pvillard31 opened a new pull request, #11722:
URL: https://github.com/apache/nifi/pull/11722
# Summary
NIFI-16387 - Support Microsoft Entra access token authentication for SQL
Server in DBCP services
This change adds support for Microsoft Entra access-token authentication to
Microsoft SQL Server and Azure SQL through NiFi DBCP controller services.
The Azure Entra Database Password Provider previously supported Azure
Database for PostgreSQL and Azure Database for MySQL by supplying an OSS RDBMS
token through the JDBC password property. The Microsoft JDBC Driver for SQL
Server instead requires the token through its `accessToken` property.
- Added `DatabaseCredentialPlacement` to the DBCP service API with:
- `PASSWORD`
- `ACCESS_TOKEN`
- Added a backward-compatible default placement method to
`DatabasePasswordProvider`.
- Updated the provider-aware DBCP data source to use attempt-local JDBC
properties for every physical connection.
- Added access-token placement that:
- Removes `user`, `userName`, and `password` aliases case-insensitively.
- Sets canonical blank `user` and `password` values.
- Sets the generated credential as `accessToken`.
- Preserves other JDBC properties for driver validation.
- Ensured provider-returned credential arrays are cleared.
- Ensured attempt-local credentials are removed after successful and failed
connection attempts.
- Added database target selection to the Azure Entra Database Password
Provider:
- **Azure OSS Database**, using the existing OSS RDBMS scope and password
placement.
- **Microsoft SQL Server**, using the SQL Server scope and access-token
placement.
- Kept Azure OSS Database as the default to preserve existing configurations.
- Updated provider documentation for both target types, token scopes, JDBC
behavior, and validation boundaries.
- Expanded existing tests without increasing the test-method count.
The changes were tested against a SQL Server instance deployed in Azure with
authentication using Workload Identity Federation via an Entra application.
<img width="1056" height="327" alt="Screenshot 2026-09-25 at 14 28 14"
src="https://github.com/user-attachments/assets/d69f5193-829a-400f-8acc-205f4ad53e2d"
/>
<img width="1052" height="587" alt="Screenshot 2026-09-25 at 14 28 29"
src="https://github.com/user-attachments/assets/49caf573-80bb-4240-a3c9-0633fe5cebd2"
/>
# Tracking
Please complete the following tracking steps prior to pull request creation.
### Issue Tracking
- [Apache NiFi Jira](https://issues.apache.org/jira/browse/NIFI) issue
created
### Pull Request Tracking
- Pull Request title starts with Apache NiFi Jira issue number, such as
`NIFI-00000`
- Pull Request commit message starts with Apache NiFi Jira issue number, as
such `NIFI-00000`
- Pull request contains [commits
signed](https://docs.github.com/en/authentication/managing-commit-signature-verification/signing-commits)
with a registered key indicating `Verified` status
### Pull Request Formatting
- Pull Request based on current revision of the `main` branch
- Pull Request refers to a feature branch with one commit containing changes
# Verification
Please indicate the verification steps performed prior to pull request
creation.
### Build
- [ ] Build completed using `./mvnw clean install -P contrib-check`
- [ ] JDK 21
- [ ] JDK 25
### Licensing
- [ ] New dependencies are compatible with the [Apache License
2.0](https://apache.org/licenses/LICENSE-2.0) according to the [License
Policy](https://www.apache.org/legal/resolved.html)
- [ ] New dependencies are documented in applicable `LICENSE` and `NOTICE`
files
### Documentation
- [ ] Documentation formatting appears as expected in rendered files
--
This is an automated message from the Apache Git Service.
To respond to the message, please log on to GitHub and use the
URL above to go to the specific comment.
To unsubscribe, e-mail: [email protected]
For queries about this service, please contact Infrastructure at:
[email protected]