Description
Azure SQL security alert policies notify you of suspicious database activity. Disabling a policy or excluding needed alert types can remove notifications for those threat indicators.
Potential impact
Missing alerts can delay investigation and response to suspicious access or queries.
Remediation
Enable the security alert policy and leave disabled_alerts empty except for reviewed exceptions. Configure appropriate recipients and verify the Defender for SQL configuration.
Examples
The examples remove exclusions for SQL injection and data-exfiltration alerts. They use the current AzureRM administrator-email setting; passwords are illustrative.
Before
hcl
resource "azurerm_mssql_server" "example" {
name = "my-mssql-server"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "sqladmin"
administrator_login_password = "SuperSecurePassword123!"
}
resource "azurerm_mssql_server_security_alert_policy" "example" {
resource_group_name = azurerm_resource_group.example.name
server_name = azurerm_mssql_server.example.name
state = "Enabled"
storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
disabled_alerts = [
"Sql_Injection",
"Data_Exfiltration"
]
retention_days = 20
}
After
hcl
resource "azurerm_mssql_server" "example" {
name = "my-mssql-server"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "sqladmin"
administrator_login_password = "SuperSecurePassword123!"
}
resource "azurerm_mssql_server_security_alert_policy" "example" {
resource_group_name = azurerm_resource_group.example.name
server_name = azurerm_mssql_server.example.name
state = "Enabled"
storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
retention_days = 20
email_account_admins_enabled = true
}