SQL Server authentication

SQL Server Password Generator

Create a random password for a SQL Server login with policy-compatible character groups and a ready-to-copy ODBC representation.

Generate a SQL Server login password

The default uses uppercase, lowercase, digits, and symbols, exceeding the documented three-of-four complexity rule when password policy is enforced.

SQL Server supports 8–128 characters. Longer is preferable.
Both include all four complexity categories and omit apostrophes.
SQL Server policy rejects a password containing the login name. This value stays in your browser.
Use after PWD=. Embedded closing braces are doubled according to ODBC grammar.

24 charactersPolicy-compatible mixRandom bits
Generated locallyThe login name and password remain in this browser tab. Move the password directly into protected configuration.

What are SQL Server password requirements?

For SQL Server authentication with password policy enabled, the documented baseline is at least eight characters, no more than 128, no login name, and characters from at least three of four categories: uppercase, lowercase, digits, and nonalphanumeric characters. This generator always includes all four categories.

Why policy varies by server

On Windows, SQL Server can call the operating system's password-policy mechanism, so domain or local security settings can be stricter than the baseline. SQL Server 2022 and later Linux releases also support configurable policy settings in current cumulative updates. Only the destination server can confirm acceptance.

Policy-compatible versus connection-simple

Policy-compatible mode uses a broad punctuation alphabet. Connection-simple mode uses a smaller punctuation set that avoids common connection-string delimiters while retaining a nonalphanumeric category. Both omit the single quote because Microsoft documents that it cannot appear in a CREATE LOGIN password literal.

Using the optional login-name check

Enter the intended SQL login name and the generator will reject any candidate containing that text, case-insensitively. The field is optional because some teams create the secret before naming the login. This local check cannot know the server's computer name, password history, or domain dictionary.

ODBC escaping

ODBC connection strings use semicolons and equals signs as structure. Braces preserve a password value containing those characters, and an embedded closing brace is represented by two closing braces. The ODBC output is the same password in that escaped syntax; it is not a second credential.

Assign the password safely

Avoid the sqlcmd -P command-line option because the password can be exposed through shell handling or process inspection. Let sqlcmd prompt for the value, or use a secret manager and your driver's connection-string builder. Do not commit credentials or connection strings to source control.

SQL authentication is not always required

Microsoft recommends Windows authentication when available, and Microsoft Entra authentication may be preferable for supported Azure and connected environments. Generate a SQL password only when the application or deployment actually uses SQL Server authentication.

Official Microsoft sources

Requirements follow Microsoft Learn's SQL Server password policy and CREATE LOGIN reference. Connection formatting follows the ODBC connection-string grammar. Command-line handling follows the official sqlcmd guidance.

Related database tools

MySQL password generator targets MySQL account policy. PostgreSQL password generator provides role-password and URI guidance. Oracle password generator supports ORA12C verification profiles. Redis password generator reproduces ACL GENPASS output format. Use this page for SQL Server authentication logins.