if your workflow fails with a login timeout against Azure SQL, check the firewall before you touch the connection string. Pick one path. Path one, simplest: on the SQL server enable the option that lets Azure services and resources reach the server. Path two, tighter: add an Azure/login step before the sql-action step in your workflow. Make sure the service principal that login uses is in the SQL Security Manager RBAC role, otherwise the action cant create the firewall rule and youll get a permission error instead. The action then adds a rule scoped to the runner IP, runs your scripts, and removes the rule again. That keeps the database closed to everything except the runner for the duration of the job, which is the secure setup.