An Azure relational database service.
Hi @Joshee, Monika
The error indicates that SQL Managed Instance cannot resolve the specified Windows account in the trusted identity provider. Since you've already configured the Incoming Trust Flow and Kerberos tickets are being issued, the remaining issue is typically related to identity synchronization or login creation requirements.
A few things to verify:
- Confirm that the user object has successfully synchronized from on-premises Active Directory to Microsoft Entra ID and appears as a valid synchronized user in Entra ID.
- Ensure the SQL Managed Instance has a Microsoft Entra administrator configured. Windows logins rely on Entra ID as the identity source, even when using Kerberos-based Windows Authentication.
Verify that the domain name used in the login matches the on-premises Active Directory domain associated with the trust configuration. The format should be:
- Check whether the user can be resolved through Entra ID by querying the synchronized identity and validating that the UserPrincipalName, SID, and domain mappings are consistent between AD DS and Entra ID.
- Review the prerequisites for Windows Authentication with Azure SQL Managed Instance, including:
- Entra Connect synchronization completed successfully
- Forest/domain trust configuration is healthy
- Kerberos realm and SPN configuration are correct
- The user exists in the trusted domain configured for Windows Authentication
- Kerberos realm and SPN configuration are correct
- Forest/domain trust configuration is healthy
- Entra Connect synchronization completed successfully
If all prerequisites appear correct and the login still cannot be created, collect the exact domain configuration details and synchronization status and open a Microsoft support case, as backend validation of the trust metadata may be required.
Microsoft documentation:
- Windows Authentication for Azure SQL Managed Instance
- Microsoft Entra authentication with SQL Managed Instance
One additional question: are you able to create a login for an Entra-synced AD group (CREATE LOGIN [DOMAIN\GroupName] FROM WINDOWS) or does the same error occur for all synchronized users and groups? That can help determine whether the issue is user-specific or related to the trust/synchronization configuration.