Loading...

Active Directory Connector (ADC) for Arc-enabled SQL Managed Instance is now generally available!

Active Directory Connector (ADC) for Arc-enabled SQL Managed Instance is now generally available!

We are excited to announce the General Availability of Active Directory Connector (ADC) for Arc-enabled SQL Managed Instance.

 

Active Directory Connector Overview

Azure Arc-enabled data services support Active Directory (AD) for Identity and Access Management (IAM). The Arc-enabled SQL Managed Instance uses an existing on-premises Active Directory (AD) domain for authentication.

 

To facilitate this, Azure Arc-enabled data services introduce a new Kubernetes-native Custom Resource Definition (CRD) called Active Directory Connector. It provides Azure Arc-enabled SQL Managed Instances running on the same data controller the ability to perform Active Directory authentication.


To enable Active Directory authentication for SQL Server on Linux and Linux containers, use a keytab file. The keytab file is a cryptographic file containing service principal names (SPNs), account names, and hostnames. SQL Server uses the key tab file for authenticating itself to the Active Directory (AD) domain and authenticating its clients using Active Directory (AD).

 

 

active-directory-user-journey.png

 


Active Directory Integration Modes

Active Directory Connector for Arc-enabled SQL Managed Instance allows deployment in two integration modes:

  • Customer-managed keytab
  • System-managed keytab

 

 

Customer-managed keytab

System-managed keytab

Use cases Small and medium size businesses who are familiar with managing Active Directory objects and want flexibility in their automation process. All sizes of businesses - seeking highly automated Active Directory management experience.
User provides An Active Directory account and SPNs under that account, and a keytab file for Active Directory authentication. An Organizational Unit (OU) and a domain service account have sufficient permissions on that OU in Active Directory.
Characteristics User managed. Users bring the Active Directory account, which impersonates the identity of the managed instance and the keytab file. System managed. The system creates a domain service account for each managed instance and sets SPNs automatically on that account. It also creates and delivers a keytab file to the managed instance.
Deployment process

1. Deploy data controller.
2. Create keytab file.
3. Set up keytab information to Kubernetes secret.
4. Deploy Active Directory connector.

5. Deploy SQL Managed Instance.

For more information, see Deploy a customer-managed keytab Active Directory connector

1. Deploy data controller.

2. Deploy Active Directory connector.
3. Deploy SQL Managed Instance.

For more information, see Deploy a system-managed keytab Active Directory connector

Manageability You can create the keytab file by following the instructions from Active Directory utility (adutil). Manual keytab rotation. Managed keytab rotation.
Limitations We do not recommend sharing keytab files among services. Each service should have a specific keytab file. As the number of keytab files increases the level of effort and complexity increases. Managed keytab generation and rotation. The service account will require sufficient permissions in Active Directory to manage the credentials.

Distributed Availability Group is not supported.

 

Get started today with an Active Directory Connector deployment using the az CLI, or Azure Portal.

 

Mikhail Almeida

Product Manager at Microsoft, Azure Data

Published on:

Learn more
Azure Arc Blog articles
Azure Arc Blog articles

Azure Arc Blog articles

Share post:

Related posts

Azure Adaptive Cloud Pre-Days at Microsoft Ignite 2024

As the excitement builds for Microsoft Ignite 2024, tech enthusiasts and professionals worldwide are eagerly anticipating the Azure Adaptive C...

1 year ago

Launching the Arc Jumpstart Newsletter: October 2024 Edition

๐Ÿ‘‹ Welcome! We are excited to kick off this monthly newsletter, where you can get the latest updates on everything happening in the Arc Jumpst...

1 year ago

Announcing Public Preview of Windows Server Hotpatch enabled by Azure Arc

Weโ€™re excited to announce the Public Preview of Hotpatch enabled by Azure Arc for Windows Sever 2025 Datacenter and Standard editions!   ...

1 year ago

Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes

Release Summary  We are thrilled to announce the Public Preview of Azure Container Storage enabled by Azure Arc Edge Volumes, a groundbre...

1 year ago

Introducing ArcBox 3.0 General Availability

Today, the Arc Jumpstart team is excited to announce the general availability of ArcBox 3.0!   Since it was first introduced in 2021, Ar...

2 years ago

CloudCasa for Azure Arc

Azure Arc is a platform that helps users build and develop their applications by extending Azure to their datacenters, edge, or even to multic...

2 years ago

Generally Available: Transition to WS2012 / R2 ESUs enabled by Azure Arc from Volume Licensing

Customers that have enrolled in WS2012/ R2 ESUs through Volume Licensing for Year 1 can transition to Azure Arc for Year 2 of the program. Ext...

2 years ago

Comparing feature sets for AKS enabled by Azure Arc deployment options

This article shows a comparison of features available for the different deployment options under AKS enabled by Azure Arc.    ...

2 years ago

Increasing Security for SQL Server Enabled by Azure Arc

Back in November 2023, the least privileges deployment model was introduced as a public preview. After thorough testing, we are excited to ann...

2 years ago

Five Key Updates on WS2012 ESUs enabled by Azure Arc

We have a myriad of key updates for customers enrolled in WS2012/R2 ESUs enabled by Azure Arc! As we continue to refine and expand the offer, ...

2 years ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts โ€” delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.