Azure_SQLServers_7

Ensure that Email service and co - administrators is ' Enabled '

Description

Enable service and co-administrators to receive security alerts from the SQL server.

Remediation

Perform the following in the Azure Console:

  1. Go to SQL servers
  2. For each server instance
  3. Click on Advanced Data Security
  4. At section Threat Detection Settings, Enable Email service and co-administrators

Perform the following in Azure PowerShell:

For each Server, enable Email service and co-administrators.

Set-AzureRmSqlServerThreatDetectionPolicy -ResourceGroupName <resource groupname> -ServerName <server name> -EmailAdmins $True

References:

  1. https://docs.microsoft.com/en-us/azure/sql-database/sql-advanced-threat-protection
  2. https://docs.microsoft.com/cs-cz/powershell/module/azurerm.sql/get-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0
  3. https://docs.microsoft.com/en-us/powershell/module/azurerm.sql/set-azurermsqlserverthreatdetectionpolicy?view=azurermps-5.2.0

Service

Database Services

Severity

High

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!