Azure_SQLServers_6

Ensure that Send alerts to is set

Description

Provide the email address where alerts will be sent when anomalous activities are detected on SQL servers.

Remediation

Perform the following in the Azure Console:

  1. Go to SQL servers
  2. For each server instance
  3. Click on Advanced Threat Protection
  4. At section Threat Detection Settings, Ensure that Send alerts to is set as appropriate.

Perform the following in Azure PowerShell:

For each Server, set Send alerts to.

Set-AzureRmSqlServerThreatDetectionPolicy -ResourceGroupName <resource groupname> -ServerName <server name> -NotificationRecipientsEmails <RecipientEmail ID>

References:

  1. https://docs.microsoft.com/en-us/azure/sql-database/sql-advanced-threat-protection
  2. https://docs.microsoft.com/cs-cz/powershell/module/azurerm.sql/get-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0
  3. https://docs.microsoft.com/en-us/powershell/module/azurerm.sql/set-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0

Service

Database Services

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!