Review Azure SQL account-administrator alert emails

Verify that Azure SQL security alerts reach the people responsible for responding.

Description

The Azure SQL security alert policy setting emailAccountAdmins sends alert emails to account administrators. Turning it off does not necessarily stop all notifications: other paths, such as explicit emailAddresses, can remain configured.

Even when other recipients exist, omitting the responsible responders can delay awareness of a security event.

Potential impact

  • Alerts may miss required responders and delay initial action.
  • An absent recipient or failed delivery path can leave an alert unattended.

Remediation

  • Set emailAccountAdmins: true when account administrators should respond. Review the effective recipient list alongside the security team’s emailAddresses.
  • Verify current ownership, actual delivery and the response procedure. Email settings alone do not complete threat detection or incident response.

Examples

These policy excerpts target an existing SQL server and database. Replace resource names and the example email with actual values. Both keep the policy enabled and retain an explicit recipient.

Before

bicep
resource sample_server_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/server/default'
  properties: {
    emailAccountAdmins: false
    emailAddresses: ['sample@email.com']
    retentionDays: 4
    state: 'Enabled'
  }
}

Account-administrator notification is off, but an explicit email address remains. Check whether this path includes the required responders.

After

bicep
resource sample_server_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/server/default'
  properties: {
    emailAccountAdmins: true
    emailAddresses: ['sample@email.com']
    retentionDays: 4
    state: 'Enabled'
  }
}

Account administrators are also included as email recipients. Verify delivery and their ability to respond.

References