Azure-docs: Login to private link using internal DNS A record and AAD User Fails but works with SQL Login

Created on 11 Mar 2020  Â·  5Comments  Â·  Source: MicrosoftDocs/azure-docs

Hi,

I have setup a private link and we are using our custom internal AD DNS to access. However, we can only access using local SQL Logins and not Azure AD logins when attempting to connect using the A record created in our DNS. I can however login using AAD accounts when connecting using the public FQDN. The error message I receive when attempting using the internal DNS FQDN we created on an AAD account seems common, but I'm not sure if there is a problem or if I'm doing something wrong or not supported.

Error: Cannot connect to azuresqlserver.domain.local, A connection was successfully established with the server, but then an error occurred during the login process. (provider: SSL Provider, error: 0 -The target principal name is incorrect.)

Is it because we are using on-prem AD synced with AAD (using AAD Connect) that is the reason this isn't working? Or is the fact that we elected to use our own DNS instead of the one provided by Azure, which really won't work in our case since we are a hybrid environment?


Document Details

⚠ Do not edit this section. It is required for docs.microsoft.com ➟ GitHub issue linking.

Pri2 assigned-to-author private-linsvc product-question triaged

Most helpful comment

We fixed this by ticking: Trust Server Certificate in the SMSS connection settings. I imagine the default certificate on the servers doesn't yet cover *.privatelink.database.windows.net .

All 5 comments

@lshunnarah77
Thanks for your feedback! We will investigate and update as appropriate.

@malopMSFT , Can you please comment whether this scenario is supported or not?

We fixed this by ticking: Trust Server Certificate in the SMSS connection settings. I imagine the default certificate on the servers doesn't yet cover *.privatelink.database.windows.net .

I could have sworn I tried that combination but apparently not. Either way, that worked! Thank you tomkeatingfei!!!

@tomkeatingfei - Thanks for sharing the answer. It saved me a lot. :)-

Was this page helpful?
0 / 5 - 0 ratings

Related issues

spottedmahn picture spottedmahn  Â·  3Comments

ianpowell2017 picture ianpowell2017  Â·  3Comments

paulmarshall picture paulmarshall  Â·  3Comments

Favna picture Favna  Â·  3Comments

jamesgallagher-ie picture jamesgallagher-ie  Â·  3Comments