Unable to set Microsoft Entra ID Group as Administrator on Azure Database for MySQL Flexible Server – InternalServerError

Stefania Campanella 0 Reputation points
2026-09-25T09:39:51.28+00:00

We are unable to set a Microsoft Entra ID security group as the Microsoft Entra Administrator for an Azure Database for MySQL Flexible Server.

The operation fails with the following error:

InternalServerError: An unexpected error occurred while processing the request.

The issue has been reproduced using:

  • Azure Portal
  • Azure CLI 2.90.0
  • Azure CLI 2.77.0

The server currently has a valid Microsoft Entra Administrator configured as an individual user. The issue occurs when attempting to replace this administrator with a Microsoft Entra ID security group.

The User Assigned Managed Identity configured for the MySQL server has the required Microsoft Graph application permissions with Admin Consent.

Since the same InternalServerError occurs through both the Azure Portal and different Azure CLI versions,we would like to investigate the server-side operation and associated backend telemetry.

Azure Database for MySQL
0 comments No comments

2 answers

Sort by: Most helpful
  1. Maksood Ahmed 15 Reputation points Microsoft External Staff Moderator
    2026-10-01T13:51:26.0433333+00:00

    Hi Stefania,

    Since the individual Entra administrator is working, I would first recheck the user-assigned managed identity configured for the MySQL Flexible Server.

    For group-based Entra administration, Microsoft documents that the managed identity requires User.Read.All, GroupMember.Read.All, and Application.Read.All permissions. Alternatively, the managed identity can have the Directory Readers role. Microsoft also supports selecting an Entra group as the administrator.

    If these permissions are already configured correctly and the same InternalServerError continues from both the portal and CLI, collect the failed operation/correlation details and open an Azure support request for further investigation.

    FYR:

    Set up Microsoft Entra authentication for Azure Database for MySQL Flexible Server

    Was this answer helpful?


  2. Taz 10,126 Reputation points MVP Volunteer Moderator
    2026-09-25T14:07:51.0366667+00:00

    Hi Stefania,

    Azure Database for MySQL Flexible Server does support using a Microsoft Entra security group as the Entra administrator. Microsoft also documents the required managed identity permissions: User.Read.All, GroupMember.Read.All, and Application.Read.All, or the Directory Readers role.

    Since you are getting the same InternalServerError from the portal and multiple Azure CLI versions, and an individual Entra administrator is already working, this looks more like a service-side issue than a CLI or configuration problem.

    I would open an Azure Support case and provide the MySQL server name, region, group object ID, managed identity details, exact timestamp, and the full error/correlation ID. Ask the MySQL engineering team to check the backend operation for setting the Entra group administrator.

    There is no need to remove the current working administrator first. The documented CLI command supports creating/replacing the Entra administrator directly.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.