STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Database Security Technical Implementation Guide Version: 2 Release: 3 Benchmark Date: 02 Jul 2025:

Azure SQL Database must only use approved firewall settings deemed by the organization to be secure, including denying public network access.

DISA Rule

SV-255346r961470_rule

Vulnerability Number

V-255346

Group Title

SRG-APP-000383-DB-000364

Rule Version

ASQL-00-011900

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Assign the approved policy to Azure SQL Database.
1. From the Azure Portal Dashboard, click on the database.
2. Click "Set Server Firewall".
3. Review the public network access option.
4. Check the box to "Disable" public network access.
5. Click "Save".

For more information about connection policies:
https://docs.microsoft.com/en-us/azure/azure-sql/database/connectivity-architecture

Check Contents

Azure SQL Database must only use approved firewall settings, including denying public network access. This value is allowed by default in Azure SQL Database and should be disabled if not otherwise documented and approved.

Obtain a list of approved firewall settings from the database documentation.

Verify that the public network access option is set to disabled.

If the value is enabled and not in use and specifically approved in the database documentation, this is a finding.

1. From the Azure Portal Dashboard, click "Set Server Firewall".
2. Review the Allow Azure services and resources to access this server option.

Vulnerability Number

V-255346

Documentable

False

Rule Version

ASQL-00-011900

Severity Override Guidance

Azure SQL Database must only use approved firewall settings, including denying public network access. This value is allowed by default in Azure SQL Database and should be disabled if not otherwise documented and approved.

Obtain a list of approved firewall settings from the database documentation.

Verify that the public network access option is set to disabled.

If the value is enabled and not in use and specifically approved in the database documentation, this is a finding.

1. From the Azure Portal Dashboard, click "Set Server Firewall".
2. Review the Allow Azure services and resources to access this server option.

Check Content Reference

M

Target Key

5500