STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Database Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

The Azure SQL Database must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the PPSM CAL and vulnerability assessments.

DISA Rule

SV-255334r1043177_rule

Vulnerability Number

V-255334

Group Title

SRG-APP-000142-DB-000094

Rule Version

ASQL-00-007700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Assign the approved policy to Azure SQL Database.
1. From the Azure Portal Dashboard, click the "database".
2. Click "Set Server Firewall".
3. Review the public network access option.
4. Check the box to "Disable" public network access.
5. Click "Save".

For more information about connection policies:
https://docs.microsoft.com/en-us/azure/azure-sql/database/connectivity-architecture

Check Contents

Azure SQL Database must only use approved firewall settings, including disabling public network access. This value is allowed by default in Azure SQL Database and must be disabled if not otherwise documented and approved.

Obtain a list of all approved firewall settings from the database documentation.

From the Azure Portal Dashboard, click the database, then click "Set Server Firewall". Verify that the public network access option is set to disabled.

If the value is enabled and not specifically approved in the database documentation, this is a finding.

Vulnerability Number

V-255334

Documentable

False

Rule Version

ASQL-00-007700

Severity Override Guidance

Azure SQL Database must only use approved firewall settings, including disabling public network access. This value is allowed by default in Azure SQL Database and must be disabled if not otherwise documented and approved.

Obtain a list of all approved firewall settings from the database documentation.

From the Azure Portal Dashboard, click the database, then click "Set Server Firewall". Verify that the public network access option is set to disabled.

If the value is enabled and not specifically approved in the database documentation, this is a finding.

Check Content Reference

M

Target Key

5500