%3CLINGO-SUB%20id%3D%22lingo-sub-1548470%22%20slang%3D%22en-US%22%3EEnhanced%20support%20for%20Azure%20AD%20Guest%20Users%20for%20Azure%20SQL%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-1548470%22%20slang%3D%22en-US%22%3E%3CP%3EWe%20are%20announcing%20public%20preview%20of%20a%20new%20capability%20that%20enables%20creation%20of%20Azure%20AD%20guest%20users%20directly%20as%20database%20users%20and%20setting%20Azure%20AD%20guest%20users%20as%20Active%20Directory%20admin%20for%20SQL%20for%20Azure%20SQL%20Database%2C%20Managed%20Instance%20and%20Synapse%20Analytics%2C%20without%20the%20requirement%20of%20adding%20them%20to%20an%20Azure%20AD%20group%20first.%3C%2FP%3E%0A%3CP%3EThis%20is%20applicable%20to%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EAzure%20SQL%20Database%3C%2FLI%3E%0A%3CLI%3EAzure%20SQL%20Managed%20Instance%3C%2FLI%3E%0A%3CLI%3ESynapse%20Analytics%20(formerly%20SQL%20DW)%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CH1%20id%3D%22toc-hId-498939850%22%20id%3D%22toc-hId-498939850%22%3E%26nbsp%3B%3C%2FH1%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%224%22%3E%3CSTRONG%3EWhat%20are%20Guest%20Users%20and%20how%20are%20they%20supported%20in%20Azure%20SQL%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3EGuest%20users%20in%20Azure%20AD%20are%20users%20that%20have%20been%20imported%20into%20the%20current%20Azure%20Active%20Directory%20from%20other%20Azure%20Active%20Directories%2C%20or%20outside%20of%20it.%20Guest%20users%20include%20users%20invited%20from%20other%20Azure%20ADs%2C%20Microsoft%20accounts%20such%20as%20outlook.com%2C%20hotmail.com%2C%20live.com%2C%20or%20other%20accounts%20like%20gmail.com.%3C%2FP%3E%0A%3CP%3EPreviously%2C%26nbsp%3B%20guest%20users%20could%20connect%20to%20SQL%20Database%20(SQL%20DB)%2C%20Managed%20Instance%20(MI)%20and%20Synapse%20Analytics%20(formerly%20SQL%20DW)%20only%20as%20part%20of%20members%20of%20a%20group%20created%20in%20current%20Azure%20AD%20that%20was%20then%20mapped%20manually%20using%20the%20Transact-SQL%26nbsp%3BCREATE%20USER%26nbsp%3Band%20CREATE%20LOGIN%20statements%20in%20a%20given%20Similarly%2C%20to%20make%20a%20guest%20user%20the%20Active%20Directory%20Admin%20for%20the%20server%2C%20the%20guest%20user%20had%20to%20be%20added%20to%20an%20Azure%20AD%20group%20and%20the%20group%20would%20then%20have%20to%20be%20set%20as%20the%20Active%20Directory%20Admin.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%224%22%3E%3CSTRONG%3EWhat%20functionality%20does%20the%20Public%20Preview%20offer%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3EThis%20public%20preview%20extends%20previous%20functionality%20by%20allowing%20Azure%20AD%20guest%20users%20to%20be%20directly%20added%20as%20database%20users%2C%20without%20the%20requirement%20of%20adding%20them%20to%20an%20Azure%20AD%20group%20first%20and%20then%20creating%20a%20database%20user%20for%20that%20Azure%20AD%20group.%26nbsp%3B%20Additionally%2C%20this%20enables%20Azure%20AD%20guest%20user%20to%20be%20set%20directly%20as%20Active%20Directory%20admin%20for%20SQL%20DB%2C%20MI%20and%20DW%20without%20being%20part%20of%20an%20Azure%20AD%20group.%3C%2FP%3E%0A%3CH2%20id%3D%22toc-hId-1189501324%22%20id%3D%22toc-hId-1189501324%22%3E%3CFONT%20size%3D%224%22%3EExample%3C%2FFONT%3E%3C%2FH2%3E%0A%3CP%3EConsider%20-ERR%3AREF-NOT-FOUND-user1%40outlook.com%20is%20a%20guest%20user%20and%20belongs%20to%20the%20Azure%20AD%20group%20%E2%80%98external_group%E2%80%99%20in%20the%20current%20Azure%20AD%20tenant.%20%26nbsp%3B%3CBR%20%2F%3EPreviously%2C%20we%20had%20to%20create%20this%20group%20as%20a%20database%20user%20using%20the%20T-SQL%20command%20below%2C%20allowing%20the%20guest%20user%20to%20connect%20to%20the%20database%20as%20-ERR%3AREF-NOT-FOUND-user1%40outlook.com%3CBR%20%2F%3E%3CSPAN%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3CEM%3Ecreate%20user%20%5Bexternal_group%5D%20from%20external%20provider%3C%2FEM%3E%3C%2FSPAN%3E%3C%2FP%3E%0A%3CP%3EWith%20this%20preview%2C%20the%20guest%20user%20can%20now%20be%20directly%20created%20as%20a%20database%20user%20using%20the%20T-SQL%20command%20below%3A%3CBR%20%2F%3E%3CSPAN%3E%3CEM%3E%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%26nbsp%3B%20%3C%2FEM%3E%3C%2FSPAN%3E%3CEM%3Ecreate%20user%20%5B%3CA%20href%3D%22mailto%3Auser1%40outlook.com%22%20target%3D%22_blank%22%20rel%3D%22noopener%20nofollow%20noopener%20noreferrer%20noopener%20noreferrer%22%3Euser1%40outlook.com%3C%2FA%3E%5D%20from%20external%20provider%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3EIn%20the%20same%20way%2C%20the%20guest%20user%20can%20now%20be%20directly%20added%20as%20the%20Active%20Directory%20Admin%20for%20the%20database%20server%20using%20the%20PowerShell%20command%20below%20(or%20equivalent%20CLI%20command)%3A%3C%2FP%3E%0A%3CP%20class%3D%22lia-indent-padding-left-30px%22%3E%3CEM%3ESet-AzSqlServerActiveDirectoryAdministrator%26nbsp%3B-ResourceGroupName%26nbsp%3B%3CRESOURCEGROUPNAME%3E%26nbsp%3B-ServerName%26nbsp%3B%3CSERVERNAME%3E%26nbsp%3B-DisplayName%20%E2%80%98user1%40outlook.com%E2%80%99%26nbsp%3B%3C%2FSERVERNAME%3E%3C%2FRESOURCEGROUPNAME%3E%3C%2FEM%3E%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3ENote%20-%20This%20works%20for%20all%20types%20of%20guest%20users%2C%20namely%3A%3C%2FP%3E%0A%3CUL%3E%0A%3CLI%3EGuest%20users%20invited%20from%20other%20Azure%20AD%20tenants%3C%2FLI%3E%0A%3CLI%3EMicrosoft%20accounts%20such%20as%20outlook.com%2C%20hotmail.com%2C%20live.com%3C%2FLI%3E%0A%3CLI%3EOther%20accounts%20like%20gmail.com%3C%2FLI%3E%0A%3C%2FUL%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CFONT%20size%3D%224%22%3E%3CSTRONG%3ENotes%3C%2FSTRONG%3E%3C%2FFONT%3E%3C%2FP%3E%0A%3CP%3EThis%20new%20capability%20does%20not%20impact%20existing%20functionality%2C%20rather%20it%20allows%20greater%20flexibility%20in%20managing%20guest%20users%20in%20SQL%20DB%2FMI%2FDW.%20Guest%20users%20can%20continue%20to%20be%20part%20of%20an%20Azure%20AD%20group%20in%20order%20to%20be%20added%20as%20a%20database%20user%20and%2For%20Active%20Directory%20admin%20for%20the%20server.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EPlease%20refer%20our%20-ERR%3AREF-NOT-FOUND-documentation%20for%20more%20details%20and%20for%20the%20PowerShell%2FT-SQL%20commands%20to%20be%20used%20for%20adding%20a%20guest%20user%20as%20a%20database%20user%20and%20as%20Active%20Directory%20Admin.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3EFor%20feedback%2Fquestions%20on%20this%20preview%2C%20please%20reach%20out%20to%20the%20SQL%20AAD%20team%20at%20-ERR%3AREF-NOT-FOUND-SQLAADFeedback%40Microsoft.com%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-1548470%22%20slang%3D%22en-US%22%3E%3CP%3EAnnouncing%20public%20preview%20of%20enhanced%20support%20for%20Azure%20AD%20guest%20users%20for%20Azure%20SQL.%3C%2FP%3E%3C%2FLINGO-TEASER%3E%3CLINGO-LABS%20id%3D%22lingo-labs-1548470%22%20slang%3D%22en-US%22%3E%3CLINGO-LABEL%3ESecurity%3C%2FLINGO-LABEL%3E%3C%2FLINGO-LABS%3E
Microsoft

We are announcing public preview of a new capability that enables creation of Azure AD guest users directly as database users and setting Azure AD guest users as Active Directory admin for SQL for Azure SQL Database, Managed Instance and Synapse Analytics, without the requirement of adding them to an Azure AD group first.

This is applicable to:

  • Azure SQL Database
  • Azure SQL Managed Instance
  • Synapse Analytics (formerly SQL DW)

 

 

What are Guest Users and how are they supported in Azure SQL

Guest users in Azure AD are users that have been imported into the current Azure Active Directory from other Azure Active Directories, or outside of it. Guest users include users invited from other Azure ADs, Microsoft accounts such as outlook.com, hotmail.com, live.com, or other accounts like gmail.com.

Previously,  guest users could connect to SQL Database (SQL DB), Managed Instance (MI) and Synapse Analytics (formerly SQL DW) only as part of members of a group created in current Azure AD that was then mapped manually using the Transact-SQL CREATE USER and CREATE LOGIN statements in a given Similarly, to make a guest user the Active Directory Admin for the server, the guest user had to be added to an Azure AD group and the group would then have to be set as the Active Directory Admin.

 

 

What functionality does the Public Preview offer

This public preview extends previous functionality by allowing Azure AD guest users to be directly added as database users, without the requirement of adding them to an Azure AD group first and then creating a database user for that Azure AD group.  Additionally, this enables Azure AD guest user to be set directly as Active Directory admin for SQL DB, MI and DW without being part of an Azure AD group.

Example

Consider user1@outlook.com is a guest user and belongs to the Azure AD group ‘external_group’ in the current Azure AD tenant.  
Previously, we had to create this group as a database user using the T-SQL command below, allowing the guest user to connect to the database as user1@outlook.com
        create user [external_group] from external provider

With this preview, the guest user can now be directly created as a database user using the T-SQL command below:
        create user [user1@outlook.com] from external provider

In the same way, the guest user can now be directly added as the Active Directory Admin for the database server using the PowerShell command below (or equivalent CLI command):

Set-AzSqlServerActiveDirectoryAdministrator -ResourceGroupName <ResourceGroupName> -ServerName <ServerName> -DisplayName ‘user1@outlook.com’ 

 

Note - This works for all types of guest users, namely:

  • Guest users invited from other Azure AD tenants
  • Microsoft accounts such as outlook.com, hotmail.com, live.com
  • Other accounts like gmail.com

 

Notes

This new capability does not impact existing functionality, rather it allows greater flexibility in managing guest users in SQL DB/MI/DW. Guest users can continue to be part of an Azure AD group in order to be added as a database user and/or Active Directory admin for the server.

 

Please refer our documentation for more details and for the PowerShell/T-SQL commands to be used for adding a guest user as a database user and as Active Directory Admin.

 

For feedback/questions on this preview, please reach out to the SQL AAD team at SQLAADFeedback@Microsoft.com