| title | Create SQL Server on a Windows Virtual Machine in the Azure Portal | ||
|---|---|---|---|
| description | This tutorial shows how to create a Windows virtual machine with SQL Server in the Azure portal. | ||
| author | MashaMSFT | ||
| ms.author | mathoma | ||
| ms.reviewer | dpless | ||
| ms.date | 09/16/2025 | ||
| ms.service | azure-vm-sql-server | ||
| ms.subservice | deployment | ||
| ms.topic | quickstart | ||
| ms.custom |
|
||
| tags | azure-resource-manager |
[!INCLUDE appliesto-sqlvm]
[!div class="op_single_selector"]
This quickstart steps through creating a SQL Server virtual machine (VM) in the Azure portal. Follow the article to deploy either a conventional SQL Server on Azure VM or SQL Server deployed to an Azure confidential VM.
Tip
- This quickstart provides a path for quickly provisioning and connecting to a SQL VM. For more information about other SQL VM provisioning choices, see the Provisioning guide for SQL Server on Windows VMs in the Azure portal.
- If you have questions about SQL Server virtual machines, see the Frequently Asked Questions.
If you don't have an Azure subscription, create a free account before you begin.
-
In the pane for SQL Server on Azure Virtual Machines, select Show options.
:::image type="content" source="media/sql-vm-create-portal-quickstart/show-options-create-virtual-machine.png" alt-text="Screenshot from the Azure portal of the Azure SQL hub, showing the Show options button and the Create SQL Managed Instance button." lightbox="media/sql-vm-create-portal-quickstart/show-options-create-virtual-machine.png":::
-
In the Select an image offer box, choose a SQL Server image (such as Free SQL Server License: SQL Server 2025 Enterprise Developer on Windows Server 2025).
For conventional SQL Server VMs, select one of the versions labeled Free SQL Server License... from the dropdown. For Confidential VMs, choose the
SQL Server 2022 Enterprise / Developer / Standard / Web on Windows Server 2022 - x64 Gen 2image from the drop-down list. -
Select Create virtual machine.
The instructions for basic details vary between deploying a conventional SQL Server on Azure VM and SQL Server on an Azure confidential VM.
[!INCLUDE sql-vm-deployment-failure]
To deploy a conventional SQL Server on Azure VM, on the Basics tab, provide the following information:
-
In the Project Details section, select your Azure subscription, and then select Create new to create a new resource group. Type SQLVM-RG for the name.
-
Under Instance details:
- Type SQLVM for the Virtual machine name.
- Choose a location for your Region.
- For the purpose of this quickstart, leave Availability options set to No infrastructure redundancy required. To find out more information about availability options, see Availability.
- In the Image list, select the image with the version of SQL Server and operating system you want. For example, you can use an image with a label that begins with Free SQL Server License.
- Choose to See all sizes for the Size of the virtual machine, and select the A2 Basic offering. Be sure to clean up your resources once you're done with them to prevent any unexpected charges.
-
Under Administrator account, provide a username such as azureuser and a password. The password must be at least 12 characters long and meet the defined complexity requirements.
-
Under Inbound port rules, choose Allow selected ports, and then select RDP (3389) from the dropdown.
To deploy your SQL Server to an Azure confidential VM, on the Basics tab, provide the following information:
-
In the Project Details section, select your Azure subscription, and then select Create new to create a new resource group. Type SQLVM-RG for the name.
-
Under Instance details:
- Type SQLVM for the Virtual machine name.
- Choose a location for your Region. To validate region supportability, look for the
ECadsv5-seriesorDCadsv5-seriesin VM products Available by Azure region. - For Security type, choose Confidential virtual machines from the dropdown. If this option is grayed out, it's likely the chosen region doesn't currently support confidential VMs. Choose a different region from the drop-down.
- For the purpose of this quickstart, leave Availability options set to No infrastructure redundancy required. To find out more information about availability options, see Availability.
- In the Image list, choose the
SQL Server 2022 Enterprise on Windows Server 2022 Database Engine Onlyimage. To change the SQL Server image, select See all images, and then filter by Security type = Confidential VMs to identify all SQL Server images that support confidential VMs. - Leave the size at the default of
Standard_EC2ads_v5. However, to see all available sizes, select See all sizes to identify all the VM sizes that support confidential VMs, as well as the sizes that don't.
:::image type="content" source="media/sql-vm-create-portal-quickstart/basic-instance-details-confidential.png" alt-text="Screen shot of the Azure portal showing instance details.":::
-
Under Administrator account, provide a username such as azureuser and a password. The password must be at least 12 characters long and meet the defined complexity requirements.
:::image type="content" source="media/sql-vm-create-portal-quickstart/basics-administrator-account.png" alt-text="Screen shot of the Azure portal, Administrator account":::
-
Under Inbound port rules, choose Allow selected ports, and then select RDP (3389) from the dropdown.
:::image type="content" source="media/sql-vm-create-portal-quickstart/basics-inbound-port-rules.png" alt-text="Screen shot of the Azure portal, Inbound port rules.":::
Configure confidential OS disk encryption. This is optional for test VMs but recommended for production environments. For greater details, review the Quickstart: Deploy a confidential VM.
-
On the tab Disks, configure the following settings:
- Under Disk options, enable Confidential compute encryption if you want to encrypt your VM's OS disk during creation.
- For Confidential compute encryption type, select the type of encryption to use.
- If Confidential disk encryption with a customer-managed key is selected, create a Confidential disk encryption set before creating your confidential VM.
-
(Optional) If necessary, create a Confidential disk encryption set as follows.
-
Create an Azure Key Vault. For the pricing tier, select Premium (includes support for HSM backed keys), or create an Azure Key Vault managed Hardware Security Module (HSM).
-
In the Azure portal, search for and select Disk Encryption Sets.
-
Select Create.
-
For Subscription, select which Azure subscription to use.
-
For Resource group, select or create a new resource group to use.
-
For Disk encryption set name, enter a name for the set.
-
For Region, select an available Azure region.
-
For Encryption type, select Confidential disk encryption with a customer-managed key.
-
For Key Vault, select the key vault you already created.
-
Under Key Vault, select Create new to create a new key.
[!NOTE]
If you selected an Azure managed HSM previously, use PowerShell or the Azure CLI to create the new key instead. -
For Name, enter a name for the key.
-
For the key type, select RSA-HSM.
-
Select your key size.
-
Select Create to finish creating the key.
-
Select Review + create to create a new disk encryption set. Wait for the resource creation to complete successfully.
-
Go to the disk encryption set resource in the Azure portal.
-
Select the pink banner to grant permissions to Azure Key Vault.
[!IMPORTANT]
You must perform this step to successfully create the confidential VM.
-
On the SQL Server settings tab, configure the following options:
-
Under Security & Networking, select Public (Internet) for SQL Connectivity, and change the port to
1401to avoid using a well-known port number in the public scenario. -
Under SQL Authentication, select Enable. The SQL login credentials are set to the same user name and password that you configured for the VM. Use the default setting for Azure Key Vault integration. Storage configuration isn't available for the basic SQL Server VM image, but you can find more information about available options for other images at storage configuration.
-
Change any other settings if needed, and then select Review + create.
On the Review + create tab, review the summary, and select Create to create SQL Server, resource group, and resources specified for this VM.
You can monitor the deployment from the Azure portal. The Notifications button at the top of the screen shows basic status of the deployment. Deployment can take several minutes.
-
In the portal, find the Public IP address of your SQL Server VM in the Overview section of your virtual machine's properties.
-
On a different computer connected to the Internet, open SQL Server Management Studio (SSMS).
-
In the Connect to Server or Connect to Database Engine dialog box, edit the Server name value. Enter your VM's public IP address. Then add a comma and add the custom port (1401) that you specified when you configured the new VM. For example,
11.22.33.444,1401. -
In the Authentication box, select SQL Server Authentication.
-
In the Login box, type the name of a valid SQL login.
-
In the Password box, type the password of the login.
-
Select Connect.
Use the following steps to connect to the SQL Server virtual machine with Bastion:
[!INCLUDE Connect to SQL Server VM with remote desktop]
After you connect to the SQL Server virtual machine, you can launch SQL Server Management Studio and connect with Windows Authentication using your local administrator credentials. If you enabled SQL Server Authentication, you can also connect with SQL Authentication using the SQL login and password you configured during provisioning.
Access to the machine enables you to directly change machine and SQL Server settings based on your requirements. For example, you could configure the firewall settings or change SQL Server configuration settings.
If you don't need your SQL VM to run continually, you can avoid unnecessary charges by stopping it when not in use. You can also permanently delete all resources associated with the virtual machine by deleting its associated resource group in the portal. This permanently deletes the virtual machine as well, so use this command with care. For more information, see Manage Azure resources through portal.
[!div class="nextstepaction"] Migration guide: SQL Server to SQL Server on Azure Virtual Machines






