Description
When database threat detection is disabled, missing alerts for unusual access or suspicious queries can delay response. Current PostgreSQL Flexible Server supports Microsoft Defender for open-source relational databases. This protection does not detect every attack or automatically block it.
Potential impact
- Suspicious database activity may be discovered late.
- Missing notification delivery or response procedures can delay action even when an alert exists.
Remediation
Enable the OpenSourceRelationalDatabases Defender plan in the required subscription, then verify server protection and security alert delivery. Review subscription-wide scope and cost, and avoid managing an existing plan through conflicting configurations. Maintain least privilege, network restrictions and required log collection.
Examples
The before example is historical, using retired Single Server and an old engine; do not reuse its password. The after example configures the current Defender plan at subscription scope. It does not create or migrate servers or configure alert recipients.
Before
resource "azurerm_postgresql_server" "example" {
name = "example-psqlserver"
location = azurerm_resource_group.example.location
resource_group_name = azurerm_resource_group.example.name
administrator_login = "psqladminun"
administrator_login_password = "H@Sh1CoR3!"
sku_name = "GP_Gen5_4"
version = "9.6"
storage_mb = 640000
backup_retention_days = 7
geo_redundant_backup_enabled = true
auto_grow_enabled = true
public_network_access_enabled = false
ssl_enforcement_enabled = true
ssl_minimal_tls_version_enforced = "TLS1_2"
threat_detection_policy {
enabled = false
}
}
After
resource "azurerm_security_center_subscription_pricing" "example" {
tier = "Standard"
resource_type = "OpenSourceRelationalDatabases"
}
The after example applies the paid Defender plan to supported open-source relational databases in the subscription. It is not a single-server option change, so check its scope and existing configuration ownership.