Review the minimum TLS version for Azure SQL

Ensure database clients use TLS 1.2 or later.

Description

Azure SQL Database has retired TLS 1.0 and 1.1 and requires at least TLS 1.2. Check that older configuration files and clients meet this requirement.

Potential impact

Clients that depend on older TLS versions cannot connect, and outdated minimum-version values cannot be applied to current configurations.

Remediation

Use minimum_tls_version = "1.2" and confirm that clients and drivers support TLS 1.2 or later. Test actual database connections before making changes.

Examples

The first example shows a historical TLS 1.1 setting that is no longer supported. Use the TLS 1.2 configuration in the second example for current deployments.

Before

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "example-mssql-server"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = var.sql_admin
  administrator_login_password = var.sql_password
  minimum_tls_version          = "1.1"
}

After

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "example-mssql-server"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = var.sql_admin
  administrator_login_password = var.sql_password
  minimum_tls_version          = "1.2"
}

References