Configuring SSMS for Read-Only Connections
When connecting to SQL Server via Kron PAM, SSMS users must include the ApplicationIntent=ReadOnly parameter to enforce the read-only mode.
- Open SQL Server Management Studio (SSMS).
- Open the Connect to Server Dialog.
- Enter the Kron PAM Server Host and Cloned Port in the Server name field.
- Select your preferred authentication mode (e.g., Windows Authentication or SQL Server Authentication) from the Authentication dropdown menu.
- Provide the Username configured in Kron PAM (must match exactly, including domain or any prefix if applicable).

Authentication mode and credentials
When a user is a member of a forced read-only group, Kron PAM automatically enforces the read-only connection on the cloned port. You do not need to add any additional parameters. (e.g., ApplicationIntent=ReadOnly). For read-write access, connect to the original Kron PAM SQL Proxy port and ensure you belong to a group that is not forced to read-only.