4. Database Services

Ensure that 'Auditing' is set to 'On'
Description: Enabling auditing on SQL Server records database activities and stores them in a log destination such as a Storage Account, Log Analytics work...
Sat, 27 Dec, 2025 at 11:49 AM
Ensure that 'Data encryption' is set to 'On' on a SQL Database
Description: Azure SQL Database uses Transparent Data Encryption (TDE) to protect data at rest by automatically encrypting the database, backups, and trans...
Sat, 27 Dec, 2025 at 12:09 PM
Ensure that 'Auditing' Retention is 'greater than 90 days'
Description: SQL Server auditing should be configured with a retention period greater than 90 days to ensure that sufficient audit data is available for mo...
Sat, 27 Dec, 2025 at 12:05 PM
Ensure that Advanced Threat Protection (ATP) on a SQL server is set to 'Enabled'
Description: Enable "Azure Defender for SQL" on critical SQL Servers. Advanced Threat Protection (ATP) on a SQL server is set to 'Enabled'...
Thu, 28 Oct, 2021 at 12:31 AM
Ensure that Vulnerability Assessment (VA) is enabled on a SQL server by setting a Storage Account
Description: Azure SQL Vulnerability Assessment scans SQL servers and their databases for security risks, configuration issues, and deviations from best pr...
Sat, 27 Dec, 2025 at 12:12 PM
Ensure that VA setting Periodic Recurring Scans is enabled on a SQL server
Description: Enable Vulnerability Assessment (VA) Periodic recurring scans for critical SQL servers and corresponding SQL databases. Rationale: VA settin...
Thu, 28 Oct, 2021 at 12:33 AM
Ensure 'Enforce SSL connection' is set to 'ENABLED' for PostgreSQL Database Server
Description: Azure Database for PostgreSQL supports encrypted connections using SSL or TLS. Enabling Enforce SSL Connection ensures that all client traffic...
Wed, 31 Dec, 2025 at 2:54 AM
Ensure that VA setting Send scan reports to is configured for a SQL server
Description: Configure 'Send scan reports to' with email ids of concerned data owners/stakeholders for a critical SQL servers. Rationale: Vulnera...
Thu, 28 Oct, 2021 at 12:38 AM
Ensure that VA setting 'Also send email notifications to admins and subscription owners' is set for a SQL server
Description: Enable Vulnerability Assessment (VA) setting 'Also send email notifications to admins and subscription owners'. Rationale: VA scan r...
Thu, 28 Oct, 2021 at 12:35 AM
Ensure SQL server's TDE protector is encrypted with Customer- managed key
Description: TDE with Customer-managed key support provides increased transparency and control over the TDE Protector, increased security with an HSM-backe...
Tue, 22 Aug, 2023 at 5:05 AM