Azure SQL security alert types are disabled

Check that required Azure SQL security alerts are not excluded.

Description

Adding an alert type to disabledAlerts in an Azure SQL Database security alert policy disables notifications for that type.

Potential impact

Missing alerts about suspicious activity such as SQL injection can delay investigation and response.

Remediation

Enable the security alert policy and remove unnecessary disabledAlerts entries. Retain only justified exceptions and verify recipients and response procedures.

Examples

The examples remove the Sql_Injection exclusion. Use the intended notification recipients for your environment. Enabling alerts does not itself prevent SQL injection.

Before

bicep
resource sample_databases_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/databases/default'
  properties: {
    disabledAlerts: ['Sql_Injection']
    emailAccountAdmins: true
    emailAddresses: ['sample@email.com']
    retentionDays: 4
    state: 'Enabled'
  }
}

After

bicep
resource sample_databases_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
  name: 'sample/databases/default'
  properties: {
    disabledAlerts: []
    emailAccountAdmins: true
    emailAddresses: ['sample@email.com']
    retentionDays: 4
    state: 'Enabled'
  }
}

References