SQL Server连接池配置Azure Active Directory认证的设置选项咨询
Azure SQL Server 改用Azure AD认证的配置说明
结论先行:不需要设置domain字段,这个字段是为传统Windows域认证设计的,和Azure AD认证完全无关,直接删掉注释的那行即可。要切换到AAD认证,需要在配置的options里指定认证类型,同时调整账号密码相关参数,以下是几种常见场景的配置示例:
1. AAD用户密码认证(普通AAD账号登录)
如果用的是格式如xxx@your-aad-domain.com的普通AAD用户账号,配置修改如下:
this.config = { server: dbConnectionInfo.server, // 格式需为 xxx.database.windows.net port: dbConnectionInfo.port, database: dbConnectionInfo.database, user: dbConnectionInfo.aadUserEmail, // 填完整的AAD用户邮箱/UPN password: dbConnectionInfo.aadUserPassword, // 填AAD用户的密码 options: { trustServerCertificate: true, encrypt: true, useUTC: false, authentication: 'azure-active-directory-password' // 核心配置:指定AAD密码认证类型 }, }; this.connectionPool = new sql.ConnectionPool(this.config); this.connectionPoolPromise = this.connectionPool.connect();
2. AAD集成认证(本地AD同步到AAD的域用户)
如果你的机器已登录同步到AAD的域账号,可使用集成认证,无需填写密码:
this.config = { server: dbConnectionInfo.server, port: dbConnectionInfo.port, database: dbConnectionInfo.database, user: dbConnectionInfo.aadUserUPN, // 填AAD用户的UPN(如 user@your-domain.com) options: { trustServerCertificate: true, encrypt: true, useUTC: false, authentication: 'azure-active-directory-integrated' // 指定AAD集成认证类型 }, }; this.connectionPool = new sql.ConnectionPool(this.config); this.connectionPoolPromise = this.connectionPool.connect();
3. AAD服务主体认证(应用程序身份)
如果用Azure AD里的应用注册(服务主体)来连接数据库,配置如下:
this.config = { server: dbConnectionInfo.server, port: dbConnectionInfo.port, database: dbConnectionInfo.database, user: dbConnectionInfo.servicePrincipalClientId, // 填服务主体的客户端ID password: dbConnectionInfo.servicePrincipalSecret, // 填服务主体的密钥 options: { trustServerCertificate: true, encrypt: true, useUTC: false, authentication: 'azure-active-directory-service-principal' // 指定服务主体认证类型 }, }; this.connectionPool = new sql.ConnectionPool(this.config); this.connectionPoolPromise = this.connectionPool.connect();
注意事项
- 确保你的Azure SQL服务器已启用Azure AD认证,且对应的AAD用户/服务主体已被授予数据库访问权限
- 需使用最新版本的
mssqlnpm包,旧版本可能不支持这些AAD认证配置项
内容的提问来源于stack exchange,提问作者Alex
相关产品推荐
相关产品推荐

