Review administrator emails for Azure SQL security alerts

Deliver security alerts through a channel their owners monitor.

Description

The administrator-email option sends Azure SQL security alerts to account administrators. Separate recipient addresses or other operational channels can still deliver alerts when this option is off, so check actual delivery.

Potential impact

Without an effective notification path, generated alerts may go unnoticed and delay response.

Remediation

Set email_account_admins_enabled = true when account administrators should receive alerts. Configure email_addresses as needed and verify delivery to the responsible people.

Examples

The examples enable the current AzureRM account-administrator email option while retaining the other alert-policy settings.

Before

hcl
resource "azurerm_mssql_server_security_alert_policy" "sql" {
  resource_group_name        = azurerm_resource_group.main.name
  server_name                = azurerm_mssql_server.main.name
  state                      = "Enabled"
  storage_endpoint           = azurerm_storage_account.logs.primary_blob_endpoint
  storage_account_access_key = azurerm_storage_account.logs.primary_access_key
}

After

hcl
resource "azurerm_mssql_server_security_alert_policy" "sql" {
  resource_group_name        = azurerm_resource_group.main.name
  server_name                = azurerm_mssql_server.main.name
  state                      = "Enabled"
  storage_endpoint           = azurerm_storage_account.logs.primary_blob_endpoint
  storage_account_access_key = azurerm_storage_account.logs.primary_access_key
  email_account_admins_enabled = true
}

References