How should Azure SQL elastic jobs access a target database with Conditional Access?

You have an Azure subscription that contains an Azure SQL database named DB1. You need to host elastic jobs by using DB1. DB1 will also be configured as a job target. The solution must support the use of location-based Conditional Access policies. What should the elastic jobs use to access DB1?

  1. a system-assigned managed identity
  2. Azure SQL sign-in credentials
  3. database-scoped credentials
  4. a user-assigned managed identity Source Reference Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

The question tests the intersection of elastic job authentication and Conditional Access support; the trap is assuming any managed identity or SQL credential is sufficient, when only a user-assigned managed identity can be bound to Conditional Access policies.

Azure SQL elastic jobs require a credential to connect to target databases, and when location-based Conditional Access policies must be honored, a user-assigned managed identity is the correct choice because it integrates with Microsoft Entra ID and supports Conditional Access.

Many candidates choose system-assigned managed identity (A) because it is simpler to configure, but system-assigned identities cannot be independently targeted by Conditional Access policies, which require a user-assigned identity.

Community Discussion (3 comments)

JamC 👍 1 Selected: D
Answer is D as it best allows you to leverage Azure AD/Microsoft Entra.
Mtour 👍 1 Selected: D
a user-assigned managed identity
2f5c7cd 👍 2 Selected: D
"The solution must support the use of location-based Conditional Access policies"

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

A user-assigned managed identity (D) is a standalone Microsoft Entra ID object that can be directly referenced in Conditional Access policies, including location-based restrictions. Elastic jobs can authenticate to Azure SQL using this identity via contained database users mapped to the managed identity. This satisfies both the elastic job requirement and the Conditional Access requirement.

Why the Other Options Are Wrong

Option A (system-assigned managed identity) is tied to the lifecycle of the job agent resource and cannot be independently targeted by Conditional Access policies. Option B (Azure SQL sign-in credentials) relies on SQL authentication, which bypasses Microsoft Entra ID entirely and therefore cannot honor Conditional Access. Option C (database-scoped credentials) is a legacy mechanism that stores SQL credentials inside the database and also cannot integrate with Conditional Access.

Community Comment Notes

Comment [1] correctly highlights the key phrase "location-based Conditional Access policies" as the deciding factor. Comment [2] reinforces that only a user-assigned managed identity leverages Microsoft Entra ID in a way that Conditional Access can evaluate. Comment [3] simply confirms D as the correct choice.

Official Reference

Exam Strategy

When a question mentions Conditional Access, always look for the option that integrates with Microsoft Entra ID as an independent identity object. System-assigned identities and SQL credentials cannot be evaluated by Conditional Access policies, so user-assigned managed identity is the only valid choice.

Related Analysis

Practice All DP-300 Questions

Access 105 questions with complete answers and detailed explanations.

View Full DP-300 Practice Test →

← Back to DP-300 Study Guide