Review TLS enforcement for Azure MySQL

Require TLS connections to Azure MySQL and retain client verification of the server certificate.

Description

Without TLS enforcement, MySQL queries and responses can travel unencrypted. The historical Azure Single Server property sslEnforcement differs from require_secure_transport on current Flexible Server.

Potential impact

An actor able to intercept traffic can read or alter database requests and responses. An internal network does not replace transport protection.

Remediation

Keep require_secure_transport set to ON on Flexible Server. Configure applications to use TLS and verify the server certificate, then confirm that required connections still work.

Examples

The initial excerpt is historical Single Server configuration for a retired service; sourceServerId represents its restore-source resource ID. In the revised excerpt, server refers to a separately prepared Flexible Server. Server declarations and data migration are separate; this code does not perform migration.

Before

bicep
resource server 'Microsoft.DBforMySQL/servers@2017-12-01' = {
  name: 'server'
  properties: {
    version: '5.6'
    createMode: 'GeoRestore'
    sourceServerId: sourceServerId
  }
}

Omitting sslEnforcement alone does not establish that the actual server permitted plaintext connections.

After

bicep
resource server_tls 'Microsoft.DBforMySQL/flexibleServers/configurations@2024-12-30' = {
  parent: server
  name: 'require_secure_transport'
  properties: {
    source: 'user-override'
    value: 'ON'
  }
}

The Flexible Server secure-transport parameter is explicit. Retain server-certificate verification in client connection settings separately.

References