Connect · Azure Database for PostgreSQL
Connect to Azure Database for PostgreSQL from your Mac
Copy the server name and admin login from the server’s Overview page, add your IP to the firewall rules on the Networking page, and connect on port 5432 with TLS, which the server requires by default.
Updated 9 October 2026
What you need
- The server name and admin login from the Azure portal, and the admin password (or a Microsoft Entra ID user, see below).
- A firewall rule for your IP address, if the server uses public access. A server created with private access (virtual network integration) has no public endpoint; reach it from inside the virtual network, for example through an SSH tunnel via a VM there.
Find your connection details
- In the Azure portal, open the server and its Overview page.
- Copy the Server name, which is the host:
<server>.postgres.database.azure.com. - Copy the Administrator login: on a flexible server it’s the plain name you chose, such as
myadmin.
The port is 5432, or 6432 for the built-in PgBouncer. Every server has a postgres database.
Firewall rules. With public access, no IP address is allowed until you add one. On the server’s Networking page, add your current client IP. Rules must be IPv4, and changes can take up to five minutes to apply. Allow public access from any Azure service lets in all of Azure, including other customers’ subscriptions, so it doesn’t help from your Mac and widens access.
Microsoft recommends always connecting with the server name, not an IP address: the IP can change.
PgBouncer. On General Purpose and Memory Optimized servers (not Burstable), you can turn on the
built-in PgBouncer with the pgbouncer.enabled server parameter (Parameters pane; no restart
needed). It listens on port 6432 on the same host name and pools in transaction mode by default.
Connection string
postgresql://<admin>:<password>@<server>.postgres.database.azure.com:5432/postgres?sslmode=verify-full
The portal and Microsoft’s quickstart use the key–value form:
host=<server>.postgres.database.azure.com port=5432 dbname=postgres user=<admin> password=<password> sslmode=require
Percent-encode special characters in the URL form; see special characters in passwords.
TLS
The server requires TLS by default (the require_secure_transport parameter is on) and accepts
TLS 1.2 and 1.3 only. Microsoft asks you not to turn that off.
Server certificates chain to public root CAs. Microsoft lists DigiCert Global Root G2 and
Microsoft RSA Root CA 2017 as the ones to trust (in China regions, DigiCert Global Root CA is
still valid too). Both are among the roots macOS trusts (checked on macOS 26.2, which also has them in
/etc/ssl/cert.pem). Use sslmode=verify-full: by default libpq clients use prefer and don’t
check the certificate at all.
Connect with Inlet
- Choose New Connection and enter the server name, port 5432, admin login and
postgres, or paste apostgresql://URL and Inlet fills in the form. - Under TLS, choose
verify-full. Inlet checks the certificate against the certificates macOS trusts, so you don’t need a CA file. - For a private access server, turn on the SSH tunnel through a VM in the virtual network.
Inlet runs the system
ssh, so your~/.ssh/config, the SSH agent and the 1Password SSH agent work. - Save the password in the Keychain or have Inlet ask every time.
- Tag the environment. A production connection opens read-only: the server refuses writes until you unlock it, for ten minutes.
Use port 5432 for production. Inlet’s read-only mode is a session setting. Through PgBouncer
on 6432 in transaction mode, each transaction can use a different server connection, and PgBouncer
doesn’t reset session state in that mode, so the setting isn’t guaranteed to hold. To make a role
read-only however it connects, set it on the server: ALTER ROLE <role> SET default_transaction_read_only = on. That’s a default a session can change, so for a hard limit
give the role only SELECT.
Microsoft Entra ID. Get a token with az account get-access-token --resource-type oss-rdbms
and use it as the password, with your Entra user principal name (for example
user@tenant.onmicrosoft.com) as the user. Tokens last between 5 and 60 minutes, so choose to be
asked for the password and paste a fresh one when you connect.
Connect from the command line
Microsoft’s example with certificate checks; on a Mac, point sslrootcert at the system roots:
psql "sslmode=verify-full sslrootcert=/etc/ssl/cert.pem host=<server>.postgres.database.azure.com dbname=postgres user=<admin>"
Through PgBouncer, change the port:
psql "host=<server>.postgres.database.azure.com port=6432 dbname=postgres user=<admin> sslmode=require"
With a Microsoft Entra ID token:
export PGPASSWORD=$(az account get-access-token --resource-type oss-rdbms --query "[accessToken]" -o tsv)
psql "host=<server>.postgres.database.azure.com user=<you@tenant.onmicrosoft.com> dbname=postgres sslmode=require"
Troubleshooting
Connection timed out: Microsoft’s first suspect is the firewall. Add your current IP on the Networking page (or withaz postgres flexible-server firewall-rule create), and allow a few minutes. If your IP changes often, ask your provider for its range. See connection refused.- no pg_hba.conf entry for host: Microsoft shows this as the error when the firewall blocks a connection.
- TLS required: if your client sends
sslmode=disable, the server refuses it. Userequireorverify-full. - password authentication failed: check the admin login and password; Entra user and group names are case-sensitive, and tokens expire.
- Too many connections: route your application through PgBouncer on 6432.
Related
Sources
- learn.microsoft.com/en-us/azure/postgresql/flexible-server/quickstart-create-server
- learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-networking-public
- learn.microsoft.com/en-us/azure/postgresql/flexible-server/how-to-connect-tls-ssl
- learn.microsoft.com/en-us/azure/postgresql/flexible-server/concepts-pgbouncer
- learn.microsoft.com/en-us/azure/postgresql/flexible-server/how-to-configure-sign-in-azure-ad-authentication
- www.pgbouncer.org/config.html