STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Managed Instance Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Sep 2025:

Azure SQL Managed Instance must protect its audit configuration from unauthorized access, modification, and deletion.

DISA Rule

SV-276299r1149806_rule

Vulnerability Number

V-276299

Group Title

SRG-APP-000121-DB-000202

Rule Version

MSQL-D0-006200

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Apply or modify permissions on tools used to view or modify audit log data (to include traces used for audit purposes), to make them accessible by authorized personnel only.

Remove audit-related permissions from individuals and roles not authorized to have them:

USE master;
DENY [ALTER ANY SERVER AUDIT] TO [User];
GO

Check Contents

Check the documentation for a list of approved users with access to Azure SQL Managed Instance Audit files.

To create, alter, or drop a server audit, principals require the ALTER ANY SERVER AUDIT or the CONTROL SERVER permission.

Review the SQL Server permissions granted to principals. Look for permissions ALTER ANY SERVER AUDIT, ALTER ANY DATABASE AUDIT, CONTROL SERVER:

SELECT login.name, perm.permission_name, perm.state_desc
FROM sys.server_permissions perm
JOIN sys.server_principals login
ON perm.grantee_principal_id = login.principal_id
WHERE permission_name in ('ALTER ANY DATABASE AUDIT', 'ALTER ANY SERVER AUDIT', 'CONTROL SERVER')
AND login.name not like '##MS_%';

Modify audit permissions to meet the requirement to protect against unauthorized access to Audit files. To review the roles and users, navigate to the Azure Portal, and review the Azure Storage container that is hosting the Audit files. Remove any undocumented permissions or excessive permissions to audit storage for user and roles.

If unauthorized accounts have these privileges, this is a finding.

Vulnerability Number

V-276299

Documentable

False

Rule Version

MSQL-D0-006200

Severity Override Guidance

Check the documentation for a list of approved users with access to Azure SQL Managed Instance Audit files.

To create, alter, or drop a server audit, principals require the ALTER ANY SERVER AUDIT or the CONTROL SERVER permission.

Review the SQL Server permissions granted to principals. Look for permissions ALTER ANY SERVER AUDIT, ALTER ANY DATABASE AUDIT, CONTROL SERVER:

SELECT login.name, perm.permission_name, perm.state_desc
FROM sys.server_permissions perm
JOIN sys.server_principals login
ON perm.grantee_principal_id = login.principal_id
WHERE permission_name in ('ALTER ANY DATABASE AUDIT', 'ALTER ANY SERVER AUDIT', 'CONTROL SERVER')
AND login.name not like '##MS_%';

Modify audit permissions to meet the requirement to protect against unauthorized access to Audit files. To review the roles and users, navigate to the Azure Portal, and review the Azure Storage container that is hosting the Audit files. Remove any undocumented permissions or excessive permissions to audit storage for user and roles.

If unauthorized accounts have these privileges, this is a finding.

Check Content Reference

M

Target Key

5711