More Info:

Enable auditing for all SQL Databases.

Risk Level

Medium

Address

Security, Operational Maturity

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the issue of auditing disabled for SQL databases in Azure, you can follow the below steps:

  1. Open the Azure portal and go to the SQL database that needs to be remediated.

  2. In the left-hand menu, select “Auditing and Threat Detection”.

  3. In the “Auditing and Threat Detection” blade, select “Audit logs”.

  4. In the “Audit logs” blade, click on the “Turn on auditing” button.

  5. In the “Audit logs” blade, select the storage account where the audit logs will be stored.

  6. Click on “Save” to enable auditing for the SQL database.

  7. In the “Auditing and Threat Detection” blade, select “Threat Detection”.

  8. In the “Threat Detection” blade, click on “Enable Threat Detection”.

  9. In the “Threat Detection” blade, select the storage account where the threat detection logs will be stored.

  10. Click on “Save” to enable threat detection for the SQL database.

Once the above steps are completed, auditing and threat detection will be enabled for the SQL database in Azure.