STIGQter STIGQter: STIG Summary: Microsoft Azure SQL Managed Instance Security Technical Implementation Guide Version: 1 Release: 1 Benchmark Date: 23 Sep 2025:

The Allow Filesystem Enumeration feature must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved.

DISA Rule

SV-276319r1150018_rule

Vulnerability Number

V-276319

Group Title

SRG-APP-000141-DB-000093

Rule Version

MSQL-D0-016800

Severity

CAT II

CCI(s)

Weight

10

Fix Recommendation

Disable use of or remove any external application executable object definitions that are not approved.

To disable the use of allow filesystem enumeration, from the query prompt:

EXEC SP_CONFIGURE 'show advanced options', 1;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'allow filesystem enumeration', 0;
RECONFIGURE WITH OVERRIDE;
EXEC SP_CONFIGURE 'show advanced options', 0;
RECONFIGURE WITH OVERRIDE;

Check Contents

To determine if allow filesystem enumeration is enabled, execute the following command:

SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'allow filesystem enumeration'

If "value_in_use" is a "1", review the system documentation to determine whether the use of allow filesystem enumeration is approved. If it is not approved, this is a finding.

Vulnerability Number

V-276319

Documentable

False

Rule Version

MSQL-D0-016800

Severity Override Guidance

To determine if allow filesystem enumeration is enabled, execute the following command:

SELECT name, value, value_in_use
FROM sys.configurations
WHERE name = 'allow filesystem enumeration'

If "value_in_use" is a "1", review the system documentation to determine whether the use of allow filesystem enumeration is approved. If it is not approved, this is a finding.

Check Content Reference

M

Target Key

5711