STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Managed Instance Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Sep 2025:

Azure SQL Managed Instance must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).

DISA Rule

SV-276249r1149656_rule

Vulnerability Number

V-276249

Group Title

SRG-APP-000180-DB-000115

Rule Version

MSQL-00-008800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Ensure all logins are uniquely identifiable and authenticate all nonorganizational users who log onto the system. This can be done via a combination of Azure Entra with unique accounts and the Azure SQL Managed Instance by ensuring mapping to individual accounts. Verify server documentation to ensure accounts are documented and unique.

Check Contents

Review documentation, Azure SQL Managed Instance settings, and authentication system settings to determine if nonorganizational users are individually identified and authenticated when logging onto the system.

If accounts are determined to be shared, determine if individuals are first individually authenticated. Where an application connects to Azure SQL Managed Instance using a standard, shared account, verify it also captures the individual user identification and passes it to Azure SQL Managed Instance.

If the documentation indicates that this is a public-facing, read-only (from the point of view of public users) database that does not require individual authentication, this is not a finding.

If nonorganizational users are not uniquely identified and authenticated, this is a finding.

Vulnerability Number

V-276249

Documentable

False

Rule Version

MSQL-00-008800

Severity Override Guidance

Review documentation, Azure SQL Managed Instance settings, and authentication system settings to determine if nonorganizational users are individually identified and authenticated when logging onto the system.

If accounts are determined to be shared, determine if individuals are first individually authenticated. Where an application connects to Azure SQL Managed Instance using a standard, shared account, verify it also captures the individual user identification and passes it to Azure SQL Managed Instance.

If the documentation indicates that this is a public-facing, read-only (from the point of view of public users) database that does not require individual authentication, this is not a finding.

If nonorganizational users are not uniquely identified and authenticated, this is a finding.

Check Content Reference

M

Target Key

5711