STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Managed Instance Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Sep 2025:

Azure SQL Managed Instance must associate organization-defined types of security labels having organization-defined security label values with information.

DISA Rule

SV-276231r1150006_rule

Vulnerability Number

V-276231

Group Title

SRG-APP-000313-DB-000309

Rule Version

MSQL-00-002600

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Deploy SQL Information Protection (refer to link below) or Azure SQL Managed Instance Row-Level Security (see link below), a third-party software, or add custom data structures, data elements and application code to provide reliable security labeling of information.

Refer to: https://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-information-protection-policy?tabs=sqlip-tenant
https://learn.microsoft.com/en-us/sql/relational-databases/security/row-level-security?view=sql-server-ver16

Check Contents

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but a third-party solution, SQL Information Protection, or an Azure SQL Managed Instance Row-Level security solution is implemented that reliably maintains labels on information, this is a finding.

Vulnerability Number

V-276231

Documentable

False

Rule Version

MSQL-00-002600

Severity Override Guidance

If security labeling is not required, this is not a finding.

If security labeling requirements have been specified, but a third-party solution, SQL Information Protection, or an Azure SQL Managed Instance Row-Level security solution is implemented that reliably maintains labels on information, this is a finding.

Check Content Reference

M

Target Key

5711