STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Database Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Azure SQL Database must be able to generate audit records when privileges/permissions are retrieved.

DISA Rule

SV-255326r960885_rule

Vulnerability Number

V-255326

Group Title

SRG-APP-000091-DB-000066

Rule Version

ASQL-00-004500

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy an audit to review the retrieval of privilege/permission/role membership information.

Refer to the supplemental file "AzureSQLDatabaseAudit.txt" PowerShell script.

Check Contents

Review Azure SQL Database configuration to verify that audit records are produced when privileges/permissions/role memberships are retrieved.

To determine if an audit is configured, follow the instructions below:
Run this TSQL command to determine if SQL Auditing AuditActionGroups are configured:
SELECT DISTINCT sd.audit_action_name
FROM sys.database_audit_specification_details sd
JOIN sys.database_audit_specifications s
ON s.database_specification_id = sd.database_specification_id
WHERE (name = 'SqlDbAuditing_ServerAuditSpec' /*Server Audit*/
OR name = 'SqlDbAuditing_AuditSpec') /*Database Audit*/
AND s.is_state_enabled = 1
ORDER BY sd.audit_action_name

If no values exist for AuditActionGroup, this is a finding.

Verify the following AuditActionGroup(s) are configured:
SCHEMA_OBJECT_ACCESS_GROUP

If any listed AuditActionGroups do not exist in the configuration, this is a finding.

Vulnerability Number

V-255326

Documentable

False

Rule Version

ASQL-00-004500

Severity Override Guidance

Review Azure SQL Database configuration to verify that audit records are produced when privileges/permissions/role memberships are retrieved.

To determine if an audit is configured, follow the instructions below:
Run this TSQL command to determine if SQL Auditing AuditActionGroups are configured:
SELECT DISTINCT sd.audit_action_name
FROM sys.database_audit_specification_details sd
JOIN sys.database_audit_specifications s
ON s.database_specification_id = sd.database_specification_id
WHERE (name = 'SqlDbAuditing_ServerAuditSpec' /*Server Audit*/
OR name = 'SqlDbAuditing_AuditSpec') /*Database Audit*/
AND s.is_state_enabled = 1
ORDER BY sd.audit_action_name

If no values exist for AuditActionGroup, this is a finding.

Verify the following AuditActionGroup(s) are configured:
SCHEMA_OBJECT_ACCESS_GROUP

If any listed AuditActionGroups do not exist in the configuration, this is a finding.

Check Content Reference

M

Target Key

5500