More Info:

Do not disable alerts related to threat detections.

Risk Level

Medium

Address

Security

Compliance Standards

HITRUST, SOC2, NISTCSF, PCIDSS

Triage and Remediation

Remediation

To remediate the misconfiguration “Threat Detection Alerts Disabled for SQL Servers” in Azure using the Azure console, follow the below steps:

  1. Login to the Azure portal and navigate to the SQL Server that needs to be remediated.

  2. Select the SQL Server and navigate to the “Security” section.

  3. Under the “Security” section, select “Advanced Data Security”.

  4. Under the “Advanced Data Security” section, select “Threat detection settings”.

  5. In the “Threat detection settings” section, toggle the “Threat detection” button to “On”.

  6. Once the “Threat detection” button is turned on, select the “Alerts” tab.

  7. Under the “Alerts” tab, select the “Email recipients” option and add the email addresses of the recipients who should receive the alerts.

  8. Click on the “Save” button to save the changes.

  9. Once the changes are saved, the threat detection alerts will be enabled for the SQL Server, and the specified recipients will receive the alerts.

By following these steps, the misconfiguration “Threat Detection Alerts Disabled for SQL Servers” will be remediated in Azure using the Azure console.