Azure_SQLServers_4

Ensure that Advanced Data Security ' on a SQL server is set to ' On '

Description

Enable Advanced Data Security on critical SQL Servers.

Remediation

Perform the following in the Azure Console:

  1. Go to SQL servers
  2. For each server instance
  3. Click on Advanced Data Security
  4. Set Advanced Data Security to On

Perform the following in Azure PowerShell:

Enable Advanced Data Security for a SQL Server.

Set-AzureRmSqlServerThreatDetectionPolicy -ResourceGroupName <resource groupname> -ServerName <server name> -EmailAdmins $True

References:

  1. https://docs.microsoft.com/en-us/azure/sql-database/sql-advanced-threat-protection
  2. https://docs.microsoft.com/cs-cz/powershell/module/azurerm.sql/get-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0
  3. https://docs.microsoft.com/en-us/powershell/module/azurerm.sql/set-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0

Service

Database Services

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!