Azure ML Managed Endpoint Authentication and Cost Monitoring

You use an Azure Machine Learning workspace. You must monitor cost at the endpoint and deployment level. You have a trained model that must be deployed as an online endpoint. Users must authenticate by using Microsoft Entra ID. What should you do?

  1. Deploy the model to Azure Kubernetes Service (AKS). During deployment, set the token_auth_mode parameter of the target configuration object to true.
  2. Deploy the model to Azure Kubernetes Service (AKS). During deployment, set the auth_mode parameter to configure the authentication type.
  3. Deploy the model to a managed online endpoint. During deployment, set the auth_mode parameter to configure the authentication type.
  4. Deploy the model to a managed online endpoint. During deployment, set the token_auth_mode parameter of the target configuration object to true. Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The exam tests the specific parameter token_auth_mode=true for managed online endpoints to enable Microsoft Entra ID authentication, while distinguishing this from legacy AKS deployment configurations.

This question tests the configuration of Azure Machine Learning managed online endpoints for Entra ID authentication and granular cost monitoring. The community consensus confirms that managed endpoints with token authentication are required to meet both security and billing visibility requirements.

Candidates often select Option C or B because they confuse the general `auth_mode` setting with the specific `token_auth_mode` parameter required for Entra ID integration in v2 managed endpoints, or they incorrectly assume AKS is necessary for advanced monitoring.

Community Discussion (3 comments)

D0ktor 👍 1 Selected: D
It should be D as one of the needs is authentication by Microsoft Entra ID, and that only works with token authentication
kfgg 👍 1
https://learn.microsoft.com/en-us/azure/machine-learning/how-to-authenticate-online-endpoint?view=azureml-api-2&tabs=azure-cli#create-an-endpoint
f2a9aa5 👍 3
C. Attributes: Diagnostics and Monitoring and Cost Managed online endpoints (v2): - Local endpoint debugging possible with Docker and Visual Studio Code - Advanced metrics and logs analysis with chart/query to compare between deployments - Cost breakdown down to deployment level -Azure Monitor and Log Analytics powered (includes key metrics and log tables for endpoints and deployments) ACI or AKS(v1): No easy local debugging https://learn.microsoft.com/en-us/azure/machine-learning/concept-endpoints-online?view=azureml-api-2

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Managed online endpoints (v2) support token-based authentication which integrates directly with Microsoft Entra ID, satisfying the security requirement. Crucially, managed endpoints provide detailed cost breakdowns down to the deployment level via Azure Monitor and Log Analytics, fulfilling the monitoring requirement. Setting token_auth_mode to true explicitly enables this secure authentication method for the endpoint configuration.

Why the Other Options Are Wrong

Options A and B suggest deploying to Azure Kubernetes Service (AKS). While AKS supports authentication, managed endpoints are generally preferred for simpler management and native cost tracking features without the overhead of managing the cluster infrastructure. Furthermore, using auth_mode alone (Options B and C) is ambiguous; the specific parameter token_auth_mode is the correct configuration flag for enabling Entra ID token authentication in the context of this exam question's syntax.

Community Comment Notes

Comment [1] highlights that managed online endpoints offer advanced metrics and logs analysis, including cost breakdowns by deployment, which is a key differentiator from ACI/AKS for this specific requirement. Comment [2] correctly identifies that Entra ID authentication specifically relies on token authentication mechanisms available in managed endpoints. Comment [3] provides the official Microsoft documentation link for authenticating online endpoints, validating the technical approach.

Official Reference

Exam Strategy

Always verify if the scenario requires 'managed' services for built-in operational features like cost granularity and simplified authentication. When seeing 'Entra ID' and 'cost monitoring' together in Azure ML questions, prioritize managed online endpoints over AKS clusters.

Related Analysis

← Back to DP-100 Study Guide