Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Encrypt=true requests encrypted communication between a PHP application and SQL Server. It does not, by itself, establish that the server is who it claims to be: that is controlled separately by TrustServerCertificate. For production, use a certificate the client can validate and keep TrustServerCertificate=false.

What Encrypt does—and what it does not do

Microsoft’s PHP drivers define Encrypt=true (or 1) as encrypted communication and Encrypt=false (or 0) as unencrypted communication. Encryption protects data in transit between the application and database.

Certificate validation is a separate setting. With TrustServerCertificate=false, the driver validates the server certificate; with true, it accepts a self-signed certificate without that validation. Encryption with validation is the safer production configuration. Microsoft’s PHP connection-options reference documents the options and their defaults.

How Encrypt and TrustServerCertificate work together

Encrypt TrustServerCertificate Effect
true false (default) Requests encrypted communication and validates the server certificate.
true true Requests encrypted communication but bypasses certificate validation.
false false Requests unencrypted communication; certificate validation is not the safeguard for this connection.

Microsoft’s troubleshooting guidance warns that TrustServerCertificate=true disables server certificate validation and says not to carry that setting into production, staging, or shared environments. Use a trusted certificate rather than treating this option as a permanent certificate-error fix. See Microsoft’s connection troubleshooting guidance.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Set the options in SQLSRV or PDO_SQLSRV

The SQLSRV procedural API and PDO_SQLSRV use the same connection-option semantics, but express connection settings differently.

SQLSRV procedural API

Pass the options as an array to sqlsrv_connect:

$serverName = "db.example.com";
$connectionOptions = [
    "Database" => "appdb",
    "Encrypt" => true,
    "TrustServerCertificate" => false
];
$conn = sqlsrv_connect($serverName, $connectionOptions);

PDO_SQLSRV

Include the options in the PDO connection string:

$pdo = new PDO(
    "sqlsrv:Server=db.example.com;Database=appdb;Encrypt=true;TrustServerCertificate=false",
    $username,
    $password
);

These examples explicitly request encryption and certificate validation. Supply a server name that matches the certificate identity and ensure the certificate chain is trusted by the PHP host.

Does Microsoft Entra authentication change the default?

Yes. When an Authentication keyword is present, Microsoft documents that Encrypt defaults to true. The server certificate is still validated unless TrustServerCertificate=true. This applies to documented Microsoft Entra managed identity, service-principal, and password authentication flows. Because defaults can depend on the complete connection configuration, review the entire connection string rather than assuming a setting from one keyword alone. Microsoft lists the authentication and encryption option behavior.

Fix certificate errors without disabling validation

A TLS connection failure commonly points to a certificate chain the client does not trust or a mismatch between the hostname used to connect and the certificate’s name. Check both before changing driver options.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Confirm the host name in the connection string matches the certificate’s subject or subject alternative name.
  2. Install or configure the certificate chain so the machine running PHP trusts the issuing certificate authority.
  3. Keep TrustServerCertificate=false and retry the connection. If it still fails, use the driver’s error details to identify whether the remaining issue is the chain, name, or TLS setup.

Setting TrustServerCertificate=true may hide a validation error, but it removes the check that detects an unverified server identity. Do not use it to get a shared or production deployment working.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

Check PHP and driver compatibility before deployment

Driver support depends on the PHP version and driver release. At the time represented by Microsoft’s download page, Microsoft Drivers 5.13.3 for PHP for SQL Server was listed as the latest general-availability release. The drivers support SQL Server, Azure SQL Database, SQL database in Fabric, and Azure SQL Managed Instance; confirm your specific PHP and driver pairing in Microsoft’s support matrix before deploying.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.