Review the Microsoft Entra administrator for Azure SQL

Configure a Microsoft Entra administrator for the Azure SQL logical server to support organizational authentication.

Description

Managing Microsoft Entra authentication for an Azure SQL logical server requires an Entra administrator. This is separate from the SQL authentication administrator; in Ansible, set the Entra administrator details in administrators.

Potential impact

Without an Entra administrator, configuring Entra-based database users and permissions is restricted, which can separate database operations from organizational account management.

Remediation

Choose the user or group responsible for administration and set its display name, object ID, and tenant ID in administrators. Configure required database users and permissions too. Setting an Entra administrator alone does not disable SQL authentication.

Examples

The revised example assigns the sqladmin group as the Entra administrator. Supply the actual group object ID and tenant ID, and provide the SQL administrator password securely.

Before

yaml
- name: SQL Server 생성
  azure.azcollection.azure_rm_sqlserver:
    resource_group: myResourceGroup
    name: server-name
    location: westus
    admin_username: mylogin
    admin_password: "{{ sql_admin_password }}"
  no_log: true

After

yaml
- name: SQL Server 생성
  azure.azcollection.azure_rm_sqlserver:
    resource_group: myResourceGroup
    name: server-name
    location: westus
    admin_username: mylogin
    admin_password: "{{ sql_admin_password }}"
    administrators:
      administrator_type: ActiveDirectory
      principal_type: Group
      login: sqladmin
      sid: "{{ sql_admin_group_object_id }}"
      tenant_id: "{{ tenant_id }}"
  no_log: true

References