Review Azure PostgreSQL threat detection

Verify Defender protection for suspicious PostgreSQL activity and actual alert delivery.

Description

When database threat detection is disabled, missing alerts for unusual access or suspicious queries can delay response. Current PostgreSQL Flexible Server supports Microsoft Defender for open-source relational databases. This protection does not detect every attack or automatically block it.

Potential impact

  • Suspicious database activity may be discovered late.
  • Missing notification delivery or response procedures can delay action even when an alert exists.

Remediation

Enable the OpenSourceRelationalDatabases Defender plan in the required subscription, then verify server protection and security alert delivery. Review subscription-wide scope and cost, and avoid managing an existing plan through conflicting configurations. Maintain least privilege, network restrictions and required log collection.

Examples

The before example is historical, using retired Single Server and an old engine; do not reuse its password. The after example configures the current Defender plan at subscription scope. It does not create or migrate servers or configure alert recipients.

Before

hcl
resource "azurerm_postgresql_server" "example" {
  name                = "example-psqlserver"
  location            = azurerm_resource_group.example.location
  resource_group_name = azurerm_resource_group.example.name

  administrator_login          = "psqladminun"
  administrator_login_password = "H@Sh1CoR3!"

  sku_name   = "GP_Gen5_4"
  version    = "9.6"
  storage_mb = 640000

  backup_retention_days        = 7
  geo_redundant_backup_enabled = true
  auto_grow_enabled            = true

  public_network_access_enabled    = false
  ssl_enforcement_enabled          = true
  ssl_minimal_tls_version_enforced = "TLS1_2"

  threat_detection_policy {
    enabled = false
  }
}

After

hcl
resource "azurerm_security_center_subscription_pricing" "example" {
  tier          = "Standard"
  resource_type = "OpenSourceRelationalDatabases"
}

The after example applies the paid Defender plan to supported open-source relational databases in the subscription. It is not a single-server option change, so check its scope and existing configuration ownership.

References