Set on an Azure SQL managed instance or logical server, this is the single Entra principal (a user, group, managed identity or service principal) able to log in to all its databases and to add further Entra users.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Entra admin in context, with comparison tables and the common traps.
Terms in this definition
- Set
Secret permission in Key Vault for writing secrets; some older material refers to it as Create.
- Azure SQL Managed Instance
Fully managed SQL Server instance offering almost complete compatibility, including SQL Agent, CLR and queries across databases; disaster recovery to another region is achieved with auto-failover groups.
- Logical server
In Azure SQL, the parent resource for a set of databases, carrying their logins, Entra admin, firewall rules, auditing and TDE configuration. Think of it as a management boundary; it isn't an instance of SQL Server.
- Principal
A user, group or service principal: anything that can receive a privilege grant.
- Chat message roles
Labels on chat messages: instructions go under system, the person's input under user, the model's previous answers under assistant, and results returned by a called tool under tool (or function).
- Managed identity
Identity in Microsoft Entra given to an Azure resource so that no secret has to be stored. It comes in two kinds: user-assigned and system-assigned.
- Service principal
The tenant-local instance of a managed identity or app registration, which users and Azure or directory roles are assigned to. Those from app registrations authenticate with a stored certificate or secret that needs rotating and can be copied, which suits code running outside Azure.
- ALL
A DAX function that ignores any filters and gives back every row of a table or every value of the named columns. Used within CALCULATE, it works as a modifier that clears filters, although REMOVEFILTERS states that intent more clearly where it is available.
Related terms
- Default user permissions
Entra settings governing ordinary users, such as whether they may register applications or open the Microsoft Entra admin portal. Blocking the portal only hides the UI and does not secure anything.
- Groups Administrator
A Microsoft Entra admin role for looking after groups in every admin center. Holders can create, change, delete and restore security and Microsoft 365 groups, control who may create groups and how they are named and expire, and license groups.
- License Administrator
A Microsoft Entra admin role that can give licences to and take them from users and groups, change a user's usage location and re-run group-based licence processing.
- SQL Server Contributor
Built-in role that can manage databases and logical servers, including setting the Microsoft Entra admin. Switching Microsoft Entra-only authentication on or off is beyond it, though Contributor or SQL Security Manager can do so.
- Two-gate policy
The built-in self-service password reset policy for anyone holding a Microsoft Entra admin role, which cannot be changed. It requires two verification methods and does not permit security questions.