Review Azure SQL server security alerts

Check that required security alerts are enabled and reach their owners.

Description

Azure SQL security alert policies notify you of suspicious database activity. Disabling a policy or excluding needed alert types can remove notifications for those threat indicators.

Potential impact

Missing alerts can delay investigation and response to suspicious access or queries.

Remediation

Enable the security alert policy and leave disabled_alerts empty except for reviewed exceptions. Configure appropriate recipients and verify the Defender for SQL configuration.

Examples

The examples remove exclusions for SQL injection and data-exfiltration alerts. They use the current AzureRM administrator-email setting; passwords are illustrative.

Before

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "my-mssql-server"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "sqladmin"
  administrator_login_password = "SuperSecurePassword123!"
}

resource "azurerm_mssql_server_security_alert_policy" "example" {
  resource_group_name        = azurerm_resource_group.example.name
  server_name                = azurerm_mssql_server.example.name
  state                      = "Enabled"
  storage_endpoint           = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key = azurerm_storage_account.example.primary_access_key
  disabled_alerts = [
    "Sql_Injection",
    "Data_Exfiltration"
  ]
  retention_days = 20
}

After

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "my-mssql-server"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "sqladmin"
  administrator_login_password = "SuperSecurePassword123!"
}

resource "azurerm_mssql_server_security_alert_policy" "example" {
  resource_group_name        = azurerm_resource_group.example.name
  server_name                = azurerm_mssql_server.example.name
  state                      = "Enabled"
  storage_endpoint           = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key = azurerm_storage_account.example.primary_access_key
  retention_days             = 20
  email_account_admins_enabled = true
}

References