Review Azure SQL administrator login names

Use a valid administrator login name that follows organizational naming standards.

Description

A common administrator name can help an attacker guess a login target. Login names are not secrets, however, and a complex name alone does not protect an account.

Potential impact

A predictable name may assist targeted login attempts, but actual access depends on credentials and access controls.

Remediation

Choose a valid organizational name and apply strong credentials and access restrictions. Changing an existing administrator_login requires server replacement, so inspect the plan first. Use supported Microsoft Entra authentication when MFA is needed.

Examples

The current AzureRM examples replace a generic name with an organization-approved input. Renaming alone does not secure the account; passwords are illustrative.

Before

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = "sqladmin"
  administrator_login_password = "thisIsDog11"
}

After

hcl
resource "azurerm_mssql_server" "example" {
  name                         = "mssqlserver"
  resource_group_name          = azurerm_resource_group.example.name
  location                     = azurerm_resource_group.example.location
  version                      = "12.0"
  administrator_login          = var.sql_admin_name
  administrator_login_password = "thisIsDog11"
}

References