SV-276246r1150054_rule
V-276246
SRG-APP-000142-DB-000094
MSQL-00-007700
CAT II
10
Assign the approved policy to Azure SQL Managed Instance:
1. From the Azure Portal, click the Azure SQL Managed Instance.
2. Click "Networking" under Security.
3. Review the public endpoint option.
4. Check the box to "Disable" public endpoint.
5. Click "Save".
Review the Azure SQL Managed Instance's NSG configuration for inbound and outbound rules to restrict access to specific ports and resources.
For more information about connection policies, refer to:
https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/connectivity-architecture-overview?view=azuresql&tabs=current
Azure SQL Managed Instance must only use approved firewall settings, including disabling public network access. This value is not allowed by default in Azure SQL Managed Instance and must be disabled if not otherwise documented and approved.
Obtain a list of all approved firewall settings from the database documentation:
1. From the Azure Portal, click the storage account.
2. Click "Networking" under Security.
3. Verify the public network endpoint option is set to disabled.
If the value is enabled and not specifically approved in the database documentation, this is a finding.
Verify Network Security Groups (NSG) are configured to restrict access only to the resources that require access to the managed instance.
If access is not restricted, this is a finding.
V-276246
False
MSQL-00-007700
Azure SQL Managed Instance must only use approved firewall settings, including disabling public network access. This value is not allowed by default in Azure SQL Managed Instance and must be disabled if not otherwise documented and approved.
Obtain a list of all approved firewall settings from the database documentation:
1. From the Azure Portal, click the storage account.
2. Click "Networking" under Security.
3. Verify the public network endpoint option is set to disabled.
If the value is enabled and not specifically approved in the database documentation, this is a finding.
Verify Network Security Groups (NSG) are configured to restrict access only to the resources that require access to the managed instance.
If access is not restricted, this is a finding.
M
5711