Login failed for user '<token-identified principal>' 🔷 Azure

Azure SQL: Login failed for user '<token-identified principal>' (Microsoft Entra / managed identity)

Entra ID authentication succeeded, but there’s no database user for that identity (or it lacks permission to the database).

Seen on: Azure

Meaning

Managed identities and Entra users must be created inside each database with CREATE USER ... FROM EXTERNAL PROVIDER and given roles. The server also needs an Entra admin configured.

Common causes

  • No contained user for the identity in the database
  • Server has no Microsoft Entra admin
  • Connecting to master instead of the user database
  • Wrong identity (system vs user-assigned)

⚡ Quick fix

  1. As the Entra admin, create the user in the target database and grant roles
  2. Set the server’s Entra admin
  3. Specify the database in the connection string

Detailed fix by platform

SQL Server

  1. bash
    CREATE USER [my-api] FROM EXTERNAL PROVIDER;
    ALTER ROLE db_datareader ADD MEMBER [my-api];
    ALTER ROLE db_datawriter ADD MEMBER [my-api];

How to diagnose

  1. User — Exists in this database?
  2. Admin — Entra admin set?
  3. Database — Connection string Initial Catalog

🔧 Still not fixed?

Many errors look alike. If the steps above didn’t solve it, one of these is probably what you’re facing:

🧠 Still stuck? Analyze your error

Paste the full message, response headers or stack trace — we'll detect the platform and point to the most likely cause.