Description
The Azure SQL security alert policy setting emailAccountAdmins sends alert emails to account administrators. Turning it off does not necessarily stop all notifications: other paths, such as explicit emailAddresses, can remain configured.
Even when other recipients exist, omitting the responsible responders can delay awareness of a security event.
Potential impact
- Alerts may miss required responders and delay initial action.
- An absent recipient or failed delivery path can leave an alert unattended.
Remediation
- Set
emailAccountAdmins: truewhen account administrators should respond. Review the effective recipient list alongside the security team’semailAddresses. - Verify current ownership, actual delivery and the response procedure. Email settings alone do not complete threat detection or incident response.
Examples
These policy excerpts target an existing SQL server and database. Replace resource names and the example email with actual values. Both keep the policy enabled and retain an explicit recipient.
Before
resource sample_server_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
name: 'sample/server/default'
properties: {
emailAccountAdmins: false
emailAddresses: ['sample@email.com']
retentionDays: 4
state: 'Enabled'
}
}
Account-administrator notification is off, but an explicit email address remains. Check whether this path includes the required responders.
After
resource sample_server_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
name: 'sample/server/default'
properties: {
emailAccountAdmins: true
emailAddresses: ['sample@email.com']
retentionDays: 4
state: 'Enabled'
}
}
Account administrators are also included as email recipients. Verify delivery and their ability to respond.