Review connection throttling for Azure PostgreSQL

Limit repeated connection attempts that use incorrect passwords in Azure PostgreSQL.

Description

Azure PostgreSQL connection throttling temporarily blocks new connections from an IP address after repeated attempts with incorrect passwords. Disabling it removes this protection against repeated attempts.

Potential impact

Password-guessing attempts can continue, and repeated authentication requests can add operational load. This feature does not limit every connection flood or large numbers of successfully authenticated connections.

Remediation

Set connection_throttle.enable to on on current Flexible Server. Review firewall and authentication policies, and correct invalid application credentials and excessive retries. Manage connection pools and general connection limits separately.

Examples

The initial excerpt is historical Single Server configuration for a retired service. In the revised excerpt, servers1 refers to a separately prepared Flexible Server. Parent server declarations and data migration are outside these excerpts.

Before

bicep
resource servers1_connection_throttling 'Microsoft.DBforPostgreSQL/servers/configurations@2017-12-01' = {
  parent: servers1
  name: 'connection_throttling'
  properties: {
    value: 'Off'
  }
}

The historical connection_throttling feature is disabled.

After

bicep
resource servers1_connection_throttling 'Microsoft.DBforPostgreSQL/flexibleServers/configurations@2024-08-01' = {
  parent: servers1
  name: 'connection_throttle.enable'
  properties: {
    source: 'user-override'
    value: 'on'
  }
}

The current Flexible Server parameter is enabled. Also verify required application connections and handling of authentication errors.

References