Forum Discussion
Azure SQL Firewall
Hi AJAJ ,
Grayed-out IPs in Azure SQL Firewall typically indicate server-level firewall rules that were created by the server-level principal login. According to Microsoft documentation, only the server-level principal login—the account created during the initial provisioning of the SQL server—can delete these rules using sp_delete_firewall_rule
Refer-
https://learn.microsoft.com/en-us/sql/relational-databases/system-stored-procedures/sp-delete-firewall-rule-azure-sql-database?view=azuresqldb-current
Even with Subscription Admin and SQL Security Manager roles, you won’t have access to delete these rules unless:
- You are logged in as the server-level principal login, or
- You are assigned as a Microsoft Entra admin for the SQL server
Therefore you can follow these steps-
- Confirm whether you are the server-level principal login or request access from whoever is.
- If you’re not, ask your Azure admin to assign you as a Microsoft Entra admin for the SQL server.
- Remove the resource group lock if you have the necessary permissions or request it from someone who does.
Hope this helps!
Thanks.
For someone referring this in future.
I got myself as Owner of resource group, navigated to Azure SQL DB. Of course as recommended above, need to be a contributor (i guess may not matter since your id is admin). On the other hand, you could ask whoever is the admin to do the below to remove / clean up greyed out IPs on Azure SQL.