do the setup in this order. Get your current IP and create a temporary server firewall rule for it with the Azure CLI: az sql server firewall-rule create with your resource group, server, a name like tmp-mi-setup, and your IP as both start and end. Then connect as the SQL Entra admin and run CREATE USER [your-app-name] FROM EXTERNAL PROVIDER, plus ALTER ROLE db_datareader ADD MEMBER and db_datawriter as needed. You can do it without sqlcmd installed using az sql db query with auth-mode ActiveDirectoryDefault. If youre scripting from a CI agent with no interactive login, mint a token yourself with az account get-access-token --resource https://database.windows.net/ and connect the mssql driver with azure-active-directory-access-token auth. The moment the user exists, delete the temp rule: az sql server firewall-rule delete. The app itself talks to the database over the Azure backbone, which the firewall allows without any IP rule, so leaving your laptop IP open would just be needless exposure.