Azure-docs: MFA or firewall issues?

Created on 10 Jul 2019  Â·  18Comments  Â·  Source: MicrosoftDocs/azure-docs

According to this documentation, Azure AD admin sign in doesn't work with accounts that have 2-factor authentication enabled. This is weird because it used to work?

Right now we get the following error "A connection to the server 'ABC.database.windows.net' could not be established. This may indicate an issue with your network connection or firewall configuration. Please check your network connection and try again."

Is this error related to MFA?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri1 assigned-to-author developmensubsvc product-question sql-databassvc triaged

Most helpful comment

@ryanps1 Found the issue was related to port 1443 - open that up and you should be fine, as stated by the yellow ribbon after the error is thrown.

All 18 comments

@bartvermeersch Are you trying this from the Azure portal? Could you please check if the firewall is configured to allow your client IP address.
I just tried using an account with 2FA and I was able to sign in without issues.

@bartvermeersch Did you get a resolution for this? Am experiencing the same issue.

I am working with my dev team to investigate the issue. I will try to get back to you as soon as possible with info on this issue.

@ninarn Following up to see if you have any updates on this issue?

This is being assigned to the content author to provide more information.

I will be able to follow up early next week with an update.

Thank you for your patience I have an update on this issue. My team is confident that they know the cause of your issue and they have implemented a fix that should go out soon. Please wait until late this week or early next week and try again. Once this fix is in place, if you encounter the issue, you will be able to click 'Try again' and it should work the second time.
I should also add clarification that we have never supported multi-factor authentication within the query editor feature. Meaning that you will not be able to login to the query editor using 2-factor auth. However if you logged in to the Azure portal with AAD MFA, connecting to the query editor with AAD should work. And we expect the fix to be available soon.

I also have MFA enabled account, login using Azure AD authentication on Query Editor takes some time and then fails but if I click Continue it works just fine. So, its not a blocker but not a good experience. Is this expected to be resolved soon?

I'm currently unable to login with the query editor using either the local administrator credentials or with Azure AD. I do have MFA on my account, but for both my AD account and a local administrator, I'm receiving the below message:

A connection to the server 'XXX.database.windows.net' could not be established. This may indicate an issue with your network connection or firewall configuration. Please check your network connection and try again.

To confirm, my local IP address is whitelisted along with Azure Services being allowed. Is anybody else experiencing this issue?

@ryanps1 I am facing the same issue. Now if only I can find the default query that Query Editor provides, I would be able to work around this annoyance.

If anyone knows the default Query for searching logged events on SQL, please share!

If anyone else was looking;

SELECT TOP 100 event_time, server_instance_name, database_name, server_principal_name, client_ip, statement, succeeded, action_id, class_type, additional_information FROM sys.fn_get_audit_file('https://xxx.blob.core.windows.net/xxx/xxx/xxx/2019-09-19/xxx.xel', default, default) WHERE (event_time <= '2019-09-19T00:00:49.586Z') /* additional WHERE clause conditions/filters can be added here */ ORDER BY event_time DESC

@ryanps1 Found the issue was related to port 1443 - open that up and you should be fine, as stated by the yellow ribbon after the error is thrown.

Yes, the query editor uses ports 443 and 1443 to communicate. Please ensure you have enabled outbound HTTPS traffic on these ports. You will also need to add your outbound IP address to the server's allowed firewall rules to access your databases and data warehouses.
Please try these and see if you can connect to query editor?

Hi there I am unable to connect to view the Query Editor. I have added the Rules according to the documentation. And I am using the local account to access the Query Editor. It keeps throwing a firewall/proxy error

Can you please clarify what error messages you are seeing when you try to connect to the query editor?

Hi this has been resolved now. It was our corporation firewall. We needed
to add port 1443 and 1433

On Tue, 3 Mar 2020, 18:04 Ninar Nuemah, notifications@github.com wrote:

Can you please clarify what error messages you are seeing when you try to
connect to the query editor?

—
You are receiving this because you commented.
Reply to this email directly, view it on GitHub
https://github.com/MicrosoftDocs/azure-docs/issues/34827?email_source=notifications&email_token=AOMXHVNZKGGZEPAUCAP7XGLRFVBCHA5CNFSM4H7NJSHKYY3PNVWWK3TUL52HS4DFVREXG43VMVBW63LNMVXHJKTDN5WW2ZLOORPWSZGOENUQZEQ#issuecomment-594087058,
or unsubscribe
https://github.com/notifications/unsubscribe-auth/AOMXHVKN3ZJIV4IIECFFDOLRFVBCHANCNFSM4H7NJSHA
.

please-close

Was this page helpful?
0 / 5 - 0 ratings

Related issues

Ponant picture Ponant  Â·  3Comments

DeepPuddles picture DeepPuddles  Â·  3Comments

paulmarshall picture paulmarshall  Â·  3Comments

AronT-TLV picture AronT-TLV  Â·  3Comments

Agazoth picture Agazoth  Â·  3Comments