Fix Azure SQL Error 18456 Login Failed for User
Question details
The user needs to resolve an authentication error preventing an Azure App Service API from connecting to an Azure SQL database.

- Product
- Azure SQL
- Device & OS
- not provided
- Scenario
- Connecting an Azure App Service API to an Azure SQL database after adding a new development database to the same production server.
- Observed behavior
- The App Service API fails to connect, returning Microsoft.Data.SqlClient error 18456, State 1 (Login failed for user).
Ensure you have administrator access to the Azure Portal for both your Azure App Service and the target Azure SQL Server. Have your connection strings, database names, and user credentials ready for verification.
Verify App Service Connection Strings and Credentials
Incorrect connection strings or mismatched database credentials are the most common causes of Error 18456, especially after new databases are added to the server.
When multiple databases exist on a single Azure SQL server, failing to specify the exact database in the connection string can route the request to the default master database, where the user might not have access.
Log into the Azure Portal, navigate to your App Service, and select 'Configuration' under the Settings menu.
Locate your SQL connection string and verify that the 'Initial Catalog' or 'Database' parameter points to the correct database name, not the newly added development database (unless intended).
Ensure that the 'User ID' and 'Password' within the connection string exactly match the valid credentials configured in the Azure SQL database.

Check SQL User Permissions and Firewall Rules
Even with correct credentials, the API will fail to connect if the database user lacks proper permissions or if Azure Firewall blocks the App Service IP.
Escalate to Official Microsoft Support
If all configurations and permissions are perfectly valid and the error persists, the issue might require Microsoft's backend investigation.
Document Your Azure SQL Architecture with WPS Office
While troubleshooting complex Azure SQL connection errors, keeping track of your database architectures, API documentation, and SQL data exports is vital. WPS Office provides a lightweight, fully compatible suite to manage Word documents, Excel spreadsheets, and PDFs natively—without the high subscription cost of Microsoft Office.
- 1. Download WPS Office: Visit the official WPS Office website and download the free installer for your operating system.
- 2. Install the Software: Run the setup file and follow the quick on-screen instructions to install the lightweight suite.
- 3. Open Your Documents: Launch WPS Office to immediately start viewing or editing your SQL data exports and configuration documentation.

Frequently Asked Questions
What does State 1 mean in Azure SQL Error 18456?
State 1 is a masked state used by Microsoft SQL Server for security reasons. It indicates that the login failed but purposely hides the exact reason (such as whether the username doesn't exist or the password was simply incorrect) to prevent attackers from guessing credentials.
Why did Error 18456 start occurring after adding a new development database?
Adding a new database often involves updating server-wide connection strings or creating new users. If the App Service connection string was accidentally modified to point to the new database, but the API user lacks permissions for that specific database, a login failure will trigger.
How do I fix 'login failed for user' when using Azure Active Directory authentication?
If you are authenticating via AAD, ensure that your Azure App Service has a Managed Identity enabled. Then, log into your SQL database as an AAD admin and use the 'CREATE USER' command to add the Managed Identity to the database, followed by granting it the necessary data reader/writer roles.




