entra-id-auth
Takes an application identity to a passwordless connection to Azure SQL Database, and diagnoses it when that fails: sets the Microsoft Entra administrator, creates the database user for a managed identity or service principal, and grants roles. Use for "set up Microsoft Entra authentication for Azure SQL", "connect with a managed identity", "stop putting the database password in configuration", or "turn on Microsoft Entra-only authentication", and for the container once its MSSQL_AAD_ variables are set. Owns failures after a credential was evaluated: Msg 33134 "Principal could not be resolved", Msg 33131 "duplicate display name", 18456 "Login failed for user", 4060 "Cannot open database". What fails before that is diagnose-connection-errors; the connection code itself is connect-from-dotnet, connect-from-python or connect-from-typescript-and-node.
Pinned to revision eeb1c6867c2d, so it is the text this page describes rather than whatever the author pushed since.
Files
- skills/entra-id-auth/SKILL.md
- skills/entra-id-auth/references/driver-auth-keywords.md
- skills/entra-id-auth/references/entra-only-and-policy.md
- skills/entra-id-auth/references/identity-errors.md
Every link opens the file at its source, pinned to the revision this page describes.