Description
Azure SQL audit records may already be deleted if their retention period is shorter than the organization’s investigation and audit requirements. In a Blob Storage auditing policy, retentionDays specifies storage retention days; 0 means indefinite retention. Ninety days is an example policy target, not a universal organizational requirement.
Potential impact
- Evidence for investigating an incident’s cause and scope may be unavailable.
- Older access and change history can become difficult to reconstruct.
Remediation
- Define the audit scope and required retention period, and reflect them in retentionDays and the actual storage deletion policy. Check retention separately for other destinations such as Azure Monitor.
- Verify auditing status, destination permissions and connectivity, and confirm that logs actually arrive and remain available. Increasing retention does not restore deleted records.
Examples
These excerpts compare retention days, omitting the existing sqlDatabase parent and destination settings. Enabled auditing requires additional settings such as storageEndpoint or an Azure Monitor destination; the excerpts alone do not complete log storage.
Before
resource sqlAudit 'Microsoft.Sql/servers/databases/auditingSettings@2021-02-01-preview' = {
name: 'default'
parent: sqlDatabase
properties: {
state: 'Enabled'
retentionDays: 30
}
}
Thirty days may be insufficient for an organization requiring a longer investigation history.
After
resource sqlAudit 'Microsoft.Sql/servers/databases/auditingSettings@2021-02-01-preview' = {
name: 'default'
parent: sqlDatabase
properties: {
state: 'Enabled'
retentionDays: 90
}
}
Retention increases to 90 days. Check that the actual retention objective and storage policies align with this period.