- Choose the SQL Server driver for SQL Server 2012 and later; DBeaver keeps an older jTDS-based driver for earlier versions.
- Enter Host, Port (default 1433), Database/Schema and an authentication method, then select Test Connection and Finish.
- Recent Microsoft JDBC drivers encrypt by default and validate the server certificate; a self-signed certificate fails unless you trust it, import it, or tick Trust Server Certificate for development servers.
- Remote connections need TCP/IP enabled in SQL Server Configuration Manager, and named instances on dynamic ports rely on the SQL Server Browser service (UDP 1434).
Create the DBeaver SQL Server connection
DBeaver's SQL Server documentation says it supports all versions of SQL Server, provided you pick the right driver: SQL Server for SQL Server 2012 and newer, and SQL Server (Old driver, jTDS) for older versions. Azure SQL, Babelfish via TDS and Google Cloud SQL for SQL Server have their own entries in the driver list.
- Select the New Connection Wizard button or press Ctrl+Shift+N.
- Select SQL Server and select Next.
- With Connect by set to Host, enter the Host, the Port (1433 by default) and the database in Database/Schema.
- Choose an Authentication method. DBeaver's list includes SQL Server Authentication, Windows Authentication, Kerberos, NTLM and several Microsoft Entra ID (Active Directory) methods. For SQL Server Authentication, enter the login and password.
- Decide on Trust Server Certificate (see the next section) and, if you want, tick Show All Schemas; otherwise only non-empty schemas are shown.
- Select Test Connection, then Finish.
| Field | What to enter |
|---|---|
| Host | Server name or IP address; localhost for a local or tunnelled server |
| Port | 1433 by default; the instance's fixed port for a named instance |
| Database/Schema | The database to open, for example master or mydb |
| Authentication | SQL Server Authentication, Windows Authentication, Kerberos, NTLM or a Microsoft Entra ID method |
| Trust Server Certificate | Trust the server TLS certificate without validating it (development only) |
| Show All Schemas | Show empty schemas as well as non-empty ones |
Encryption and the Trust Server Certificate option
According to Microsoft's documentation for the JDBC driver, the encrypt property defaults to true from driver version 10.2, where earlier versions defaulted to false. With encryption on and trustServerCertificate false, the driver validates the server's TLS certificate. A server that uses a self-signed certificate, which is common on development machines, therefore fails validation.
DBeaver exposes this as Trust Server Certificate. Its documentation explains that when it is true the certificate is trusted automatically, and when it is false the Microsoft driver validates the certificate and terminates the connection if validation fails. For production servers, keep validation on and add the server's CA certificate to DBeaver's truststore instead. Microsoft also notes that a mismatch between the server name you connect to and the name in the certificate produces an error, so connect using the name the certificate was issued for.
Named instances, TCP/IP and SSH tunnels
Enable TCP/IP. Not every network protocol is enabled by SQL Server Setup. Microsoft documents the steps: in SQL Server Configuration Manager, expand SQL Server Network Configuration, select Protocols for <instance name>, right-click the protocol and select Enable, then restart the SQL Server service. For a named instance, including SQL Server Express, restart the SQL Server Browser service too.
Named instances. A named instance often uses a dynamic port. The SQL Server Browser service listens on UDP port 1434 and tells clients which TCP port the instance is using. In the Microsoft JDBC URL format, a port number takes precedence over an instance name, and Microsoft recommends setting the port for named instances to avoid an extra round trip. The simplest reliable setup in DBeaver is to give the instance a fixed port and enter that port on the Main tab.
SSH tunnel. For a SQL Server reachable only from a bastion host, select the plus button in the connection dialog, choose SSH, fill in the SSH host, port 22, user and authentication method, and select Test tunnel configuration. DBeaver forwards a local port to the database port for host-based connections; URL-based connections need the ports set manually.
Common DBeaver SQL Server connection errors
The SQL Server messages behind most failed connections have their own pages in our error library:
- Error 18456, login failed for user: wrong login or password, a disabled login, or SQL Server Authentication not enabled on the server.
- Error 4060, cannot open database requested by the login: the database in Database/Schema does not exist or the login has no access to it.
- Error 53, network-related or instance-specific error: wrong host or instance name, TCP/IP disabled, or a firewall in the way.
- Error 10061, target machine actively refused it: nothing is listening on that host and port.
- The driver could not establish a secure connection: a certificate problem; see the encryption section above.
For client-side details, open Window, Show View, Error Log in DBeaver.
Frequently asked questions
What port does DBeaver use for SQL Server?
The port on the Main tab, 1433 by default. Named instances often use a different, sometimes dynamic, port; give the instance a fixed port and enter it in DBeaver.
Can DBeaver use Windows Authentication with SQL Server?
Windows Authentication is one of the methods in DBeaver's SQL Server authentication list, alongside Kerberos and NTLM. Microsoft's JDBC documentation describes integrated security as using the Windows credentials of the signed-in user on Windows operating systems; on macOS or Linux, Kerberos is the usual route to domain logins.
Is it safe to tick Trust Server Certificate?
It disables certificate validation, so the connection is encrypted but the server's identity is not checked. That is acceptable for a local development server, not for production; import the server's CA certificate instead.
Does DBeaver support Azure SQL Database?
Yes. DBeaver lists Azure SQL Server as a separate driver entry, and documents Microsoft Entra ID authentication for SQL Server connections.
Should I use DBeaver or SSMS for SQL Server?
SSMS is Microsoft's own tool with deeper SQL Server administration features; DBeaver suits people who also work with other engines. See our DBeaver vs SSMS comparison.
Sources
- DBeaver docs: Microsoft SQL Server
- DBeaver docs: Create connection
- DBeaver docs: SSH configuration
- Microsoft Learn: Setting the connection properties (JDBC)
- Microsoft Learn: Connecting with encryption (JDBC)
- Microsoft Learn: Building the connection URL (JDBC)
- Microsoft Learn: Enable or disable a server network protocol
- Microsoft Learn: SQL Server Browser service
Checked 8 October 2026.
How we research tool guides: our editorial method. CodeWithSQL earns nothing from the vendors mentioned.