---
title: Secure Your Azure SQL Estate with Azure AD-only authentication
description: Azure AD-only authentication for Azure SQL, Azure SQL Database, Azure SQL Managed Instance. Azure Active Directory, AAD.
image: https://blog.coeo.com/hubfs/Coeo%20Socials-Mar-03-2022-03-12-30-96-PM.png
---

[![](https://www.coeo.com/wp-content/themes/coeo/images/logo.svg)](https://blog.coeo.com/)

+44 (0)20 3051 3595 | [info@coeo.com](mailto:info@coeo.com) | [Client portal login](https://my.coeo.com)

# Secure Your Azure SQL Estate with Azure AD-only authentication

# The Coeo Blog

![Andy Jones](https://blog.coeo.com/hubfs/Profile%20photos/AndyCircle.jpg)

*You wouldn’t allow simple single-factor authentication for your social media or personal email accounts, so is it appropriate for your corporate highly-sensitive data?*

![20220228_1_AJ_SQLAAD](https://blog.coeo.com/hs-fs/hubfs/Blog%20Images%20Andy%20J/20220228_1_AJ_SQLAAD.jpg?width=7526&name=20220228_1_AJ_SQLAAD.jpg)

Many companies have experienced security incidents with data loss and ransomware attacks. It is no longer good enough to secure the network layer and hope for the best. The solution is to follow the Zero-Trust security principles of:

- Verify explicitly
- Least privilege access
- Assume breach

In this post, I want to discuss one feature of Azure SQL Database and Azure SQL Managed Instance that became Generally Available in November 2021, namely **Azure AD-only authentication**.

Users have long had the option to authenticate to SQL Server using a simple username and password or integrated Windows authentication. The Platform-as-a-Service Azure SQL offerings also offer Azure Active Directory authentication in a cloud-first world.

***Assume breach*** means you acknowledge a hacker will reach and attempt to authenticate to your database. With SQL authentication, you are at the mercy of a password to prevent access. Do all your users choose unique, strong passwords they regularly cycle and not log them in plain text format? If not, the question is, what can you do about it? Enter Azure AD-only authentication.

Below is a snippet of the bicep file to include in your deployment pipeline with azureADOnlyAuthentication set to true. The excerpt shown is a section of a script to deploy an Azure SQL Database.

 ![20220228_2_AJ_SQLAAD](https://blog.coeo.com/hs-fs/hubfs/Blog%20Images%20Andy%20J/20220228_2_AJ_SQLAAD.jpg?width=1297&name=20220228_2_AJ_SQLAAD.jpg)

The result is the box “***Support only Azure Active Directory authentication for this server***” is checked in the Azure portal below, and SQL logins cannot authenticate to this server. You then build your authentication and authorisation in one place, Azure Active Directory, to take advantage of its rich security capabilities and adhere to the ***Verify Explicitly*** zero-trust principle. In Azure Active Directory, you can specify multi-factor authentication, trusted locations, all devices must be compliant and much more to significantly enhance your security posture.

 ![20220228_3_AJ_SQLAAD](https://blog.coeo.com/hs-fs/hubfs/Blog%20Images%20Andy%20J/20220228_3_AJ_SQLAAD.jpg?width=972&name=20220228_3_AJ_SQLAAD.jpg)

 

Of course, before configuring Azure AD-only authentication, you must perform due diligence and a login audit to verify if SQL Logins are still a requirement for your Azure SQL database. For example, you might support a third-party app that requires SQL logins. The critical point here is to consider if SQL logins are an absolute necessity or just how you have always done things. You wouldn’t allow simple single-factor authentication for your social media or personal email accounts, so is it appropriate for your corporate highly-sensitive data?

### Subscribe to Email Updates

## Related posts

---

### [Migrate to SQL Managed Instance using the Log Replay Service](https://blog.coeo.com/migrate-to-sql-managed-instance-using-the-log-replay-service)

### [The GREATEST and LEAST functions arrive in Azure SQL Database](https://blog.coeo.com/the-greatest-and-least-functions-arrive-in-azure-sql-database)

### [Introducing Private Endpoints for Azure SQL Database](https://blog.coeo.com/introducing-private-endpoints-for-azure-sql-database)

### [Power BI Security in Ten Steps](https://blog.coeo.com/ten-steps-to-secure-power-bi)

![](https://www.coeo.com/wp-content/uploads/2016/12/logo-invert.png)

+44 (0)20 3051 3595 | info@coeo.com

## Contact Us

By clicking submit below, you consent to allow Coeo to store and process the personal information submitted above to provide you the content requested.

You may unsubscribe from these communications at any time. For more information on how to unsubscribe and our commitment to your privacy, please review our **[Privacy Policy](https://www.coeo.com/privacy/)**.

## Upcoming Events

[See all events](https://www.coeo.com/events/)

#### NOW Building, Thames Valley Park Drive, Reading, RG6 1RB

[![](https://www.coeo.com/wp-content/themes/coeo/images/social-glass.png)](https://www.glassdoor.co.uk/Overview/Working-at-Coeo-EI_IE959052.11,15.htm)[![](https://www.coeo.com/wp-content/themes/coeo/images/social-in.png)](https://www.linkedin.com/company/coeo-ltd)[![](https://www.coeo.com/wp-content/themes/coeo/images/social-twitter.png)](https://twitter.com/CoeoLtd)[![](https://www.coeo.com/wp-content/themes/coeo/images/social-fb.png)](https://www.facebook.com/coeoltd/)

![](https://www.coeo.com/wp-content/themes/coeo/images//menu-icon.png)

![](https://www.coeo.com/wp-content/themes/coeo/images//menu-close.png)

![](https://www.coeo.com/wp-content/uploads/2016/12/logo-invert.png)

+44 (0)20 3051 3595 | [info@coeo.com](mailto:info@coeo.com)

- [Solutions](https://www.coeo.com/solutions/)
- [Next Steps](https://www.coeo.com/next-steps/)
- [Dedicated Support](https://www.coeo.com/dedicated-support/)
- [Case studies](https://www.coeo.com/case-studies/)
- [Technologies](https://www.coeo.com/solutions/technologies/)

- [Industries](https://www.coeo.com/industries/)
- [Finance](https://www.coeo.com/industries/finance/)
- [Retail](https://www.coeo.com/industries/retail/)
- [Technology](https://www.coeo.com/industries/technology/)

- [The Team](https://www.coeo.com/people/)
- [Join Us](https://www.coeo.com/careers/)
- [Graduate Programme](https://www.coeo.com/graduate-programme/)

- [About Coeo](https://www.coeo.com/about-coeo/)
- [The Coeo Blog](https://www.coeo.com/blog/)
- [Contact us](https://www.coeo.com/contact-us/)
- [Privacy Notice](https://www.coeo.com/privacy/)
- [Cookie Policy](https://www.coeo.com/privacy#Cookie_Policy)

- [Events](https://www.coeo.com/events)

Sign up to our newsletter ![go arrow](https://www.coeo.com/wp-content/themes/coeo/images/newsletter-go.png)

 Back to top