Chapter 24 · Upgrades, Compatibility Levels, Migration, Cloud/Hybrid Paths, and Change Management

Cross-Platform Windows/Linux Considerations, Collations, Agents, External Dependencies, and Tooling

Assess Windows/Linux migration through feature parity, paths, authentication, Agent, providers, CLR, certificates, and external operational dependencies.

Advanced180–260 minutesCross-platform dependency inventory labSQL Server 2025 CU7 · 17.0.4065.4Target compatibility 170 · staged labSSMS 22.8.2 · Last reviewed August 2026

Learning outcomes

A Windows-to-Linux SQL Server move can restore the same user database and still fail operationally because the database is only one layer of the system. Paths, service control, authentication, Agent subsystems, linked-server providers, CLR permissions, FILESTREAM, external scripts, certificates and third-party tooling are platform dependencies. ServiceHub therefore treats cross-platform migration as a feature-parity and operations migration, not “copy the .bak and we are done.”

01

Inventory platform, collation, file paths and instance-scoped dependencies before a Windows/Linux move.

02

Identify current SQL Server 2025 on Linux feature gaps that can block a seemingly simple restore migration.

03

Distinguish database collation from OS filesystem case sensitivity and application identifier/path assumptions.

04

Assess Agent jobs, CLR, linked servers, certificates, authentication and third-party tools as external migration work.

05

Build a target-readiness manifest with explicit supported/replaced/retired decisions for every dependency.

Lab baseline. SQL Server 2025 (17.x), CU7 build 17.0.4065.4; compatibility level 170 is the target, but several labs deliberately stage at level 160 to demonstrate compatibility-controlled change. SSMS 22.8.2 is the checked Windows administration tool; current VS Code + MSSQL extension and current sqlcmd are valid free alternatives. Azure Data Studio is retired. Mandatory work uses a free non-production SQL Server 2025 Developer edition or Express where the feature exists and a disposable database named ServiceHubUpgradeLab. SQL Server 2025 uses the same core Database Engine across Windows and Linux, but Microsoft documents platform-specific unsupported services/features. Production Linux should use a currently supported distribution/filesystem combination from the SQL Server 2025 Linux release notes.

1. Start with evidence about the current host

sql · capture platform, collation, paths and file placement
SELECT    h.host_platform,    h.host_distribution,    h.host_release,    SERVERPROPERTY('ProductVersion') AS product_version,    SERVERPROPERTY('Collation') AS server_collation,    SERVERPROPERTY('InstanceDefaultDataPath') AS default_data_path,    SERVERPROPERTY('InstanceDefaultLogPath') AS default_log_path,    SERVERPROPERTY('InstanceDefaultBackupPath') AS default_backup_pathFROM sys.dm_os_host_info AS h;USE ServiceHubUpgradeLab;SELECT name, physical_name, type_descFROM sys.database_files;SELECT DATABASEPROPERTYEX(DB_NAME(),'Collation') AS database_collation;

Windows paths such as D:\SQLData\ServiceHub.mdf are not Linux paths. Restore with MOVE and target-approved locations. A database collation can move across platforms, but filesystem semantics and external scripts can still be case-sensitive. Do not infer application correctness from a successful restore.

2. Inventory dependencies that are platform-sensitive

sql · build a cross-platform dependency report
SELECT name, enabled FROM msdb.dbo.sysjobs ORDER BY name;SELECT j.name AS job_name, s.step_id, s.subsystem, s.commandFROM msdb.dbo.sysjobsteps AS sJOIN msdb.dbo.sysjobs AS j ON j.job_id=s.job_idORDER BY j.name,s.step_id;SELECT name, permission_set_desc, is_user_definedFROM sys.assembliesWHERE is_user_defined=1;SELECT name, product, provider, data_sourceFROM sys.serversWHERE server_id<>0;USE ServiceHubUpgradeLab;SELECT name, type_desc FROM sys.database_scoped_credentials;SELECT name, type_desc, data_source FROM sys.external_data_sources;SELECT name, thumbprint, expiry_date FROM sys.certificates WHERE name NOT LIKE '##%';

On SQL Server 2025 Linux, current Microsoft documentation lists several gaps that matter to migration: merge replication is unavailable; linked servers to non-SQL Server third-party sources are unavailable (PolyBase can be an alternative in suitable cases); FILESTREAM/FileTable are unavailable; CLR assemblies requiring EXTERNAL_ACCESS or UNSAFE are unavailable; SQL Server Agent does not support the Windows-style CmdExec/PowerShell/Queue Reader/SSIS/SSAS/SSRS subsystems and Agent alerts are unavailable. SQL Server Browser is also unnecessary because Linux supports a single default instance per host and the port is explicitly configured.

3. Authentication, certificates and external services do not migrate themselves

Windows authentication can be integrated with Active Directory on Linux, but the setup and service identity are different from merely copying Windows logins. Availability Group endpoints on Linux use certificate-based authentication rather than Windows integrated authentication. TDE/backup-encryption protectors, database master keys, linked-server credentials and application TLS trust all need explicit target handling.

sql · inventory security dependencies without exposing secrets
SELECT name, type_desc, is_disabled, sidFROM sys.server_principalsWHERE type IN ('S','U','G') AND name NOT LIKE '##%';SELECT name, credential_identityFROM sys.credentials;USE ServiceHubUpgradeLab;SELECT name, thumbprint, pvt_key_encryption_type_descFROM sys.certificatesWHERE name NOT LIKE '##%';SELECT name, is_master_key_encrypted_by_serverFROM sys.databasesWHERE name=N'ServiceHubUpgradeLab';
Do not export secrets into inventory files. Record identity names, certificate thumbprints, expiry and required transfer/re-creation procedure. Private keys/passwords belong in the approved secrets process, not the migration spreadsheet.

4. Deliberately wrong: “same engine, therefore feature parity”

The core Database Engine is shared, but platform support is not identical. A Windows job step that shells out to PowerShell, an UNSAFE CLR assembly, FILESTREAM document storage or a third-party OLE DB linked server can be business-critical even though the relational tables restore perfectly. The repair is to classify every dependency: supported unchanged, supported with reconfiguration, replace, or block migration.

sql · store a simple readiness classification in the lab
USE ServiceHubUpgradeLab;GOIF OBJECT_ID(N'lab24.PlatformReadiness',N'U') IS NULLCREATE TABLE lab24.PlatformReadiness(    dependency_name nvarchar(200) NOT NULL PRIMARY KEY,    dependency_type varchar(40) NOT NULL,    target_status varchar(24) NOT NULL,    remediation nvarchar(600) NULL,    evidence_uri nvarchar(500) NULL,    checked_at datetime2(0) NOT NULL DEFAULT SYSUTCDATETIME());UPDATE lab24.PlatformReadinessSET dependency_type=N'Agent subsystem',target_status=N'REPLACE',    remediation=N'Use an external scheduler/automation path or supported Linux job design.',checked_at=SYSUTCDATETIME()WHERE dependency_name=N'Agent PowerShell step';IF @@ROWCOUNT=0 INSERT lab24.PlatformReadiness(dependency_name,dependency_type,target_status,remediation)VALUES(N'Agent PowerShell step',N'Agent subsystem',N'REPLACE',N'Use an external scheduler/automation path or supported Linux job design.');UPDATE lab24.PlatformReadinessSET dependency_type=N'Certificate/key',target_status=N'RECONFIGURE',    remediation=N'Transfer certificate/private key securely before restore.',checked_at=SYSUTCDATETIME()WHERE dependency_name=N'TDE protector';IF @@ROWCOUNT=0 INSERT lab24.PlatformReadiness(dependency_name,dependency_type,target_status,remediation)VALUES(N'TDE protector',N'Certificate/key',N'RECONFIGURE',N'Transfer certificate/private key securely before restore.');UPDATE lab24.PlatformReadinessSET dependency_type=N'Database setting',target_status=N'VALIDATE',    remediation=N'Test comparisons plus application/filesystem assumptions on target.',checked_at=SYSUTCDATETIME()WHERE dependency_name=N'Database collation';IF @@ROWCOUNT=0 INSERT lab24.PlatformReadiness(dependency_name,dependency_type,target_status,remediation)VALUES(N'Database collation',N'Database setting',N'VALIDATE',N'Test comparisons plus application/filesystem assumptions on target.');

The readiness table is deliberately not an auto-remediation engine. It is evidence that each dependency has an owner and disposition.

5. Production judgment

Cross-platform migration is attractive when Linux operational standards, container/VM platforms or cost models justify it, but the database must be assessed together with the surrounding instance and application ecosystem. Use current SSMS migration assessment feature parity, current Linux supported-feature documentation, a restored target rehearsal and representative application tests. Keep unsupported dependencies visible rather than silently dropping them during migration.

Check your understanding

  1. Does a successful database restore prove Windows-to-Linux migration success?
  2. Is merge replication currently supported on SQL Server 2025 Linux?
  3. Why can identical database collation still leave cross-platform bugs?
  4. Can EXTERNAL_ACCESS/UNSAFE SQL CLR assemblies simply move unchanged to Linux?
  5. What should a readiness manifest contain?
Review the answers

1. No. Instance, platform, authentication, Agent, provider, filesystem and application dependencies can still fail.

2. No, Microsoft lists merge replication as unsupported on SQL Server 2025 Linux.

3. External filesystem paths, shell/scripts and application behaviors can have different case/path semantics independent of database collation.

4. No. Those permission sets are currently listed as unsupported on SQL Server 2025 Linux.

5. Each dependency, target support status, remediation/replacement, owner/evidence, and an explicit blocker decision if unresolved.

Authoritative references

Keep knowledge open

Help the academy stay free and grow.

If these tutorials save you time, a small donation supports new lessons, technical review, diagrams, examples, and long-term maintenance.

ETHEthereum / ERC-20 only
0x716c4Ab160C4B66F31a28AE2448BfF68fc3a2ef0

Send only Ethereum or ERC-20 compatible assets to this address.