Description
Adding an alert type to disabledAlerts in an Azure SQL Database security alert policy disables notifications for that type.
Potential impact
Missing alerts about suspicious activity such as SQL injection can delay investigation and response.
Remediation
Enable the security alert policy and remove unnecessary disabledAlerts entries. Retain only justified exceptions and verify recipients and response procedures.
Examples
The examples remove the Sql_Injection exclusion. Use the intended notification recipients for your environment. Enabling alerts does not itself prevent SQL injection.
Before
bicep
resource sample_databases_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
name: 'sample/databases/default'
properties: {
disabledAlerts: ['Sql_Injection']
emailAccountAdmins: true
emailAddresses: ['sample@email.com']
retentionDays: 4
state: 'Enabled'
}
}
After
bicep
resource sample_databases_default 'Microsoft.Sql/servers/databases/securityAlertPolicies@2021-02-01-preview' = {
name: 'sample/databases/default'
properties: {
disabledAlerts: []
emailAccountAdmins: true
emailAddresses: ['sample@email.com']
retentionDays: 4
state: 'Enabled'
}
}