Description
The administrator-email option sends Azure SQL security alerts to account administrators. Separate recipient addresses or other operational channels can still deliver alerts when this option is off, so check actual delivery.
Potential impact
Without an effective notification path, generated alerts may go unnoticed and delay response.
Remediation
Set email_account_admins_enabled = true when account administrators should receive alerts. Configure email_addresses as needed and verify delivery to the responsible people.
Examples
The examples enable the current AzureRM account-administrator email option while retaining the other alert-policy settings.
Before
hcl
resource "azurerm_mssql_server_security_alert_policy" "sql" {
resource_group_name = azurerm_resource_group.main.name
server_name = azurerm_mssql_server.main.name
state = "Enabled"
storage_endpoint = azurerm_storage_account.logs.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.logs.primary_access_key
}
After
hcl
resource "azurerm_mssql_server_security_alert_policy" "sql" {
resource_group_name = azurerm_resource_group.main.name
server_name = azurerm_mssql_server.main.name
state = "Enabled"
storage_endpoint = azurerm_storage_account.logs.primary_blob_endpoint
storage_account_access_key = azurerm_storage_account.logs.primary_access_key
email_account_admins_enabled = true
}