Azure SQL: Login failed for user '<token-identified principal>' (Microsoft Entra / managed identity)
Entra ID authentication succeeded, but there’s no database user for that identity (or it lacks permission to the database).
Seen on:
Azure
Meaning
Managed identities and Entra users must be created inside each database with CREATE USER ... FROM EXTERNAL PROVIDER and given roles. The server also needs an Entra admin configured.
Common causes
- No contained user for the identity in the database
- Server has no Microsoft Entra admin
- Connecting to master instead of the user database
- Wrong identity (system vs user-assigned)
⚡ Quick fix
- As the Entra admin, create the user in the target database and grant roles
- Set the server’s Entra admin
- Specify the database in the connection string
Detailed fix by platform
SQL Server
- bash
CREATE USER [my-api] FROM EXTERNAL PROVIDER; ALTER ROLE db_datareader ADD MEMBER [my-api]; ALTER ROLE db_datawriter ADD MEMBER [my-api];
How to diagnose
- User — Exists in this database?
- Admin — Entra admin set?
- Database — Connection string Initial Catalog
🔧 Still not fixed?
Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:
Similar errors
- 40615 Azure SQL: Cannot open server 'x' requested by the login. Client with IP address 'y' is not allowed to access the server (Error 40615)
- AADSTS500113 AADSTS500113: No reply address is registered for the application
- AADSTS50020 AADSTS50020: User account from identity provider does not exist in tenant and cannot access the application
Most viewed in Azure
- AADSTS50076 Azure AD (Entra ID): AADSTS50076 / AADSTS50079 — multi-factor authentication required
- AuthorizationPermissionMismatch Azure Storage: AuthorizationPermissionMismatch (403) — This request is not authorized to perform this operation using this permission
- AADSTS700016 Azure AD (Entra ID): AADSTS700016 Application not found in the directory
Other ways to find it
🧠 Still stuck? Analyze your error
Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.
Was this page helpful?
Report a correction or suggest an improvement
Last updated 7 Oct 2026