Description
Deleting audit logs before they are needed makes past database activity harder to reconstruct. Set retention to service and organizational needs; retention_in_days = 0 means unlimited retention in the Blob Storage audit policy.
Potential impact
Insufficient retention can remove evidence of older access or changes.
Remediation
Set retention_in_days on the server or database audit policy to the required period. Check that expiry rules at the actual log destination follow the same retention goal.
Examples
The examples define the audit policy as a separate resource and change retention from 20 to 95 days. Neither that duration nor the illustrative password should be adopted as a production standard without review.
Before
hcl
resource "azurerm_mssql_server" "example" {
name = "mssqlserver"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "mradministrator"
administrator_login_password = "thisIsDog11"
}
resource "azurerm_mssql_server_extended_auditing_policy" "example" {
server_id = azurerm_mssql_server.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 20
}
After
hcl
resource "azurerm_mssql_server" "example" {
name = "mssqlserver"
resource_group_name = azurerm_resource_group.example.name
location = azurerm_resource_group.example.location
version = "12.0"
administrator_login = "mradministrator"
administrator_login_password = "thisIsDog11"
}
resource "azurerm_mssql_server_extended_auditing_policy" "example" {
server_id = azurerm_mssql_server.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 95
}