Reference Guide
...
Read-Only Mode on SQL Server
Configuring SSMS for Read-Only Connections
when connecting to sql server via kron pam, ssms users must include the applicationintent=readonly parameter to enforce the read only mode open sql server management studio (ssms) open the connect to server dialog enter the kron pam server host and cloned port in the server name field select your preferred authentication mode (e g , windows authentication or sql server authentication) from the authentication dropdown menu provide the username configured in kron pam (must match exactly, including domain or any prefix if applicable) when a user is a member of a forced read only group , kron pam automatically enforces the read only connection on the cloned port you do not need to add any additional parameters (e g , applicationintent=readonly) for read write access, connect to the original kron pam sql proxy port and ensure you belong to a group that is not forced to read only