from functioning.
  • C. Firewall rules control network access, not the authentication method used once a connection is established.
  • D. Azure Private Link secures network connectivity but does not dictate the authentication method used by clients.

Azure AD-only Authentication for Azure SQL

A server-level setting for Azure SQL Database and Azure Synapse Analytics that disables SQL authentication and enforces the exclusive use of Azure Active Directory identities for all database connections.

  • Disables SQL authentication entirely.
  • Mandates Azure AD for all connections.
  • Configured at the SQL server level.

Memory trick: AAD-only auth is like a 'VIP pass' for your SQL DB, only letting AD identities in.

More Secure data and applications questions