An Azure relational database service.
The most targeted next test is a single, time-correlated OpenAsync attempt from a minimally authorized managed identity while collecting SqlClient EventSource, an application-container packet capture, and Azure SQL connection metrics.
1. Check the remaining private-endpoint prerequisite
Before tracing, inspect the effective server-level firewall rules for the source address that the SQL gateway sees. Microsoft’s private-endpoint troubleshooting guidance states that Azure SQL can still enforce server-level firewall rules for private-endpoint traffic.^1^
Do not assume that the private-endpoint subnet is the correct source range:
- Determine the effective source address from the packet capture and Azure configuration.
- If no matching rule exists, add the narrowest temporary rule for that address/range through SQL logical server → Networking → Firewall rules, or have the administrator use
sp_set_firewall_rule. - Repeat one bounded
OpenAsyncattempt. - Remove the temporary rule afterward if it is not part of the intended design.
This does not require enabling public access.
2. Establish a controlled authorization baseline
Have the Microsoft Entra administrator connect to the explicit target database and create a contained user for the disposable worker’s managed identity. Grant only CONNECT, not reader, writer, DDL, or administrator roles:
USE [TargetDatabase];
GO
CREATE USER [DiagnosticWorkerIdentity] FROM EXTERNAL PROVIDER;
GRANT CONNECT TO [DiagnosticWorkerIdentity];
GO
Use an unambiguous principal-creation method supported by your tenant if display names are duplicated. Azure SQL authorization is controlled through database users, roles, and explicit permissions, with least privilege recommended.^2^
A missing database principal normally belongs in the authentication/authorization branch, but 10054 alone does not prove either authorization failure or transport failure. This controlled mapping removes that ambiguity without granting schema privileges.
3. Capture both client layers during exactly one attempt
SqlClient EventSource
If the App Service image contains a compatible .NET SDK and permits diagnostic-tool installation and process attachment, attach at information level:
dotnet tool install --global dotnet-trace
export PATH="$PATH:$HOME/.dotnet/tools"
dotnet-trace ps
dotnet-trace collect --process-id <PID> \
--providers Microsoft.Data.SqlClient.EventSource:1FFF:4
If the image has only the runtime or blocks tool installation/attachment, package dotnet-trace with the diagnostic deployment or launch the diagnostic assembly under the documented collector form instead:
dotnet-trace collect \
--providers Microsoft.Data.SqlClient.EventSource:1FFF:5 \
-- dotnet DiagnosticWorker.dll
Verbose level 5 produces more sensitive and voluminous output; use it only for a short window and protect the trace. These are the documented SqlClient tracing forms.^3^
Application-container packet capture
For a built-in Linux App Service where SSH/root package installation is available:
apt-get update && apt-get install -y tcpdump
tcpdump -D
tcpdump -i eth0 -nn -s 0 -w /home/sql-open.pcap \
host <private-endpoint-ip> and port 1433
Reproduce one connection, stop tcpdump, and download the capture from /home. This is the documented Linux App Service procedure.^4^
The capture can show:
- which peer transmitted the TCP RST;
- whether the reset occurs before or after visible TDS pre-login/TLS exchange;
- retransmissions or timeout behavior.
It cannot generally identify which internal Azure gateway component generated the reset or why; that requires Microsoft Support correlation. The SQL Server 10054 TLS article also recommends examining Client Hello and Server Hello in a client/server trace, although it applies specifically to SQL Server rather than establishing an Azure SQL root cause here.^5^
4. Correlate with Azure SQL metrics
Record UTC start/end timestamps and inspect SQL database → Monitoring → Metrics using one-minute granularity:
- Successful Connections
- Failed Connections: System Errors
- Failed Connections: User Errors
Split failures by Error and ValidatedDriverNameAndVersion; successful connections can also be split by SslProtocol.^6^
Reading metrics requires Microsoft.Insights/metrics/read, commonly supplied through Monitoring Reader, scoped as narrowly as practical. Publication delay, one-minute aggregation, and concurrent attempts prevent guaranteed one-to-one attribution; absence of a metric is supporting evidence, not proof that the gateway received nothing.
Standard platform metrics have no charge. Sending audit or diagnostic logs to Log Analytics can incur ingestion and retention charges.^7^
Do not rely on SQL auditing to exclude Entra authentication failure: failed Microsoft Entra logins do not appear in Azure SQL audit logs because credential verification occurs before the requested database is accessed.^8^
Independent client
Deploy sqlcmd (Go) inside the same diagnostic app/container image and invoke it from the application startup process—not Kudu—with the same system-assigned identity:
sqlcmd \
-S <server>.database.windows.net \
-d <database> \
--authentication-method ActiveDirectoryManagedIdentity \
-Q "SELECT 1"
That managed-identity mode is documented for system-assigned identities.^9^
No published issue in the supplied material ties this exact combination to 10054. Version 6.1.6 is supported, but 6.1.7 is the latest 6.1 LTS patch; test it only as a controlled comparison, not as a presumed fix.^10^
If the capture shows a gateway-originated RST and metrics/traces do not expose the reason, open a private support request with UTC timestamps, database/server resource IDs, .pcap, .nettrace, driver version, and any tracing ID—never the token or complete connection string.
References
- Troubleshoot connectivity issues and other errors
- Authorize database access to Azure SQL Database
- Enable event tracing in SqlClient
- Troubleshoot virtual network integration with Azure App Service
- An existing connection was forcibly closed by the remote host (OS error 10054)
- Monitor Azure SQL Database with metrics and alerts
- Azure Monitor cost and usage
- Auditing for Azure SQL Database
- Authenticate with Microsoft Entra ID in sqlcmd
- SqlClient Driver Support Lifecycle - ADO.NET Provider for SQL Server