Review Azure SQL Database threat detection

Enable the threat detection needed in addition to audit logging.

Description

Azure SQL threat detection provides security alerts for anomalous activity such as suspicious logins or SQL injection. Storing audit logs alone does not enable threat detection.

Potential impact

Without threat detection, automated security alerts are unavailable and response to suspicious activity may be delayed.

Remediation

Enable the database’s threat detection policy and verify Defender for SQL settings and notification delivery. Also retain audit records needed for investigations.

Examples

These current AzureRM examples keep auditing in place while enabling threat detection. The six-day retention is illustrative; adjust it to actual requirements.

Before

hcl
resource "azurerm_mssql_database" "example" {
  name                = "myexamplesqldatabase"
  server_id           = azurerm_mssql_server.example.id

  threat_detection_policy {
    state = "Disabled"
  }

}

resource "azurerm_mssql_database_extended_auditing_policy" "example" {
  database_id = azurerm_mssql_database.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 6
}

After

hcl
resource "azurerm_mssql_database" "example" {
  name                = "myexamplesqldatabase"
  server_id           = azurerm_mssql_server.example.id

  threat_detection_policy {
    state = "Enabled"
  }

}

resource "azurerm_mssql_database_extended_auditing_policy" "example" {
  database_id = azurerm_mssql_database.example.id
  blob_storage_endpoint                        = azurerm_storage_account.example.primary_blob_endpoint
  storage_account_access_key              = azurerm_storage_account.example.primary_access_key
  storage_account_access_key_is_secondary = false
  retention_in_days                       = 6
}

References