Although the SQL Server Driver for PHP allows you to execute any Transact-SQL string, Microsoft does not recommend concatenating user-input with query strings. Following this approach can lead to SQL injection, potentially allowing the user to change the query in ways that the developer may not have expected and possibly leading to security problems within the application.