We help IT Professionals succeed at work.

ODBC connection to Azure SQL database using AD Integrated Authentication fails from Azure VM.

rdyaz
rdyaz asked
on
638 Views
Last Modified: 2018-12-20
I've copied an on-premise SQL database to Azure SQL for testing, using the Azure online migration process, which is done and the database is in ready to cutover mode..  
From a local Windows 10 machine using ODBC driver 17, I can set up an ODBC connection to the Azure SQL database using Active Directory Integrated security and it works fine.
From the same machine, SSMS 17 connects to the Azure SQL database fine.
However when I try the same ODBC connection from an Azure VM (Server 2016, joined to the local domain via VPN) I cannot get it to authenticate even with the same domain user.  On the VM, I've tried ODBC driver 13.1 and 17.2.  Here is the error message I get:

"Microsoft ODBC Driver for SQL Server Version 13.00.4414

Running connectivity tests...

Attempting connection
[Microsoft][ODBC Driver 13 for SQL Server][SQL Server]Failed to authenticate the user '<user>' in Active Directory (Authentication option is 'ActiveDirectoryIntegrated').
Error code 0xCAA9001F; state 10
Integrated Windows authentication supported only in federation flow.

TESTS FAILED!"

I'm not sure why this would be any different for an Azure VM than a local machine--both are domain joined.
-Azure AD Connect is synchronizing users to Azure.
-I have the firewall open on the Azure SQL database server to allow both local subnet and the Azure vNet the VM is on.
-I have the ADAL for SQL Server and the Microsoft Online Services Sign-in Assistant both installed on the VM.

Thanks for any help.
Comment
Watch Question

Shreedhar EtteTechnical Manager
CERTIFIED EXPERT
Top Expert 2010

Commented:
Hi Rdyaz,

Looking at the error "Integrated Windows authentication supported only in federation flow." We can conclude that Azure Active Directory has to be federated.

Further refer this article to better understand the requirements:
https://stackoverflow.com/questions/39367634/sql-azure-integrated-authentication-with-a-cloud-only-azure-active-directory-fai

Author

Commented:
Thanks for the reply.  If federation was required, how could this be working for an on-premise machine accessing Azure SQL?
Commented:
This problem has been solved!
(Unlock this solution with a 7-day Free Trial)
UNLOCK SOLUTION

Gain unlimited access to on-demand training courses with an Experts Exchange subscription.

Get Access
Why Experts Exchange?

Experts Exchange always has the answer, or at the least points me in the correct direction! It is like having another employee that is extremely experienced.

Jim Murphy
Programmer at Smart IT Solutions

When asked, what has been your best career decision?

Deciding to stick with EE.

Mohamed Asif
Technical Department Head

Being involved with EE helped me to grow personally and professionally.

Carl Webster
CTP, Sr Infrastructure Consultant
Empower Your Career
Did You Know?

We've partnered with two important charities to provide clean water and computer science education to those who need it most. READ MORE

Ask ANY Question

Connect with Certified Experts to gain insight and support on specific technology challenges including:

  • Troubleshooting
  • Research
  • Professional Opinions