An Azure managed PostgreSQL database service for app development and deployment.
The token appears to contain the mfa authentication-method reference, so this looks more like an Azure Database for PostgreSQL Flexible Server MFA-validation issue/compatibility issue than a missing MFA token. Flexible Server supports Microsoft Entra authentication, but the observed isMfa=true rejection needs server-side validation.
Recommendation:
- Confirm Microsoft Entra authentication and the Entra principal are configured correctly.
- Test with the latest supported Azure CLI/token flow.
- Since recreating the principal still fails with a token containing mfa, open a Microsoft Azure support case and provide the PostgreSQL version, token claims (with sensitive data removed), server region, and reproduction steps.
- Ask Microsoft to verify whether this is a PostgreSQL 18/Flexible Server isMfa validation defect or limitation.