Flexible Server: Entra user with ismfa=true refused even though token amr contains "mfa"

Adam 0 Reputation points
2026-10-08T04:16:15.93+00:00

On Azure Database for PostgreSQL Flexible Server (PostgreSQL 18, Burstable tier), an Entra user principal created with pgaadauth_create_principal('<user UPN>', false, true) is refused at login with:

FATAL: The specified role must be authenticated using Azure Multi-Factor Authentication.

The access token does contain mfa. What I've checked:

  1. Principal created while connected to the postgres database as the Entra admin. pgaadauth_list_principals shows isadmin=0, ismfa=1.
  2. Signed in with Azure CLI using device code in a private browser window, completing MFA. Token from: az account get-access-token --resource https://ossrdbms-aad.database.windows.net
  3. Decoded token claims: ver 1.0, aud https://ossrdbms-aad.database.windows.net, amr ["pwd","mfa"], acr "1", idtyp user, appid = Azure CLI, scp user_impersonation. upn and oid match the principal.
  4. Connected with psql, token as the password, sslmode=require, token used promptly. Refused every time.
  5. Dropped and recreated the principal with ismfa=true. Security labels look well-formed (pgaadauth-int: type=user, oid, tenant_id, mfa; pgaadauth: aadauth,mfa). Still refused.
  6. Recreated with ismfa=false: the same account and the same token connect immediately.

The documentation says "The isMfa flag tests the mfa claim in the Microsoft Entra ID token", which this token has.

Questions:

  • Which claim (and token version) does the isMfa check actually evaluate on Flexible Server?
  • Is this a known issue on PostgreSQL 18?
  • Is there a supported way to get a token from Azure CLI that this check accepts?
Azure Database for PostgreSQL
0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.