Description
Managing Microsoft Entra authentication for an Azure SQL logical server requires an Entra administrator. This is separate from the SQL authentication administrator; in Ansible, set the Entra administrator details in administrators.
Potential impact
Without an Entra administrator, configuring Entra-based database users and permissions is restricted, which can separate database operations from organizational account management.
Remediation
Choose the user or group responsible for administration and set its display name, object ID, and tenant ID in administrators. Configure required database users and permissions too. Setting an Entra administrator alone does not disable SQL authentication.
Examples
The revised example assigns the sqladmin group as the Entra administrator. Supply the actual group object ID and tenant ID, and provide the SQL administrator password securely.
Before
- name: SQL Server 생성
azure.azcollection.azure_rm_sqlserver:
resource_group: myResourceGroup
name: server-name
location: westus
admin_username: mylogin
admin_password: "{{ sql_admin_password }}"
no_log: true
After
- name: SQL Server 생성
azure.azcollection.azure_rm_sqlserver:
resource_group: myResourceGroup
name: server-name
location: westus
admin_username: mylogin
admin_password: "{{ sql_admin_password }}"
administrators:
administrator_type: ActiveDirectory
principal_type: Group
login: sqladmin
sid: "{{ sql_admin_group_object_id }}"
tenant_id: "{{ tenant_id }}"
no_log: true