More Info:

Enable threat detection for all SQL Databases.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, SOC2, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration of threat detection being disabled for SQL databases in Azure using the Azure console, follow these steps:

  1. Log in to the Azure portal and navigate to the SQL databases page.
  2. Select the SQL database for which you want to enable threat detection.
  3. In the left-hand menu, click on “Security”.
  4. Click on “Advanced Threat Protection” in the security menu.
  5. Click on “Configure advanced threat protection” to start configuring the settings.
  6. In the “Configure advanced threat protection” blade, toggle the “Advanced Threat Protection” switch to “On”.
  7. In the “Storage account” field, select the storage account where you want to store the logs.
  8. In the “Email addresses to notify” field, add the email addresses of the people who should be notified in case of a threat.
  9. In the “Send alerts to Azure Security Center” field, toggle the switch to “On” if you want to send alerts to Azure Security Center.
  10. Click on “Save” to save the settings.

Once you have followed these steps, threat detection will be enabled for the SQL database and you will be notified in case of any security threats.