In Azure SQL, the parent resource for a set of databases, carrying their logins, Entra admin, firewall rules, auditing and TDE configuration. Think of it as a management boundary; it isn't an instance of SQL Server.
Also called Azure SQL server.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Logical server in context, with comparison tables and the common traps.
Terms in this definition
- Auditing
Azure SQL capability that sends database audit logs to Log Analytics, Event Hubs or a storage account; that account is allowed to be in a different region.
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Transparent Data Encryption
At-rest encryption of database files and nothing more; any user able to query the database still reads the data in plaintext.
- SQL Server
The relational database from Microsoft that organisations host and run themselves, in their own data centres or on VMs. Its engine also sits underneath the Azure SQL services and SQL database in Fabric.
Related terms
- Deny public network access
When switched on for an Azure SQL logical server, connections through the public endpoint are refused and clients can only get in through a private endpoint.
- Login
A server-wide security principal used for connecting to SQL Server or an Azure SQL logical server; users inside each database are linked to it. EXECUTE AS LOGIN can't be used in Azure SQL Database.
- Microsoft Entra admin
Set on an Azure SQL managed instance or logical server, this is the single Entra principal (a user, group, managed identity or service principal) able to log in to all its databases and to add further Entra users.
- Microsoft Entra-only authentication
Setting on an Azure SQL server that turns off SQL authentication, leaving Entra identities as the only way to connect.
- SAMI
A system-assigned managed identity, which exists only as long as the single Azure resource it belongs to. To mirror Azure SQL Database or Azure SQL Managed Instance, the logical server's SAMI must be turned on and set as the primary identity (for SQL Database a user-assigned identity can be used instead, in preview).
- Server IP firewall rules
Rules on an Azure SQL logical server that permit ranges of public source IPs. Private VNet addresses never match them; those require a virtual network rule.
- Server-level auditing
An auditing policy set on the Azure SQL logical server that applies to every database on it. Turning on database-level auditing adds destinations instead of overriding the server policy.
- Server-level auditing policy
An auditing setup defined once on the Azure SQL logical server. It covers every database on that server, current or added later, whatever each database's own audit settings say.