Environment
- Windows Server 2025 Standard
- SQL Server 2025 Express 17.0.1135.8
- Azure Arc enabled server
- Azure SQL Extension version 1.1.3518.465
- Region: Germany West Central
Background
The server was originally onboarded in Poland Central, where Azure Arc SQL Extension installation failed. During troubleshooting we found DNS resolution issues for the SQL Arc endpoints used by the extension.
After removing the Arc resource and re-onboarding the server into Germany West Central, the Azure Arc SQL Extension installed successfully and the SQL Server instance became healthy.
Current Status
- SQL Server instance is visible in Azure Arc.
- Azure SQL Extension status = Succeeded.
- DPS upload status = OK.
- Metrics upload status = OK.
- SQL Server is listening on TCP port 1433.
- Remote connectivity to SQL Server works correctly.
- Azure Arc agent is healthy and connected.
Goal
I would like Microsoft Entra ID users and groups (students and teachers) to authenticate directly to the on-premises SQL Server instance using Microsoft Entra authentication.
Issue
When executing the following command:
CREATE LOGIN [******@domain.com]
FROM EXTERNAL PROVIDER;
SQL Server returns:
Msg 37525
Command 'CREATE LOGIN FROM EXTERNAL PROVIDER' is not supported as Azure Active Directory is not configured for this instance.
Additional Information
- SQL Server authentication mode is Mixed Mode.
- Azure Arc SQL Extension is installed and healthy.
- The Azure Arc SQL resource does not show any option to configure Microsoft Entra Administrator or Microsoft Entra Authentication.
- The SQL Server instance is visible and managed through Azure Arc.
Potentially Related Observation
In Azure Portal, under SQL Server Configuration for the Arc-enabled SQL Server instance, the following message is displayed:
"SQL Server management experience on Azure Arc-enabled servers is currently not supported in this region."
Current region:
Germany West Central
It is unclear whether this regional limitation is related to the inability to configure Microsoft Entra authentication or to the absence of Microsoft Entra Administrator configuration options.
The client computers are Microsoft Entra joined (AzureAdJoined = YES, DomainJoined = NO).
The intended scenario is for students and teachers to connect to the on-premises SQL Server using Microsoft Entra authentication from Microsoft Entra joined devices.
Questions
- Is Microsoft Entra authentication supported for SQL Server 2025 Express enabled by Azure Arc?
- How can Microsoft Entra authentication be enabled for this SQL Server instance?
- Are there any additional prerequisites required before CREATE LOGIN FROM EXTERNAL PROVIDER can be used?
- Could the message "SQL Server management experience on Azure Arc-enabled servers is currently not supported in this region" be related to the inability to configure Microsoft Entra authentication?
- Which Azure regions currently support Microsoft Entra authentication and Microsoft Entra Administrator configuration for Arc-enabled SQL Server instances?
Thank you for your guidance.