Description
Azure SQL threat detection provides security alerts for anomalous activity such as suspicious logins or SQL injection. Storing audit logs alone does not enable threat detection.
Potential impact
Without threat detection, automated security alerts are unavailable and response to suspicious activity may be delayed.
Remediation
Enable the database’s threat detection policy and verify Defender for SQL settings and notification delivery. Also retain audit records needed for investigations.
Examples
These current AzureRM examples keep auditing in place while enabling threat detection. The six-day retention is illustrative; adjust it to actual requirements.
Before
hcl
resource "azurerm_mssql_database" "example" {
name = "myexamplesqldatabase"
server_id = azurerm_mssql_server.example.id
threat_detection_policy {
state = "Disabled"
}
}
resource "azurerm_mssql_database_extended_auditing_policy" "example" {
database_id = azurerm_mssql_database.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 6
}
After
hcl
resource "azurerm_mssql_database" "example" {
name = "myexamplesqldatabase"
server_id = azurerm_mssql_server.example.id
threat_detection_policy {
state = "Enabled"
}
}
resource "azurerm_mssql_database_extended_auditing_policy" "example" {
database_id = azurerm_mssql_database.example.id
blob_storage_endpoint = azurerm_storage_account.example.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.example.primary_access_key
storage_account_access_key_is_secondary = false
retention_in_days = 6
}