Edit

Managed identities in Microsoft Entra for Azure Synapse Analytics

Microsoft Entra ID (formerly Azure Active Directory) supports two types of managed identities: system-assigned managed identity (SMI) and user-assigned managed identity (UMI). For more information, see Managed identity types.

You can use managed identities to access a Synapse SQL database by using the SQL connection string option Authentication=Active Directory Managed Identity. You need to create a SQL user from the managed identity in the target database by using the CREATE USER statement. For more information, see Using Microsoft Entra authentication with SqlClient.

Create a user-assigned managed identity

For information on how to create a UMI, see Manage user-assigned managed identities.

To use a UMI with a Synapse workspace, first create credentials in your service instance. For more information, see Managed service identity for Azure Synapse Analytics.

Permissions

To access a database in a dedicated or serverless SQL pool, create a database user for the managed identity and grant the required permissions. For details about Microsoft Entra users and database permissions in Synapse SQL, see SQL Authentication in Azure Synapse Analytics.