Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Microsoft DP-800 Exam - Topic 2 Question 13 Discussion

You have an Azure SQL database named SalesDB on a logical server named sales-sql01.You have an Azure App Service web app named OrderApi that connects to SalesDB by using SQL authentication.You enable a user-assigned managed identity named OrderApi-Id for OrderApi.You need to configure OrderApi to connect to SalesDB by using Microsoft Entra authentication. The managed identity must have read and write permissions to SalesDB.Which Transact-SQL statements should you run in SalesDB?
C) CREATE USER [OrderApi-Id] FROM EXTERNAL PROVIDER; ALTER ROLE db_datareader ADD MEMBER [OrderApi-Id]; ALTER ROLE db_datawriter ADD MEMBER [OrderApi-Id];
A) CREATE LOGIN [OrderApi-Id] FROM EXTERNAL PROVIDER; ALTER ROLE db_datareader ADD MEMBER [OrderApi-Id]; ALTER ROLE db_datawriter ADD MEMBER [OrderApi-Id];
B) CREATE USER [OrderApi-Id] WITH PASSWORD = 'P@ssw0rd!'; ALTER ROLE db_datareader ADD MEMBER [OrderApi-Id]; ALTER ROLE db_datawriter ADD MEMBER [OrderApi-Id];
D) CREATE LOGIN [OrderApi-Id] WITH PASSWORD = 'P@ssw0rd!'; ALTER SERVER ROLE sysadmin ADD MEMBER [OrderApi-Id];

Microsoft DP-800 Exam - Topic 2 Question 13 Discussion

Actual exam question for Microsoft's DP-800 exam
Question #: 13
Topic #: 2
[All DP-800 Questions]

You have an Azure SQL database named SalesDB on a logical server named sales-sql01.

You have an Azure App Service web app named OrderApi that connects to SalesDB by using SQL authentication.

You enable a user-assigned managed identity named OrderApi-Id for OrderApi.

You need to configure OrderApi to connect to SalesDB by using Microsoft Entra authentication. The managed identity must have read and write permissions to SalesDB.

Which Transact-SQL statements should you run in SalesDB?

Show Suggested Answer Hide Answer
Suggested Answer: C

For an Azure App Service using a user-assigned managed identity to connect to Azure SQL Database with Microsoft Entra authentication, the required database-side step is to create a database user from the external provider, then grant the needed database roles. Microsoft's Azure SQL documentation for managed identities states that to let a managed identity access the target database, you create a SQL user for that identity by using:

CREATE USER [<identity-name>] FROM EXTERNAL PROVIDER;

and then assign the appropriate roles.

That makes db_datareader and db_datawriter the right role grants here, because the requirement says the identity must have read and write permissions to SalesDB.

The other options are incorrect:

A uses CREATE LOGIN ... FROM EXTERNAL PROVIDER, which is not the right choice for this Azure SQL Database scenario; the documented pattern is to create a database user from the external provider.

B and D create SQL-authentication principals with passwords, which does not meet the Microsoft Entra managed-identity requirement.

D also grants sysadmin, which is a server-level overgrant and not appropriate for the stated read/write requirement.


Contribute your Thoughts:

0/2000 characters
Michell
2 days ago
I think we need to create a user from the external provider since we're using managed identity, but I'm not entirely sure if it's option A or C.
upvoted 0 times
...

Save Cancel