Description
If neither server-level nor database-level auditing applies to an Azure SQL Database, the required database activity is not recorded in audit logs.
Potential impact
Evidence needed to investigate suspicious connections or data changes may be missing.
Remediation
Enable auditing at the appropriate scope and configure audited actions and a destination. Server auditing sent to Azure Monitor also requires SQLSecurityAuditEvents diagnostic settings on the master database.
Examples
The examples show only the addition of a server audit policy. Prepare server configuration and destination diagnostic settings separately and verify actual records. A duplicate audit policy is not required on every database.
Before
bicep
resource sqlServer 'Microsoft.Sql/servers@2023-02-01-preview' = {
name: 'example-sql-server'
location: resourceGroup().location
properties: {}
}
resource sqlDatabase 'Microsoft.Sql/servers/databases@2024-11-01-preview' = {
parent: sqlServer
name: 'application'
location: resourceGroup().location
properties: {}
}
After
bicep
resource sqlServer 'Microsoft.Sql/servers@2023-02-01-preview' = {
name: 'example-sql-server'
location: resourceGroup().location
properties: {}
}
resource sqlDatabase 'Microsoft.Sql/servers/databases@2024-11-01-preview' = {
parent: sqlServer
name: 'application'
location: resourceGroup().location
properties: {}
}
resource sqlServerAudit 'Microsoft.Sql/servers/auditingSettings@2024-11-01-preview' = {
parent: sqlServer
name: 'default'
properties: {
isAzureMonitorTargetEnabled: true
state: 'Enabled'
}
}