How to run sql script as AAD user from Build pipeline?

Viewed 644

I'm setting up Managed Identity for my web app. As part of deployment I'm deploying database, run migrations and I also need to add the managed identity user with this script

CREATE USER [<identity-name>] FROM EXTERNAL PROVIDER;
ALTER ROLE db_datareader ADD MEMBER [<identity-name>];
ALTER ROLE db_datawriter ADD MEMBER [<identity-name>];
ALTER ROLE db_ddladmin ADD MEMBER [<identity-name>];
GO

as described here. I do this using Azure SQL Database deployment task. The problem I have is that this has to be executed as a Azure AD user.

Principal 'xyz' could not be created. Only connections established with Active Directory accounts can create other Active Directory users.

I don't want to use my account and I can't create new user accounts other than Guest users.

Is there any other option than to create user in Azure AD first and then provide it's login and password (stored as secure variable or in my Azure KeyVault)?

0 Answers
Related