Skip to content
Discussion options

You must be logged in to vote

Hi @Koro110,

Thank you for your question.

[Q1]: Yes. Both app registrations will be needed if your MCP client also authenticates with Entra before reaching out to the SQL MCP Server (in DAB).

[Q2]: Yes that is correct. The resulting configuration should be as per the example here: https://learn.microsoft.com/en-us/azure/data-api-builder/concept/security/authenticate-entra?tabs=bash#resulting-configuration

[Q3]: That is true. RLS feature uses SESSION_CONTEXT.
Additionally, if you also need a "Pass Through" authentication i.e. the MCP client is also a user in SQL, you could use the On behalf of feature introduced in DAB 2.0.0-rc currently in preview. In addition to the RLS feature, OBO allo…

Replies: 1 comment 2 replies

Comment options

You must be logged in to vote
2 replies
@Koro110
Comment options

@Aniruddh25
Comment options

Answer selected by Aniruddh25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants