How should Azure SQL elastic jobs access a target database with Conditional Access?
You have an Azure subscription that contains an Azure SQL database named DB1. You need to host elastic jobs by using DB1. DB1 will also be configured as a job target. The solution must support the use of location-based Conditional Access policies. What should the elastic jobs use to access DB1?
Community Votes
100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.
Community Insight
The question tests the intersection of elastic job authentication and Conditional Access support; the trap is assuming any managed identity or SQL credential is sufficient, when only a user-assigned managed identity can be bound to Conditional Access policies.
Azure SQL elastic jobs require a credential to connect to target databases, and when location-based Conditional Access policies must be honored, a user-assigned managed identity is the correct choice because it integrates with Microsoft Entra ID and supports Conditional Access.
Many candidates choose system-assigned managed identity (A) because it is simpler to configure, but system-assigned identities cannot be independently targeted by Conditional Access policies, which require a user-assigned identity.
Community Discussion (3 comments)
Comments & Corrections
No comments yet — spotted an error or have a note? Share it below.
Expert Analysis
Why the Answer Is Correct
A user-assigned managed identity (D) is a standalone Microsoft Entra ID object that can be directly referenced in Conditional Access policies, including location-based restrictions. Elastic jobs can authenticate to Azure SQL using this identity via contained database users mapped to the managed identity. This satisfies both the elastic job requirement and the Conditional Access requirement.Why the Other Options Are Wrong
Option A (system-assigned managed identity) is tied to the lifecycle of the job agent resource and cannot be independently targeted by Conditional Access policies. Option B (Azure SQL sign-in credentials) relies on SQL authentication, which bypasses Microsoft Entra ID entirely and therefore cannot honor Conditional Access. Option C (database-scoped credentials) is a legacy mechanism that stores SQL credentials inside the database and also cannot integrate with Conditional Access.Community Comment Notes
Comment [1] correctly highlights the key phrase "location-based Conditional Access policies" as the deciding factor. Comment [2] reinforces that only a user-assigned managed identity leverages Microsoft Entra ID in a way that Conditional Access can evaluate. Comment [3] simply confirms D as the correct choice.Official Reference
Exam Strategy
When a question mentions Conditional Access, always look for the option that integrates with Microsoft Entra ID as an independent identity object. System-assigned identities and SQL credentials cannot be evaluated by Conditional Access policies, so user-assigned managed identity is the only valid choice.
Related Analysis
Practice All DP-300 Questions
Access 105 questions with complete answers and detailed explanations.
View Full DP-300 Practice Test →