More Info:

Set an Azure Active Directory admin for every SQL server.

Risk Level

Medium

Address

Security

Compliance Standards

CISAZURE, CBP, HITRUST, SOC2, NISTCSF

Triage and Remediation

Remediation

Sure, here are the step-by-step instructions to remediate the misconfiguration of a short threat detection retention period for SQL Servers in Azure:

  1. Log in to the Azure portal (https://portal.azure.com/).
  2. In the left-hand menu, click on “SQL servers”.
  3. Select the SQL server you want to remediate.
  4. In the left-hand menu of the SQL server page, click on “Advanced Data Security”.
  5. On the Advanced Data Security page, click on the “Settings” tab.
  6. Scroll down to the “Data retention” section.
  7. Increase the retention period to the desired value (e.g. 90 days).
  8. Click on the “Save” button at the top of the page to save the changes.

Once you have completed these steps, your SQL server will have a longer threat detection retention period. This will allow you to detect and investigate security threats over a longer period of time, improving your overall security posture.