Description
When Azure MariaDB public network access is enabled, clients allowed by the firewall can connect through the public path. Data access still requires authentication and database permissions, but overly broad firewall rules or weak account security increase risk.
Azure Database for MariaDB retired on September 19, 2025. This guidance is for reviewing legacy configuration; migrate to a supported database service and apply the required network controls there.
Potential impact
- Allowed external clients may attempt password guessing or vulnerability exploitation.
- Compromised accounts or excessive privileges can lead to data access or modification.
Remediation
- Prioritize migration to a supported service and review its firewall, TLS and account permissions.
- If public access is unnecessary, configure the destination service’s supported private connectivity and DNS, test application connections, then disable public access.
- In the legacy MariaDB configuration,
public_network_access_enabled = falsedisabled public access. Allowing a limited public administrator IP is different from providing private connectivity.
Examples
These legacy excerpts compare network options for the retired service. They are not new deployment examples; required settings such as SKU, version and TLS are omitted. Supply the password securely rather than storing it in code, and protect Terraform state.
Before
resource "azurerm_mariadb_server" "app_db" {
name = "example-mariadb-server"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
administrator_login = "mariadbadmin"
administrator_login_password = var.administrator_password
public_network_access_enabled = true
}
Public network access is allowed. Firewall and authentication requirements still govern actual connections.
After
resource "azurerm_mariadb_server" "app_db" {
name = "example-mariadb-server"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
administrator_login = "mariadbadmin"
administrator_login_password = var.administrator_password
public_network_access_enabled = false
}
This option disables public access. It does not create a private endpoint or DNS configuration.