More Info:

Configure the ‘AuditActionGroups’ property to appropriate groups to capture all the critical activities on the SQL Server and all the SQL databases hosted on the SQL server.

Risk Level

Medium

Address

Reliability, Security

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration related to AuditActionGroups in Azure, please follow the below steps:

  1. Login to the Azure portal (https://portal.azure.com/).
  2. Go to the Azure Active Directory service.
  3. Select the “Audit logs” option under the Monitoring section.
  4. In the Audit logs blade, click on the “Diagnostic settings” option.
  5. Select the diagnostic setting that needs to be remediated.
  6. In the “Diagnostic settings” blade, scroll down to the “Categories” section.
  7. In the “Categories” section, ensure that the “AuditLogs” option is selected.
  8. Under the “AuditLogs” option, select the “Select specific actions” radio button.
  9. In the “Select specific actions” section, ensure that all the required AuditActionGroups are selected.
  10. Click on the “Save” button to save the changes.

By following the above steps, the misconfiguration related to AuditActionGroups in Azure can be remediated.