Un servizio di database relazionale di Azure.
Hi @Manoj Kumar Boyini
Thanks for the response, i work together with @Roberto Patuelli , who opened this thread.
We have already validated all standard configuration items and would like to summarize the current state to avoid repeating generic checks.
Current verified state:
- Azure SQL Entra authentication is correctly configured
- Azure AD administrator is set on the logical server
- Managed Identity configuration
- A user-assigned managed identity is used
- Database principal
- The identity exists in the target database as an external user created via Azure AD provider
- The mapping between the identity and the database principal is consistent
- Permissions
- CONNECT permission is granted to the user principal
- Token validation
- Access token is successfully acquired using DefaultAzureCredential
- Token contains valid tenant, application, and object identifiers
- Audience is correct for Azure SQL
- Behavior
- Authentication consistently fails with:
"Login failed for user '<token-identified principal>' (Error 18456, State 1)"
- The issue occurs both when using:
- direct access token injection
- built-in managed identity authentication flow
- Timeline
- The configuration has been stable and working for a period of time
- The issue appears to have started suddenly without any known application or configuration changes
We also reviewed Azure SQL audit logs, which confirm the authentication failure at the service level.
The audit entry shows:
- Error code: 18456
- Error state: 5
- The request reaches Azure SQL successfully (client IP and application context are present)
- The managed identity is correctly identified from the incoming token (client ID / SID is present in the audit event)
At this point, all client-side configuration and identity mapping checks have been validated.
Given that:
- the identity exists in the database
- the mapping is consistent
- the token is valid and correctly issued
- Azure AD administrator is configured
- required permissions are granted
- the issue is fully reproducible and confirmed in audit logs
we would appreciate a backend verification of Azure SQL authentication processing for this identity.
Specifically:
- whether the identity is correctly resolved during authentication
- whether the failure occurs during token validation or principal resolution on the Azure SQL service side
- whether there are any known service-side issues affecting Azure AD authentication for managed identities in this period
If this requires deeper investigation, please advise on how to proceed with a private support channel involving backend telemetry access, as the issue cannot be resolved through standard configuration validation alone.