Authentication failure during token refresh for Azure SQL Database Managed Identities
0 reputation · 07 Jul 2024, 16:59 UTC
Implementing least-privilege access in Azure SQL Database often involves utilizing Microsoft Entra ID Managed Identities to remove hardcoded credentials. In this architecture, the application relies on OAuth2 tokens that possess a finite lifespan and must be refreshed to maintain a persistent connection to the database engine.
A challenge arises when the identity's credentials expire or the token refresh mechanism fails at the gateway level. Because the authentication occurs before the request reaches the SQL engine, it is unclear how the database handles existing sessions when the underlying identity token expires during a long-running transaction or a persistent connection pool.
- Does the Azure SQL Database gateway terminate active sessions immediately upon token expiration?
- What is the expected behavior for connection pools when the managed identity token cannot be refreshed?