login failed for user ' token-identified principal

login failed for user ' token-identified principal

avatar

Hi, we are migrating from onpremise RDM to RDM in Azure SQL. I created the Auzre Admin account and this account works perfectly on the database.

The setup is like this, we have a tenant where the Azure resources exist like the Azure SQL for RDM and we have a seperate tenant where users exist. The account that exists in the Azure resources tenant is a local account in this tenant and also the Azure Admin Account.

I tried to create seperate users in RDM but these users exist in Azure AD as ExternalAD (Guest/Member) accounts. These users receive the error after Authentication in Azure AD : login failed for user ' token-identified principal

I already tried to play with the settings of "Is Guest/Federated". I dont know how to resolve this.

With kind regards,

John

All Comments (3)

avatar

Hello John,

Thank you for reaching out to the Devolutions support team.

According to the permission you want to apply to your users and the access they will have in SQL,
We may have an excellent solution for you.
Custom login is a way to create an RDM user who does not have access to the database information.

This is the article about it:
Implement the custom login mode - Devolutions Documentation

Let me know if this is a good way to manage your guest's permission.

Best regards,

Patrick Ouimet

avatar
Hello John,

Thank you for reaching out to the Devolutions support team.

According to the permission you want to apply to your users and the access they will have in SQL,
We may have an excellent solution for you.
Custom login is a way to create an RDM user who does not have access to the database information.

This is the article about it:
Implement the custom login mode - Devolutions Documentation

Let me know if this is a good way to manage your guest's permission.

Best regards,


Hi,

Thank you for the respons. I rather have an option where i can centrally manage the users like from Entra ID instead of local users per app. Is there no option to get this working? As there is the option of "Guest/Federated" when creating users and choosing Microsoft?

With kind regards,

John

avatar

Hello John,

If the ultimate goal is to import your users and user groups from AAD into our product,
I suggest having a look at the Devolutions Server.

This on-prem web application is SQL-based and has this feature.
Also, this is a must-have in terms of security and user access.

We offer informative sessions and installation sessions for free.
If you wish to try it yourself, there is also a free version for 10 users.

Devolutions Server - Devolutions

Best regards,

Patrick Ouimet