| Checked | Name | Title |
|---|
| ☐ | SV-276225r1150094_rule | Azure SQL Managed Instances must integrate with Microsoft Entra ID for providing account management and automation for all users, groups, roles, and any other principals. |
| ☐ | SV-276226r1149587_rule | Azure SQL Managed Instance must enforce approved authorizations for logical access to database information and system resources in accordance with applicable access control policies. |
| ☐ | SV-276227r1149590_rule | Database objects must be owned by Azure SQL Managed Instance principals authorized for ownership. |
| ☐ | SV-276228r1149593_rule | The role(s)/group(s) used to modify database structure and logic modules inside Azure SQL Server Managed Instance must be restricted to authorized users. |
| ☐ | SV-276229r1149596_rule | Azure SQL Managed Instance contents must be protected from unauthorized and unintended information transfer by enforcement of a data-transfer policy. |
| ☐ | SV-276230r1150043_rule | Azure SQL Managed Instance and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack. |
| ☐ | SV-276231r1150006_rule | Azure SQL Managed Instance must associate organization-defined types of security labels having organization-defined security label values with information. |
| ☐ | SV-276232r1149605_rule | Azure SQL Managed Instance must enforce discretionary access control policies, as defined by the data owner, over defined subjects and objects. |
| ☐ | SV-276233r1149608_rule | Azure SQL Managed Instance must restrict execution of stored procedures and functions that utilize "execute as" to necessary cases only. |
| ☐ | SV-276234r1149611_rule | Azure SQL Managed Instance must prohibit user installation of logic modules without explicit privileged status. |
| ☐ | SV-276235r1150008_rule | Azure SQL Managed Instance must enforce access restrictions associated with changes to the configuration of the database(s). |
| ☐ | SV-276236r1150044_rule | Azure SQL Managed Instance must use NSA-approved cryptography to protect classified information in accordance with the data owners' requirements. |
| ☐ | SV-276237r1149620_rule | Azure SQL Managed Instance must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest on organization-defined information system components. |
| ☐ | SV-276238r1150056_rule | Azure SQL Managed Instance must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components. |
| ☐ | SV-276239r1149626_rule | When invalid inputs are received, the Azure SQL Managed Instance must behave in a predictable and documented manner that reflects organizational and system objectives. |
| ☐ | SV-276240r1149629_rule | Azure SQL Managed Instance must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the database. |
| ☐ | SV-276241r1149632_rule | Azure SQL Managed Instance must protect against a user falsely repudiating by use of system-versioned tables (Temporal Tables). |
| ☐ | SV-276242r1150021_rule | The Azure SQL Managed Instance must be able to generate audit records when attempts to retrieve privileges/permissions occur. |
| ☐ | SV-276243r1149638_rule | Azure SQL Managed Instance must initiate session auditing upon startup. |
| ☐ | SV-276244r1149641_rule | Azure SQL Managed Instance default demonstration and sample databases, database objects, and applications must be removed. |
| ☐ | SV-276245r1150051_rule | The Azure SQL Managed Instance audit storage account must be configured to prohibit public access. |
| ☐ | SV-276246r1150054_rule | The Azure SQL Managed Instance must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments. |
| ☐ | SV-276247r1150045_rule | Azure SQL Managed Instance must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users). |
| ☐ | SV-276248r1150096_rule | Azure SQL Managed Instance must map the PKI-authenticated identity to an associated user account. |
| ☐ | SV-276249r1149656_rule | Azure SQL Managed Instance must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users). |
| ☐ | SV-276250r1150065_rule | Azure SQL Managed Instance must separate user functionality (including user interface services) from database management functionality. |
| ☐ | SV-276251r1149662_rule | Azure SQL Managed Instance must protect the confidentiality and integrity of all information at rest. |
| ☐ | SV-276252r1149665_rule | Azure SQL Managed Instance must be able to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements. |
| ☐ | SV-276253r1150067_rule | Azure SQL Managed Instance must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75 percent of maximum audit record storage capacity. |
| ☐ | SV-276254r1149671_rule | Azure SQL Managed Instance must generate audit records when security objects are modified. |
| ☐ | SV-276255r1149674_rule | Azure SQL Managed Instance must generate audit records when attempts to modify categorized information (e.g., classification levels/security levels) occur. |
| ☐ | SV-276256r1149677_rule | Azure SQL Managed Instance must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject. |
| ☐ | SV-276257r1150023_rule | Azure SQL Managed Instance must generate audit records when attempts to delete security objects occur. |
| ☐ | SV-276258r1150024_rule | Azure SQL Managed Instance must generate audit records when attempts to delete categories of information (e.g., classification levels/security levels) occur. |
| ☐ | SV-276259r1150012_rule | Azure SQL Managed Instance must generate audit records when logon or connection attempts occur. |
| ☐ | SV-276260r1149689_rule | Azure SQL Managed Instance must generate audit records for all privileged activities or other system-level access. |
| ☐ | SV-276261r1150068_rule | Azure SQL Managed Instance must generate audit records showing starting and ending time for user access to the database(s). |
| ☐ | SV-276262r1149695_rule | Azure SQL Managed Instance must generate audit records when concurrent logons/connections by the same user from different workstations occur. |
| ☐ | SV-276263r1150070_rule | Azure SQL Managed Instance must be able to generate audit records when access to objects occur. |
| ☐ | SV-276264r1149701_rule | Azure SQL Managed Instance must generate audit records for all direct access to the database(s). |
| ☐ | SV-276265r1149704_rule | Azure SQL Managed Instance must store audit records in an immutable blob storage container for an organizationally defined period of time. |
| ☐ | SV-276267r1150098_rule | Azure SQL Managed Instance must implement the capability to centrally review and analyze audit records from multiple components within the system using a service such as Azure Log Analytics. |
| ☐ | SV-276268r1149713_rule | Azure SQL Server Managed Instance must alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information. |
| ☐ | SV-276269r1149716_rule | Azure SQL Managed Instance must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization. |
| ☐ | SV-276276r1149737_rule | Azure SQL Server Managed Instance must, for password-based authentication, require immediate selection of a new password upon account recovery. |
| ☐ | SV-276285r1149764_rule | Azure SQL Managed Instance must limit privileges to change software modules, to include stored procedures, functions, and triggers. |
| ☐ | SV-276286r1149767_rule | Azure SQL Managed Instance must limit privileges to change software modules, to include schema ownership. |
| ☐ | SV-276287r1149770_rule | The database master key (DMK) encryption password for Azure SQL Server Managed Instance must meet DOD password complexity requirements. |
| ☐ | SV-276288r1150072_rule | The database master key (DMK) for Azure SQL Server Managed Instance must be encrypted by the service master key (SMK), where a DMK is required and another encryption method has not been specified. |
| ☐ | SV-276289r1149776_rule | The Certificate used for encryption for Azure SQL Managed Instance must be backed up, stored offline and off-site. |
| ☐ | SV-276290r1149779_rule | Azure SQL Managed Instance must isolate security functions from nonsecurity functions. |
| ☐ | SV-276291r1150014_rule | Azure SQL Managed Instance must check the validity of all data inputs except those specifically identified by the organization. |
| ☐ | SV-276293r1149788_rule | Azure SQL Managed Instance must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies. |
| ☐ | SV-276294r1149791_rule | Azure SQL Managed Instance must protect against a user falsely repudiating by ensuring databases are not in a trust relationship. |
| ☐ | SV-276295r1149794_rule | Azure SQL Managed Instance must be configured to generate audit records for DOD-defined auditable events within all DBMS/database components. |
| ☐ | SV-276296r1150100_rule | Azure SQL Managed Instance must allow only documented and approved individuals or roles to select which auditable events are to be audited. |
| ☐ | SV-276297r1150073_rule | Azure SQL Managed Instance must have an audit defined to track Microsoft Support Operations. |
| ☐ | SV-276298r1150102_rule | The audit information produced by Azure SQL Managed Instance must be protected from unauthorized access. |
| ☐ | SV-276299r1149806_rule | Azure SQL Managed Instance must protect its audit configuration from unauthorized access, modification, and deletion. |
| ☐ | SV-276300r1149809_rule | Access to xp_cmdshell must be disabled for Azure SQL Server Managed Instance unless specifically required and approved. |
| ☐ | SV-276301r1149812_rule | Access to CLR code must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved. |
| ☐ | SV-276302r1149815_rule | Access to linked servers must be disabled or restricted for Azure SQL Server Managed Instance, unless specifically required and approved. |
| ☐ | SV-276303r1150104_rule | If DBMS authentication using passwords is employed, Azure SQL Managed Instance must enforce the DOD standards for password complexity and lifetime. |
| ☐ | SV-276304r1149821_rule | Azure SQL Server Managed Instance contained databases must use Microsoft Entra or native Windows principals. |
| ☐ | SV-276305r1150105_rule | If passwords are used for authentication, Azure SQL Server Managed Instance must transmit only encrypted representations of passwords. |
| ☐ | SV-276306r1150025_rule | Azure SQL Managed Instance must reveal detailed error messages only to the information system security officer (ISSO), information system security manager (ISSM), system administrator (SA), and database administrator (DBA). |
| ☐ | SV-276307r1150107_rule | Azure SQL Managed Instance must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures. |
| ☐ | SV-276308r1149833_rule | Azure SQL Managed Instance must enforce access restrictions associated with changes to the configuration of the instance. |
| ☐ | SV-276309r1149836_rule | Azure Resource Manager must enforce access restrictions associated with changes to the configuration of Azure SQL Managed Instance. |
| ☐ | SV-276310r1150016_rule | Azure SQL Managed Instance must produce audit records of its enforcement of access restrictions associated with changes to the configuration of Azure SQL Managed Instance or database(s). |
| ☐ | SV-276311r1149842_rule | Azure SQL Managed Instance must maintain a separate execution domain for each executing process. |
| ☐ | SV-276312r1150026_rule | Azure SQL Managed Instance must be able to generate audit records when attempts to access security objects occur. |
| ☐ | SV-276313r1149848_rule | Azure SQL Managed Instance must generate audit records when attempts to access categorized information (e.g., classification levels/security levels) occur. |
| ☐ | SV-276314r1149851_rule | Azure SQL Managed Instance must generate audit records when attempts to add privileges/permissions occur. |
| ☐ | SV-276315r1149854_rule | Azure SQL Managed Instance must generate audit records when attempts to modify privileges/permissions occur. |
| ☐ | SV-276316r1150060_rule | Azure SQL Managed Instance must generate audit records when attempts to delete privileges/permissions occur. |
| ☐ | SV-276317r1150033_rule | The Azure SQL Managed Instance default [sa] account must be disabled. |
| ☐ | SV-276318r1150020_rule | Azure SQL Managed Instance default [sa] account must have its name changed. |
| ☐ | SV-276319r1150018_rule | The Allow Filesystem Enumeration feature must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved. |
| ☐ | SV-276320r1149869_rule | The CLR Strict Security feature must be enabled for Azure SQL Server Managed Instance, unless specifically required and approved. |
| ☐ | SV-276321r1149872_rule | The Hadoop Connectivity feature must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved. |
| ☐ | SV-276322r1150027_rule | Azure SQL Server Managed Instance Replication Xps feature must be disabled, unless specifically required and approved. |
| ☐ | SV-276323r1149878_rule | When using command-line tools with Azure SQL Server Managed Instance, such as SQLCMD, in a mixed-mode authentication environment, users must use a logon method that does not expose the password. |
| ☐ | SV-276324r1150034_rule | Applications connecting to Azure SQL Server Managed Instance must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals. |