An Azure managed MySQL database service for app development and deployment.
Hi Stefania,
Azure Database for MySQL Flexible Server does support using a Microsoft Entra security group as the Entra administrator. Microsoft also documents the required managed identity permissions: User.Read.All, GroupMember.Read.All, and Application.Read.All, or the Directory Readers role.
Since you are getting the same InternalServerError from the portal and multiple Azure CLI versions, and an individual Entra administrator is already working, this looks more like a service-side issue than a CLI or configuration problem.
I would open an Azure Support case and provide the MySQL server name, region, group object ID, managed identity details, exact timestamp, and the full error/correlation ID. Ask the MySQL engineering team to check the backend operation for setting the Entra group administrator.
There is no need to remove the current working administrator first. The documented CLI command supports creating/replacing the Entra administrator directly.