Connect · Amazon RDS
Connect to Amazon RDS for SQL Server from your Mac
Copy the endpoint and port from the Connectivity & security tab and sign in as the master user you chose, not sa; it isn’t a sysadmin. Your Mac needs a network path (a publicly accessible instance and a security group rule, or a bastion and an SSH tunnel) and the RDS CA bundle to check the certificate.
Updated 9 October 2026
What you need
- The instance’s endpoint and port, and the master user name and password (or another login).
- A network path from your Mac. AWS says the instance must be reachable from your network: for a Mac outside the VPC, that means publicly accessible and a VPC security group rule that lets your address in on the instance’s port. Otherwise, go through a host inside the VPC.
- The RDS certificate bundle,
global-bundle.pem, to check the server’s certificate.
Find your connection details
- Open the Amazon RDS console, choose the instance’s Region, and choose Databases.
- Choose the SQL Server instance. On the Connectivity & security tab, copy the Endpoint and note the Port (1433 unless you chose another).
- On the Configuration tab, Master username is the login RDS created for you.
Or from the AWS CLI:
aws rds describe-db-instances \
--query "DBInstances[].[DBInstanceIdentifier,Engine,Endpoint.Address,Endpoint.Port,MasterUsername,CACertificateIdentifier]"
The instance’s status must be available before anything connects.
Network access. RDS instances start with a firewall that lets nothing in. Add an inbound rule to the instance’s VPC security group for its port from your address (the console’s My IP source fills it in). For an instance that isn’t publicly accessible, AWS recommends a VPN or AWS Direct Connect, or else a bastion host: an EC2 instance in the same VPC that you tunnel through over SSH. RDS also refuses client connections from 169.254.0.0/16 addresses.
The master user is your administrator, not sa, and it isn’t a sysadmin. It’s a SQL Server login in the processadmin, public
and setupadmin server roles, with server permissions such as CREATE ANY DATABASE,
ALTER ANY LOGIN and VIEW SERVER STATE. The sysadmin, serveradmin, securityadmin,
dbcreator, bulkadmin and diskadmin roles aren’t available on RDS at all; RDS keeps
administration (backups, server settings, shutdown) for itself, and you change server settings
through a DB parameter group instead. If the master user loses its permissions, setting a new master
password (Modify) restores them.
There’s no database for your app yet. You sign in to master. Create your own database and a
login for your app:
CREATE DATABASE app;
GO
CREATE LOGIN app WITH PASSWORD = '<app-password>', DEFAULT_DATABASE = app;
GO
USE app;
CREATE USER app FOR LOGIN app;
ALTER ROLE db_owner ADD MEMBER app;
GO
Whoever creates a database becomes its db_owner. RDS adds a few naming rules: database names can’t
start with rdsadmin (RDS’s own database), start or end with a space, or contain a single quote.
The number of databases per instance depends on the instance class: 30 on the smallest classes, up
to 100.
Editions. RDS runs SQL Server 2016, 2017, 2019, 2022 and 2025, as Express, Web, Standard and Enterprise editions, plus Developer Edition (non-production, installed from media you upload). They all connect the same way.
Connection string
Server=tcp:<instance>.<id>.<region>.rds.amazonaws.com,1433;Initial Catalog=<database>;User ID=<user>;Password=<password>;Encrypt=True;TrustServerCertificate=False;
As a URL:
sqlserver://<user>:<password>@<instance>.<id>.<region>.rds.amazonaws.com:1433?database=<database>&encrypt=true
Percent-encode special characters in the URL form; see special characters in passwords and SQL Server connection strings.
TLS
RDS gives every SQL Server instance a certificate with the instance endpoint as its common name, and
every edition supports encryption. It isn’t required unless you ask for it: set the
rds.force_ssl parameter to 1 in a custom DB parameter group (the default group can’t be
changed). The parameter is static, so reboot the instance afterwards. To see whether your own
session is encrypted, AWS suggests:
SELECT encrypt_option FROM sys.dm_exec_connections WHERE session_id = @@SPID;
The certificate is signed by an Amazon RDS certificate authority, rds-ca-rsa2048-g1 unless you
chose another. macOS doesn’t trust these CAs (none is in the system roots on macOS 26.2), so
download the bundle that covers every commercial Region:
curl -O https://truststore.pki.rds.amazonaws.com/global/global-bundle.pem
Trust only the root certificates in it. AWS warns that adding the intermediate certificates to a trust store can break connections when RDS rotates the server certificate.
Connect with Inlet
- Choose New Connection, pick SQL Server, and enter the endpoint, port, master user (or your
login), password and database. Or paste the ADO.NET string or a
sqlserver://URL and Inlet fills in the form. - Under encryption, choose to verify the certificate and the host name, and select
global-bundle.pemas the CA certificate. Without it, the check fails: Inlet says “The server’s certificate couldn’t be verified:” followed by OpenSSL’s reason. - For an instance that isn’t publicly accessible, turn on the SSH tunnel and give the bastion host.
Keep the RDS endpoint as the database host. Inlet uses the system
ssh, so~/.ssh/configand the SSH agent work. - Save the password in the Keychain, or have Inlet ask every time.
- Tag the environment. A production connection opens read-only: SQL Server has no read-only
session, so Inlet refuses writes itself, before they’re sent. For a limit the server enforces,
sign in as a login whose user is only in
db_datareader.
Inlet’s Activity view (sessions and who blocks whom, locks, table sizes, the plan cache’s costliest
queries) needs VIEW SERVER STATE (VIEW SERVER PERFORMANCE STATE is enough on SQL Server 2022
and later). The master user has VIEW SERVER STATE; other logins may not.
Connect from the command line
Microsoft’s Go-based sqlcmd installs with Homebrew (brew install sqlcmd). Give the endpoint and
port with a comma, and leave out -P to be asked for the password:
sqlcmd -S <instance>.<id>.<region>.rds.amazonaws.com,1433 -U <master-user> -d master
Microsoft documents that go-sqlcmd checks the certificate only when you pass -N (without -C),
and checks it against the certificates your Mac trusts, which don’t include the RDS CAs. We
couldn’t run this against RDS for this page; it follows Microsoft’s and AWS’s documentation as of
October 2026. To check that the port is open from your network first:
nc -vz <instance>.<id>.<region>.rds.amazonaws.com 1433
Troubleshooting
- A network-related or instance-specific error or
a timeout: check the endpoint and port, that Publicly accessible is Yes, and that the security
group allows your current IP address. Some company networks block outgoing port 1433. Inlet says
Couldn’t connect to <host>:1433: Operation timed out. - Login failed for user: wrong user name or password. The master user name is on the Configuration tab; to reset the password, modify the instance and set a new master password.
- Cannot open database requested by the login: the database doesn’t exist yet (a new instance has only the system databases) or your login has no user in it.
- The certificate chain isn’t trusted: the
client doesn’t have the RDS CA, or you connected by IP address or your own DNS name. Use the
endpoint and
global-bundle.pem. - A permission is denied for something server-wide: the master user isn’t
sysadmin, and RDS doesn’t grant permissions such asALTER SETTINGSorSHUTDOWN. Use a DB parameter group for server settings and the console’s reboot for restarts. - The port you wanted is refused when creating the instance: RDS reserves 1234, 1434, 3260, 3343, 3389, 47001 and 49152–49156 on SQL Server instances.
Related
Sources
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToMicrosoftSQLServerInstance.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/CHAP_SQLServer.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/SQLServer.Concepts.General.FeatureSupport.UnsupportedRoles.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.MasterAccounts.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/SQLServer.Concepts.General.SSL.Using.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/UsingWithRDS.SSL.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/sqlserver-dev-edition.html
- docs.aws.amazon.com/AmazonRDS/latest/UserGuide/USER_ConnectToInstance.html
- repost.aws/knowledge-center/rds-connect-ec2-bastion-host
- learn.microsoft.com/en-us/sql/tools/sqlcmd/sqlcmd-utility