Review Azure SQL security alert email recipients

Verify that Azure SQL alert delivery includes the people responsible for responding.

Description

An Azure SQL security alert policy uses emailAddresses to list email recipients. Even with an enabled policy, alerts may be noticed late if the delivery path omits required responders.

An empty list does not mean all notifications stop. Review emailAccountAdmins and other notification paths together, and verify that operational responders actually receive alerts.

Potential impact

  • Alerts may miss required responders, increasing response time.
  • Outdated addresses or unavailable recipients can leave gaps in operations.

Remediation

  • Put actual operational and security addresses in emailAddresses when direct notification is needed.
  • Decide whether to combine these with account-administrator notifications, keep addresses current, and verify delivery and response procedures.

Examples

These excerpts show the Default alert policy for existing server sample and database server. Replace resource names and email with actual values. Both retain emailAccountAdmins: true.

Before

bicep
resource sqlServer1_sqlDatabase1_securityPolicy1 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/server/Default'
  properties: {
    emailAccountAdmins: true
    retentionDays: 4
    state: 'Enabled'
  }
}

No explicit email list is supplied, but account-administrator notifications are enabled. Check whether they include the required responders.

After

bicep
resource sqlServer1_sqlDatabase1_securityPolicy1 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/server/Default'
  properties: {
    emailAccountAdmins: true
    emailAddresses: ['sample@email.com']
    retentionDays: 4
    state: 'Enabled'
  }
}

An explicit email recipient is added. Replace the example with an operational address and verify receipt.

References