Flexible Server: Entra user with ismfa=true refused even though token amr contains "mfa"

Adam 0 Reputation points
2026-10-08T04:16:15.93+00:00

On Azure Database for PostgreSQL Flexible Server (PostgreSQL 18, Burstable tier), an Entra user principal created with pgaadauth_create_principal('<user UPN>', false, true) is refused at login with:

FATAL: The specified role must be authenticated using Azure Multi-Factor Authentication.

The access token does contain mfa. What I've checked:

  1. Principal created while connected to the postgres database as the Entra admin. pgaadauth_list_principals shows isadmin=0, ismfa=1.
  2. Signed in with Azure CLI using device code in a private browser window, completing MFA. Token from: az account get-access-token --resource https://ossrdbms-aad.database.windows.net
  3. Decoded token claims: ver 1.0, aud https://ossrdbms-aad.database.windows.net, amr ["pwd","mfa"], acr "1", idtyp user, appid = Azure CLI, scp user_impersonation. upn and oid match the principal.
  4. Connected with psql, token as the password, sslmode=require, token used promptly. Refused every time.
  5. Dropped and recreated the principal with ismfa=true. Security labels look well-formed (pgaadauth-int: type=user, oid, tenant_id, mfa; pgaadauth: aadauth,mfa). Still refused.
  6. Recreated with ismfa=false: the same account and the same token connect immediately.

The documentation says "The isMfa flag tests the mfa claim in the Microsoft Entra ID token", which this token has.

Questions:

  • Which claim (and token version) does the isMfa check actually evaluate on Flexible Server?
  • Is this a known issue on PostgreSQL 18?
  • Is there a supported way to get a token from Azure CLI that this check accepts?
Azure Database for PostgreSQL
0 comments No comments

1 answer

Sort by: Most helpful
  1. Salamat Shah 830 Reputation points MVP
    2026-10-08T10:31:31.3033333+00:00

    The token appears to contain the mfa authentication-method reference, so this looks more like an Azure Database for PostgreSQL Flexible Server MFA-validation issue/compatibility issue than a missing MFA token. Flexible Server supports Microsoft Entra authentication, but the observed isMfa=true rejection needs server-side validation.

    Recommendation:

    • Confirm Microsoft Entra authentication and the Entra principal are configured correctly.
    • Test with the latest supported Azure CLI/token flow.
    • Since recreating the principal still fails with a token containing mfa, open a Microsoft Azure support case and provide the PostgreSQL version, token claims (with sensitive data removed), server region, and reproduction steps.
    • Ask Microsoft to verify whether this is a PostgreSQL 18/Flexible Server isMfa validation defect or limitation.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.