Microsoft DP-300: What the Blueprint Covers

DP-300 remains the live Microsoft exam for administering Azure SQL solutions. As of October 4, 2026, the current English skills are the April 24, 2026 version. Microsoft has already published a future October 27 update, so candidates testing before that date should keep the April blueprint as the source of truth. The current DP-300 weights are 15–20% Plan and implement data platform resources, 20–25% Implement a secure environment, 20–25% Monitor/configure/optimize resources, 15–20% Automate tasks, and 20–25% Plan/configure HA/DR.

Microsoft requires a score of 700 or greater to pass. The audience is an Azure database administrator responsible for cloud and hybrid relational databases across Azure SQL Database, Azure SQL Managed Instance, SQL Server on Azure VMs, and SQL Server on-premises.

Data-platform planning is 15–20%

The first domain covers selecting Azure SQL offerings, automated deployment, Azure Arc-enabled SQL services, Azure SQL Database in Microsoft Fabric, table partitioning, sharding, hybrid deployment, patching, scaling, compression, and migration strategy.

A DP-300 Azure SQL foundation begins with matching the service and deployment model to business, compatibility, availability, and operational requirements.

Migration is part of resource planning

Candidates should evaluate requirements, choose online or offline strategies, migrate to Azure or between Azure SQL services, use Managed Instance database copy/move where appropriate, and troubleshoot migration.

An on-premises SQL migration model should include assessment, compatibility, downtime, data validation, application connection changes, and rollback.

Security is 20–25%

The security domain covers Microsoft Entra authentication, SQL authentication scenarios, security principals, users from Entra identities, least privilege, T-SQL authorization, TDE, object-level encryption, firewalls, Always Encrypted, VBS enclaves, Private Link/service endpoints, data classification, auditing, change data tracking, dynamic data masking, ledger, and row-level security.

The scope combines identity, network, cryptography, and compliance controls around the database service.

Authentication and authorization should be separated

Entra or SQL authentication establishes who the principal is; database/server permissions determine what that principal can do. A login that succeeds can still be correctly denied access to an object by least-privilege authorization.

Troubleshooting should identify whether the failure is identity, firewall/network, database user mapping, or object permission.

Monitoring and optimization are 20–25%

The current guide includes operational baselines, performance metrics, database watcher, Extended Events, Query Store, blocking, DMVs, index changes, query modifications, execution plans, Intelligent Insights, index/statistics maintenance, integrity checks, automatic tuning, server/database configuration, scaling, Resource Governor, and intelligent query processing.

Performance work begins with evidence, not an automatic “add an index” response.

Query Store and execution plans are central performance tools

Query Store helps track query history, plans, and runtime performance over time, while execution plans show how SQL Server chooses to execute a statement. DMVs, blocking information, waits, and metrics provide additional context.

A DP-300 roadmap should include reading enough T-SQL and plan evidence to identify the limiting layer.

Automation is 15–20%

This domain covers SQL Server Agent jobs, schedules, alerts, troubleshooting, ARM/Bicep, PowerShell, Azure CLI, deployment monitoring, elastic jobs, automated database tasks, and alerting around task failures.

The DBA should automate repeatable maintenance and deployment while preserving logging, credentials, and rollback.

HA/DR is 20–25%

Candidates should select HA/DR strategies from RPO/RTO, evaluate hybrid and Azure-specific options, plan testing, perform native backup/restore and point-in-time recovery, configure long-term retention, use cloud storage, and manage active geo-replication, availability groups, failover groups, failover cluster instances, and log shipping.

Availability and disaster recovery should follow business recovery requirements rather than product preference.

Backup is not the same as high availability

Backups provide recoverable data after deletion, corruption, or other loss, while high-availability mechanisms reduce service interruption from infrastructure or platform failure. Many critical databases need both.

Recovery procedures should be tested because a backup file alone does not prove the application can resume within its RTO.

Current DP-300 is an operational database exam

The exam expects candidates to deploy, secure, monitor, tune, automate, migrate, and recover Azure SQL and hybrid SQL environments. It is neither a pure T-SQL developer exam nor an Azure architecture survey.

The current audience profile explicitly includes SQL Server on Windows and Linux Azure VMs plus on-premises SQL Server. That makes DP-300 a hybrid administration exam: candidates need to know what Azure manages for PaaS offerings and what remains the DBA’s responsibility in IaaS or on-premises deployments.

Service selection should begin with compatibility and operational responsibility. Azure SQL Database minimizes infrastructure administration, Managed Instance provides broader SQL Server compatibility in a managed service, and SQL Server on Azure VMs preserves operating-system and instance-level control at the cost of more management.

Azure Arc-enabled SQL services appear because Microsoft extends management and governance to selected SQL resources outside native Azure PaaS. Candidates should understand the use case—centralized Azure control/visibility for hybrid data estates—without treating Arc as a replacement for the database engine itself.

Azure SQL Database in Microsoft Fabric also appears in the current guide, reflecting integration between operational relational data and Fabric experiences. At DP-300 depth, the relevant skill is recognizing deployment/use cases and administrative implications rather than becoming a Fabric analytics specialist.

Table partitioning and sharding address different scale problems. Partitioning organizes one logical table inside a database and can improve manageability/performance; sharding distributes data across multiple databases when one database is not the right scale boundary. The DBA should not use the terms interchangeably.

Compression can reduce storage and I/O, but it consumes CPU for compression/decompression. The right choice depends on workload characteristics. DP-300 scenarios often reward measuring resource pressure before applying a feature that moves cost from one resource to another.

Migration planning should also include connectivity and application dependencies. A database may migrate successfully while the application still points to the old server, firewall rules block the target, or logins/users are incomplete. Post-migration validation should include both data and client connectivity.

Managed Instance copy and move operations are current objectives because they can simplify selected migration or operational scenarios inside Azure. Candidates should still understand when full migration tooling, backup/restore, replication, or other methods are more appropriate.

Entra authentication reduces dependence on SQL passwords and can integrate Azure identity governance, but database users/permissions still need correct mapping. A successful Entra sign-in does not automatically grant database access.

Always Encrypted protects selected sensitive columns from the database engine or administrators that should not see plaintext, depending on configuration. VBS enclaves extend supported operations on protected data. This is different from TDE, which protects database files at rest but decrypts data for the engine.

Private Link and service endpoints are also a useful network-security contrast. Private endpoints bring the service onto a private IP path, while service endpoints extend VNet identity to the service’s public endpoint model. DNS can determine whether a client actually uses the private endpoint.

Dynamic data masking changes how query results appear to selected users but is not an encryption control. Row-level security filters rows according to policy; classification labels sensitive data; auditing records activity. DP-300 expects candidates to match the control to the confidentiality or compliance requirement.

Ledger introduces tamper-evidence capabilities around data changes. It is useful for integrity and verification scenarios, not as a universal replacement for backup, auditing, or access control. The DBA should recognize which assurance question ledger helps answer.

Database watcher is a current monitoring objective that provides fleet-oriented monitoring for Azure SQL environments. It complements native metrics, Query Store, Extended Events, and other diagnostic sources. The DBA should choose evidence according to whether the question is resource, query, blocking, or historical plan behavior.

Blocking should be distinguished from slow execution. One query can be fast in isolation yet wait behind another transaction. Session/blocking analysis and DMVs help identify the blocking chain before the DBA tunes indexes or increases compute unnecessarily.

Automatic tuning can apply or recommend selected performance corrections in supported Azure SQL environments. It should still be monitored because a previously beneficial plan or index change can become inappropriate as the workload evolves.

Resource Governor applies to SQL Server/Managed Instance-style environments where workloads may need resource governance. Database-scoped configuration and intelligent query processing provide other tuning levers. The exam expects the DBA to know which platform supports which control.

SQL Server Agent remains important for SQL Server and Managed Instance operational jobs, while elastic jobs or Azure automation can coordinate work across Azure SQL Database scenarios. The automation mechanism should match the service platform rather than forcing one job system everywhere.

Infrastructure deployment through ARM/Bicep, PowerShell, and CLI reflects modern DBA responsibilities beyond T-SQL. Database resources, networking, identities, and configuration increasingly need repeatable deployment alongside schema and data operations.

HA/DR testing should be planned, not improvised. Failover groups, geo-replication, availability groups, FCI, log shipping, or backup recovery all need documented tests that confirm applications can reconnect and data loss remains within the intended RPO.

Long-term retention belongs on the backup lifecycle branch. Operational point-in-time restore may cover days or weeks, while regulatory or business requirements can require much longer retention. Storage cost and restore procedures should be understood before policy is applied broadly.

The future October 27 update should be treated as a date boundary. The current April 24 blueprint remains authoritative on October 4. Candidates testing later should compare Microsoft’s future change log and refresh only the affected objectives rather than blending both versions in one study plan.

Within the broader Microsoft certification path, the Azure SQL administration role is hands-on and evidence-driven. Candidates testing after October 27 should refresh against Microsoft’s updated skills rather than relying on the April version.