SV-276263r1150070_rule
V-276263
SRG-APP-000507-DB-000356
MSQL-00-015300
CAT II
10
Deploy an Azure SQL Managed Instance audit. Refer to the supplemental file "AzureSQLMIAudit.sql" script.
Reference: https://learn.microsoft.com/en-us/azure/azure-sql/managed-instance/auditing-configure?view=azuresql-mi
Review Azure SQL Managed Instance configuration to verify audit records are produced when successful accesses to objects occur.
Run this TSQL command to determine if SQL Auditing AuditActionGroups are configured:
SELECT a.name AS 'AuditName', s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
AND d.audit_action_name = 'SCHEMA_OBJECT_ACCESS_GROUP'
If no values are listed for AuditActionGroups, this is a finding.
V-276263
False
MSQL-00-015300
Review Azure SQL Managed Instance configuration to verify audit records are produced when successful accesses to objects occur.
Run this TSQL command to determine if SQL Auditing AuditActionGroups are configured:
SELECT a.name AS 'AuditName', s.name AS 'SpecName',
d.audit_action_name AS 'ActionName',
d.audited_result AS 'Result'
FROM sys.server_audit_specifications s
JOIN sys.server_audits a ON s.audit_guid = a.audit_guid
JOIN sys.server_audit_specification_details d ON s.server_specification_id = d.server_specification_id
WHERE a.is_state_enabled = 1
AND d.audit_action_name = 'SCHEMA_OBJECT_ACCESS_GROUP'
If no values are listed for AuditActionGroups, this is a finding.
M
5711