STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Database Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Azure SQL Database must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.

DISA Rule

SV-255341r961353_rule

Vulnerability Number

V-255341

Group Title

SRG-APP-000340-DB-000304

Rule Version

ASQL-00-010400

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Restrict permissions to Azure SQL Database securables to only authorized users.

Check Contents

Review Azure SQL Database securables and built-in role membership to ensure only authorized users have privileged access and the ability to create server-level objects and grant permissions to themselves or others.

Review the system documentation to determine the required levels of protection for Azure SQL Database securables.

Review the permissions in place in the control and data planes in Azure SQL Database. If the actual permissions do not match the documented requirements, this is a finding.

Ensure only the documented and approved logins have privileged functions in Azure SQL Database.

If the current configuration does not match the documented baseline, this is a finding.

Vulnerability Number

V-255341

Documentable

False

Rule Version

ASQL-00-010400

Severity Override Guidance

Review Azure SQL Database securables and built-in role membership to ensure only authorized users have privileged access and the ability to create server-level objects and grant permissions to themselves or others.

Review the system documentation to determine the required levels of protection for Azure SQL Database securables.

Review the permissions in place in the control and data planes in Azure SQL Database. If the actual permissions do not match the documented requirements, this is a finding.

Ensure only the documented and approved logins have privileged functions in Azure SQL Database.

If the current configuration does not match the documented baseline, this is a finding.

Check Content Reference

M

Target Key

5500