I was in touch with an MVP colleague who those this Azure stuff a lot better than I do, and his answer was that he don't think there is a way to what you want. Your logon trigger may be as good as it can be.
Managed SQL Instance: Entra ID and SQL authentication
RobBul
0
Reputation points
Hi,
is it possible to combine SQL authentication and Entra ID authentication with Azure managed SQL instance, depending on the connection endpoint (private or public). I have this in mind:
- enforce Entra ID authenticated users on the public endpoint (as that one is more secure and MFA enabled). Disable SQL authentication on public endpoint.
- allow SQL authentication only on the private endpoint, to support some legacy apps connecting from within the private Azure VNET.
Any feedback welcomed on how to achieve the above requirements.
Thank you!