Azure MSSQL Server public network access needs review

Identify required database connection paths and restrict unnecessary public access.

Description

Enabling public network access on an Azure MSSQL Server provides a database connection path through its public endpoint. Broad firewall allowances can then permit unnecessary external connection attempts.

An enabled public endpoint does not let everyone read the database. Firewall rules, authentication and database permissions still apply.

Potential impact

  • External clients that do not need access may attempt connections or logins.
  • Network restrictions may provide less protection if leaked credentials or incorrect permissions are exploited.

Remediation

For private-only connectivity, configure and test private endpoints, DNS and client routes before setting public_network_access_enabled to false. If public connections are required, restrict firewall allowances to the clients that actually need access. Apply strong authentication and least-privilege data permissions, and verify application connectivity after the change.

Examples

These excerpts change network settings on the same SQL server. Private endpoints and DNS are omitted. Do not use the published sample password in production; manage it through protected input.

Before

hcl
resource "azurerm_mssql_server" "app_db" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"
}

Public network access is not explicitly disabled. Check the server’s firewall rules for the actual allowed sources.

After

hcl
resource "azurerm_mssql_server" "app_db" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "mradministrator"
  administrator_login_password = "thisIsDog11"
  public_network_access_enabled = false
}

This disables public network access. Applications must be able to connect through the prepared private path.

References