last sync: 2020-Jul-10 14:05:01 UTC

Azure Policy

Advanced data security should be enabled on Azure SQL Database servers

Policy DisplayName Advanced data security should be enabled on Azure SQL Database servers
Policy Id 7fe3b40f-802b-4cdd-8bd4-fd799c948cc2
Policy Category Security Center
Policy Description Advanced data security standard tier should be enabled on Azure SQL Database servers. This provides functionality for surfacing and mitigating potential database vulnerabilities, detecting anomalous activities that could indicate a threat on SQL database and discovering and classifying sensitive data.
Policy Mode All
Policy Type BuiltIn
Policy in Preview FALSE
Policy Deprecated FALSE
Policy Effect Default: AuditIfNotExists
Allowed: (AuditIfNotExists,Disabled)
Roles used none
Policy Changes
Date/Time (UTC ymd) (i) Change Change detail
2020-06-23 16:03:25 add: Policy 7fe3b40f-802b-4cdd-8bd4-fd799c948cc2
Used in Policy Initiative(s)
Initiative DisplayName Initiative Id
Enable Monitoring in Azure Security Center 1f3afdf9-d0c9-4c3d-847f-89da613e70a8
Policy Rule
{
  "properties": {
    "displayName": "Advanced data security should be enabled on Azure SQL Database servers",
    "policyType": "BuiltIn",
    "mode": "All",
    "description": "Advanced data security standard tier should be enabled on Azure SQL Database servers. This provides functionality for surfacing and mitigating potential database vulnerabilities, detecting anomalous activities that could indicate a threat on SQL database and discovering and classifying sensitive data.",
    "metadata": {
      "version": "1.0.1",
      "category": "Security Center"
    },
    "parameters": {
      "effect": {
        "type": "String",
        "metadata": {
          "displayName": "Effect",
          "description": "Enable or disable the execution of the policy"
        },
        "allowedValues": [
          "AuditIfNotExists",
          "Disabled"
        ],
        "defaultValue": "AuditIfNotExists"
      }
    },
    "policyRule": {
      "if": {
        "field": "type",
        "equals": "Microsoft.Resources/subscriptions"
      },
      "then": {
      "effect": "[parameters('effect')]",
        "details": {
          "type": "Microsoft.Security/pricings",
          "name": "SqlServers",
          "existenceScope": "subscription",
          "existenceCondition": {
            "field": "Microsoft.Security/pricings/pricingTier",
            "equals": "Standard"
          }
        }
      }
    }
  },
  "id": "/providers/Microsoft.Authorization/policyDefinitions/7fe3b40f-802b-4cdd-8bd4-fd799c948cc2",
  "type": "Microsoft.Authorization/policyDefinitions",
  "name": "7fe3b40f-802b-4cdd-8bd4-fd799c948cc2"
}