STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Managed Instance Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Sep 2025:

The Azure SQL Managed Instance must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.

DISA Rule

SV-276246r1150054_rule

Vulnerability Number

V-276246

Group Title

SRG-APP-000142-DB-000094

Rule Version

MSQL-00-007700

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Assign the approved policy to Azure SQL Managed Instance:

1. From the Azure Portal, click the Azure SQL Managed Instance.
2. Click "Networking" under Security.
3. Review the public endpoint option.
4. Check the box to "Disable" public endpoint.
5. Click "Save".

Review the Azure SQL Managed Instance's NSG configuration for inbound and outbound rules to restrict access to specific ports and resources.

For more information about connection policies, refer to:
https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/connectivity-architecture-overview?view=azuresql&tabs=current

Check Contents

Azure SQL Managed Instance must only use approved firewall settings, including disabling public network access. This value is not allowed by default in Azure SQL Managed Instance and must be disabled if not otherwise documented and approved.

Obtain a list of all approved firewall settings from the database documentation:

1. From the Azure Portal, click the storage account.
2. Click "Networking" under Security.
3. Verify the public network endpoint option is set to disabled.

If the value is enabled and not specifically approved in the database documentation, this is a finding.

Verify Network Security Groups (NSG) are configured to restrict access only to the resources that require access to the managed instance.

If access is not restricted, this is a finding.

Vulnerability Number

V-276246

Documentable

False

Rule Version

MSQL-00-007700

Severity Override Guidance

Azure SQL Managed Instance must only use approved firewall settings, including disabling public network access. This value is not allowed by default in Azure SQL Managed Instance and must be disabled if not otherwise documented and approved.

Obtain a list of all approved firewall settings from the database documentation:

1. From the Azure Portal, click the storage account.
2. Click "Networking" under Security.
3. Verify the public network endpoint option is set to disabled.

If the value is enabled and not specifically approved in the database documentation, this is a finding.

Verify Network Security Groups (NSG) are configured to restrict access only to the resources that require access to the managed instance.

If access is not restricted, this is a finding.

Check Content Reference

M

Target Key

5711