AzureAD Connection Credentials

I see DRA 10 has the ability to connect to AzureAD and create users/groups etc. We use conditional access on AzureAD. How does DRA connect to the tenant using its 'service' account? Is it using a username.password, app registration or certificate?