Microsoft Entra ID (MFA) sign-in for Azure SQL on Mac, iPhone and iPad
Posted by Kyle Hankinson
A lot of Azure SQL databases no longer have a SQL login you can use. Many organizations turn SQL authentication off entirely and require everyone to sign in with their work account, usually with multi-factor authentication on top. Until now, that left Mac, iPhone and iPad users without a native way in.
That changes with the latest update. SQLPro Studio and SQLPro for MSSQL now sign in to SQL Server with Microsoft Entra ID (the service formerly called Azure Active Directory) on macOS, iPhone and iPad. You sign in with Microsoft the same way you do everywhere else at work, MFA prompt included, and the app connects with the token Microsoft issues. The Windows apps already supported Entra ID sign-in; this brings the Apple platforms up to the same level.
What you can connect to
Entra ID sign-in works with the SQL Server services that accept it:
- Azure SQL Database
- Azure SQL Managed Instance
Nothing changes for SQL Server authentication or Windows authentication. Existing connections keep working exactly as before.
Two ways to sign in
Open a SQL Server connection and pick one of the two new authentication types.
Microsoft Entra - Interactive (MFA). This is the one most people want. When you connect, a Microsoft sign-in window opens. Choose your account, complete whatever your organization asks for (password, Authenticator push, security key, passkey) and the connection opens. The window always shows the account picker, so if you are signed in to more than one Microsoft account you pick the right one instead of the browser quietly reusing the last one.
Microsoft Entra - Device Code. For when a browser window is not practical, or you would rather finish the sign-in on another device. The app shows a short code; go to microsoft.com/devicelogin on your phone or any computer, enter the code, and sign in there. The app waits and connects as soon as you are done.
In both cases the login field is your work address, for example jane@contoso.com. There is no password to enter in the app.
You will not be asked every time
After the first sign-in, the app keeps a refresh token in the system keychain and gets new access tokens quietly in the background. Reconnecting, opening a second window on the same server, or relaunching the app does not bring the sign-in window back. You only see Microsoft again when your organization's policy says so (a password change, a revoked session, or a sign-in frequency rule).
A few details worth knowing:
- Your password never passes through the app. You type it into Microsoft's own sign-in page. The app only receives the token Microsoft issues.
- The account is checked. If you sign in as a different account from the one in the connection's login field, the app refuses the token and tells you which account Microsoft signed in, rather than connecting you as the wrong person.
- Several connections, one prompt. Restore a workspace with five tabs on the same server and you get one sign-in, not five.
The tenant setting
Most people can ignore this. By default the sign-in uses the directory that belongs to the domain of your login, so jane@contoso.com signs in to the Contoso tenant.
Set the tenant yourself if you are a guest in another organization's directory, or if your organization's sign-in domain differs from the address in your login. On the Mac it is the Entra ID tenant field in the connection's advanced settings; on iPhone and iPad it is the Tenant field on the connection. Either the tenant's domain (company.onmicrosoft.com) or its tenant ID works.
First sign-in: consent
The first time anyone in an organization signs in, Microsoft asks whether the app may access Azure SQL Database on their behalf. Accept it once and it is not asked again.
Some organizations do not let users approve apps themselves. In that case Microsoft shows a message saying administrator approval is needed, or the sign-in ends with an error such as AADSTS65004 or access_denied. An administrator can approve the app for everyone from the Entra admin center; Microsoft describes the steps in grant tenant-wide admin consent to an application. The application ID to look for is a61530ad-aa3d-43bc-8d9d-e4e264e28263.
On the database side
Signing in with Microsoft only proves who you are. The server still has to know you. If you are setting up Entra ID access on Azure SQL for the first time:
- The logical server (or managed instance) needs a Microsoft Entra admin. You set it in the Azure portal under the server's Microsoft Entra ID settings.
- Each person or group needs a user in the database, created by that admin:
CREATE USER [jane@contoso.com] FROM EXTERNAL PROVIDER;
ALTER ROLE db_datareader ADD MEMBER [jane@contoso.com];
Groups work the same way, using the group's display name, which saves adding people one at a time. Microsoft's overview of Entra authentication for Azure SQL and the configuration guide cover the rest.
If it does not connect
- "Client with IP address ... is not allowed to access the server" (Msg 40615). The sign-in worked, but the Azure SQL firewall is blocking your network. Add your address in the Azure portal under the server's networking settings, or ask whoever manages it. See Azure SQL firewall rules.
- Login failed for a user that should exist. Check the
CREATE USER ... FROM EXTERNAL PROVIDERstep above, and that you are connecting to the database the user was created in. - "Tenant not found" (AADSTS90002). Your login's domain is not the domain your directory uses for sign-in. Enter the tenant explicitly, as described above.
- The sign-in window was closed or timed out. Just connect again. Device codes expire after about 15 minutes, so a new one is issued each time.
- Signed in as the wrong account. The error names the account Microsoft used. Connect again and choose the right one in the account picker, or correct the login.
Where to get it
Entra ID sign-in is in the current releases for macOS, iPhone and iPad, in both apps. It is not in the Android apps yet. If you are new to SQL Server on the Mac, our guide to connecting to SQL Server from a Mac walks through the rest of the connection settings.
If your organization's sign-in setup does something we have not covered here, please open an issue on GitHub with the error you see. We would like to hear about it.
About the author - Kyle Hankinson is the founder and sole developer of SQLPro for MySQL and the Hankinsoft Development suite of database tools. He has been building native macOS and iOS applications since 2010, and now ships SQLPro on Windows and Android as well.
Try SQLPro for MySQL - A native MySQL and MariaDB client for macOS, iOS, and Android. No Java required.
Download Free Trial View Pricing Compare