Description
Enabling public network access on an Azure MSSQL Server provides a database connection path through its public endpoint. Broad firewall allowances can then permit unnecessary external connection attempts.
An enabled public endpoint does not let everyone read the database. Firewall rules, authentication and database permissions still apply.
Potential impact
- External clients that do not need access may attempt connections or logins.
- Network restrictions may provide less protection if leaked credentials or incorrect permissions are exploited.
Remediation
For private-only connectivity, configure and test private endpoints, DNS and client routes before setting public_network_access_enabled to false. If public connections are required, restrict firewall allowances to the clients that actually need access. Apply strong authentication and least-privilege data permissions, and verify application connectivity after the change.
Examples
These excerpts change network settings on the same SQL server. Private endpoints and DNS are omitted. Do not use the published sample password in production; manage it through protected input.
Before
resource "azurerm_mssql_server" "app_db" {
name = "mssqlserver"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "mradministrator"
administrator_login_password = "thisIsDog11"
}
Public network access is not explicitly disabled. Check the server’s firewall rules for the actual allowed sources.
After
resource "azurerm_mssql_server" "app_db" {
name = "mssqlserver"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "mradministrator"
administrator_login_password = "thisIsDog11"
public_network_access_enabled = false
}
This disables public network access. Applications must be able to connect through the prepared private path.