QuestionQ45

Implement a secure environment

You have an Azure SQL database named DB1.

A user named User1 has an Azure Active Directory (Azure AD) account.

You need to enable User1 to add and remove columns in the tables in DB1. The solution must follow the principle of least privilege.

Which two actions should you take? Each correct answer represents part of the solution.

NOTE: Each correct selection is worth one point.

Choose two
Explanation

A Microsoft Entra user can be created as a contained database user in Azure SQL Database. Membership in db_ddladmin grants the database DDL permissions needed to alter table definitions, including adding or dropping columns, while db_owner would grant unnecessary full control of the database.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!