AZ-DEV-130: Azure SQL Database for .NET Developers
Comprehensive Azure SQL Database for .NET developers. Cover the full family (single database, elastic pool, Managed Instance, Hyperscale), Entity Framework Core 9 patterns, passwordless authentication with Managed Identity, performance tuning, DR/HA, security features (RLS, Always Encrypted, Auditing), and modern DevOps with SQL Database Projects and DACPACs.
About This Course
Azure SQL Database is the most-used relational database on Azure and the primary target for .NET applications with a relational data model. This course covers the full family single database, elastic pool, Hyperscale, Managed Instance from a .NET developer's perspective. Every lab uses Entity Framework Core 9 patterns with passwordless authentication via Managed Identity no connection strings with usernames and passwords anywhere in code.Beyond CRUD, the course goes deep on the topics working developers actually need: Query Store for diagnosing slow queries, execution plans, retry policies for transient faults, connection resiliency, sharding patterns via Elastic Database Tools, Row-Level Security for multi-tenant applications, and Always Encrypted for PII. The capstone builds a multi-tenant SaaS data layer with RLS + Always Encrypted + a full CI/CD pipeline using SQL Database Projects.By the end of this course you will be able to choose the right Azure SQL offering for a workload, build EF Core 9 domain models with connection resiliency and compiled queries, authenticate to Azure SQL passwordlessly with Managed Identity, diagnose and fix slow queries with Query Store, secure multi-tenant data with Row-Level Security, encrypt PII with Always Encrypted, test failover-group failover and PITR, and ship schema changes through a GitHub Actions pipeline built on SQL Database Projects.
Course Curriculum
20 Lessons
Azure SQL offerings - single database, elastic pool, Hyperscale, and Managed Instance
Learn the Azure SQL family end to end. This lesson walks through the differences between Azure SQL Database (single, elastic pool, Hyperscale), Azure SQL Managed Instance, and SQL Server on VMs — how they compare on features, compatibility, HA/DR, and cost — plus the DTU vs vCore purchasing models and the General Purpose, Business Critical, and Hyperscale service tiers. You will finish able to pick the right Azure SQL offering for a given .NET workload and defend the choice on IOPS, memory, storage, and reserved-capacity pricing.
Provision a General Purpose vCore Azure SQL Database and connect from .NET with a Managed Identity token - Lab Exercises
Note: This lab pre-provisions an empty resource group at start — allow up to 3 minutes for it to become ready before beginning the exercises.
Create an Azure SQL logical server and a General Purpose vCore serverless database yourself using the Azure CLI, then configure the firewall so Azure services can reach it. Flip the server to Entra ID admin auth, whitelist your client IP, and finally connect to it from a .NET 10 console app using Microsoft.Data.SqlClient and a Managed Identity access token acquired with DefaultAzureCredential. By the end you will have provisioned Azure SQL from the CLI and run a query against it from .NET code with zero credentials on disk or in configuration.
Entity Framework Core 9 with Azure SQL - DbContext, migrations, resiliency, compiled queries
Modern EF Core 9 patterns for Azure SQL. This lesson covers DbContext lifetimes, migrations (add-migration, script-migration for prod), connection resiliency via EnableRetryOnFailure, compiled queries for hot read paths, AsNoTracking() for read-only queries, and split-query vs single-query strategies. By the end you can build a production-ready EF Core data layer that survives transient Azure SQL faults and reads fast on the hot paths.
Build the Anchorline order model with EF Core 9 migrations and compiled queries - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Build a real EF Core 9 data layer against Azure SQL Database. You will scaffold a four-entity Anchorline order model, produce two migrations (one adds an index), script the migration to .sql for a controlled prod deploy, add a compiled query for the hot read path, and measure the throughput difference against a plain LINQ query. By the end you can defend when to use AsNoTracking, AsSplitQuery, and EF.CompileAsyncQuery.
Authentication and authorization - Managed Identity, contained users, and Row-Level Security
Passwordless authentication to Azure SQL from .NET is the modern default. This lesson covers the full auth stack: Managed Identity via Microsoft.Data.SqlClient, contained database users mapped to MI object ids, Entra ID group access + database roles, and Row-Level Security (RLS) with security predicates. By the end you know why "no connection strings with passwords" is achievable and how to configure the SQL server, the database, and the .NET app to make it work.
Wire an MI-backed ASP.NET Core API to Azure SQL as a contained user - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Take passwordless auth end to end. Deploy an ASP.NET Core minimal API to Azure App Service backed by a User-Assigned Managed Identity, add the MI as a contained database user in Azure SQL, grant table-level permissions, and confirm from within the app that queries execute under the MI's identity — no username, no password, anywhere.
Connection management - pooling, transient faults, and EF Core execution strategy
A production .NET app talking to Azure SQL will see transient errors — throttling, gateway failovers, brief service restarts. This lesson covers ADO.NET connection pooling, EF Core's EnableRetryOnFailure execution strategy, exponential backoff, the transient fault error codes SQL Server returns, and connection-string best practices for MI-authenticated apps. By the end you can explain why a canned "retry 3 times with 1s delay" pattern is inferior to SqlAzureExecutionStrategy and what the operational implications are.
Instrument EF Core retries and prove transient faults recover transparently - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Prove EnableRetryOnFailure handles transient Azure SQL faults without user-visible failures. You will inject synthetic transient errors via an IDbCommandInterceptor, watch EF Core retry with exponential backoff, contrast with a version that has retries disabled, then correctly wrap a multi-command transaction so retries do not break atomicity.
Performance tuning for developers - Query Store, execution plans, and indexes
Query Store is Azure SQL's built-in performance-history recorder. This lesson covers Query Store fundamentals (capture policy, retention, plan history), reading a query execution plan for the operators developers see most (Clustered Index Scan, Nested Loop, Hash Match, Key Lookup), covering nonclustered indexes as the go-to fix, and knowing when to reach for columnstore or in-memory OLTP. By the end you can read a slow-query plan, recognize the pattern that a covering nonclustered index would fix, and validate the fix worked.
Diagnose a slow query with Query Store and fix it with a covering index - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Diagnose a real slow query end-to-end. Load 1 M rows of synthetic order data, run a slow query that scans, use Query Store DMVs to identify it, examine the execution plan, add a covering nonclustered index, verify the plan changes, and measure the improvement. Target: 10x+ reduction in duration.
Scaling patterns - Hyperscale, named replicas, elastic pools, and sharding
When a single database is not enough. This lesson covers Business Critical read scale-out, Hyperscale's page-server architecture, Hyperscale named replicas for OLAP + reporting, elastic pools for many small databases, and the sharding pattern via Elastic Database Tools. By the end you can pick the right scaling pattern for a workload and defend the decision.
Route reads to a Hyperscale named replica and prove writes go to primary - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Take a Hyperscale database, create a named replica, wire an ASP.NET Core app with two connection strings (write vs read-only), then prove writes go to primary and reads route to the replica by inspecting @@SERVERNAME at both endpoints. By the end you have hands-on evidence of the write/read topology and a mental model for scaling reads without duplicating the storage.
Backup, HA, and DR - PITR, geo-restore, and failover groups
Everything you get for free (backups, RTO/RPO) and everything you configure yourself (PITR window, LTR policies, zone-redundant configuration, active geo-replication, failover groups). This lesson walks the spectrum from "I need last-hour recovery" to "I need automatic region-level failover with app-transparent endpoints." By the end you can size the RTO/RPO knobs to your workload's tolerances and explain the cost implications of each.
Test a failover-group failover and PITR-restore a dropped table - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Exercise both DR patterns hands-on. Configure an Azure SQL failover group across two regions, trigger a planned failover, watch the app reconnect through the failover-group listener without a connection-string change. Then simulate a data-corruption incident — drop a table — and use PITR to restore it as a new DB, then copy the table back to production.
Security deep-dive - TDE, Always Encrypted, auditing, and Advanced Threat Protection
Cover the full Azure SQL security stack: TDE (on by default), Always Encrypted with client-side keys managed in Azure Key Vault, Data Discovery + Classification for PII inventory, SQL Auditing to Log Analytics, Advanced Threat Protection, and private endpoints. By the end you know when each protects what — and why "encrypted at rest" and "encrypted from the DBA" are two very different threats.
Encrypt PII columns with Always Encrypted and prove the DBA sees only ciphertext - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Provision Key Vault + CMK, encrypt Customer.SSN and Customer.Email with Always Encrypted (deterministic on Email for equality lookup, randomized on SSN), configure the .NET app with an AE-enabled connection string, then prove Azure Portal sees ciphertext but the app sees plaintext.
DevOps for Azure SQL - SQL Database Projects, DACPAC, and GitHub Actions
The modern SQL DevOps stack: SDK-style SQL Database Projects (.sqlproj), DACPAC deployments, schema drift detection, GitHub Actions workflows that build a DACPAC on every PR and gate promotion behind manual approval. By the end you can wire up a full "schema change flows from a PR to prod" pipeline.
Ship a schema change with SQL Database Projects and sqlpackage - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 10 minutes for the environment to become ready before beginning the exercises.
Take the Anchorline schema, convert it to an SDK-style SQL Database Project, build a DACPAC, run sqlpackage /Action:DeployReport to preview the diff against dev, then deploy — and add a new column via a source-controlled change to observe how the DACPAC picks it up.
Multi-tenant SaaS data layer patterns - RLS, database-per-tenant, and blast radius
The architectural decisions behind a multi-tenant SaaS on Azure SQL. Compare database-per-tenant, shared-database-with-schema, and shared-database-with-RLS. Blast-radius, cost, isolation, backup, rollback — the tradeoffs that determine which one a company can operate at scale. By the end you can defend a specific choice and describe how to migrate between patterns as the business grows.
Ship the Anchorline multi-tenant SaaS data layer end-to-end - Capstone - Lab Exercises
Note: This lab pre-provisions Azure resources at start — allow up to 12 minutes for the environment to become ready before beginning the exercises.
Bring it all together. Build the Anchorline multi-tenant SaaS data layer using shared-database-with-RLS: TenantId on every business table, RLS security predicate + BLOCK, ASP.NET Core middleware that sets SESSION_CONTEXT('TenantId') per request, MI auth to Azure SQL, contained user with least privilege. Verify with two tenants that neither can see the other's data through any query path — even bulk operations, even from a mistake in the app code.