STIGQter STIGQter: STIG Summary:

Microsoft Azure SQL Managed Instance Security Technical Implementation Guide

Version: 1

Release: 1 Benchmark Date: 23 Sep 2025

CheckedNameTitle
SV-276225r1150094_ruleAzure SQL Managed Instances must integrate with Microsoft Entra ID for providing account management and automation for all users, groups, roles, and any other principals.
SV-276226r1149587_ruleAzure SQL Managed Instance must enforce approved authorizations for logical access to database information and system resources in accordance with applicable access control policies.
SV-276227r1149590_ruleDatabase objects must be owned by Azure SQL Managed Instance principals authorized for ownership.
SV-276228r1149593_ruleThe role(s)/group(s) used to modify database structure and logic modules inside Azure SQL Server Managed Instance must be restricted to authorized users.
SV-276229r1149596_ruleAzure SQL Managed Instance contents must be protected from unauthorized and unintended information transfer by enforcement of a data-transfer policy.
SV-276230r1150043_ruleAzure SQL Managed Instance and associated applications, when making use of dynamic code execution, must scan input data for invalid values that may indicate a code injection attack.
SV-276231r1150006_ruleAzure SQL Managed Instance must associate organization-defined types of security labels having organization-defined security label values with information.
SV-276232r1149605_ruleAzure SQL Managed Instance must enforce discretionary access control policies, as defined by the data owner, over defined subjects and objects.
SV-276233r1149608_ruleAzure SQL Managed Instance must restrict execution of stored procedures and functions that utilize "execute as" to necessary cases only.
SV-276234r1149611_ruleAzure SQL Managed Instance must prohibit user installation of logic modules without explicit privileged status.
SV-276235r1150008_ruleAzure SQL Managed Instance must enforce access restrictions associated with changes to the configuration of the database(s).
SV-276236r1150044_ruleAzure SQL Managed Instance must use NSA-approved cryptography to protect classified information in accordance with the data owners' requirements.
SV-276237r1149620_ruleAzure SQL Managed Instance must implement cryptographic mechanisms to prevent unauthorized modification of organization-defined information at rest on organization-defined information system components.
SV-276238r1150056_ruleAzure SQL Managed Instance must implement cryptographic mechanisms preventing the unauthorized disclosure of organization-defined information at rest on organization-defined information system components.
SV-276239r1149626_ruleWhen invalid inputs are received, the Azure SQL Managed Instance must behave in a predictable and documented manner that reflects organizational and system objectives.
SV-276240r1149629_ruleAzure SQL Managed Instance must protect against a user falsely repudiating by ensuring only clearly unique Active Directory user accounts can connect to the database.
SV-276241r1149632_ruleAzure SQL Managed Instance must protect against a user falsely repudiating by use of system-versioned tables (Temporal Tables).
SV-276242r1150021_ruleThe Azure SQL Managed Instance must be able to generate audit records when attempts to retrieve privileges/permissions occur.
SV-276243r1149638_ruleAzure SQL Managed Instance must initiate session auditing upon startup.
SV-276244r1149641_ruleAzure SQL Managed Instance default demonstration and sample databases, database objects, and applications must be removed.
SV-276245r1150051_ruleThe Azure SQL Managed Instance audit storage account must be configured to prohibit public access.
SV-276246r1150054_ruleThe Azure SQL Managed Instance must be configured to prohibit or restrict the use of organization-defined functions, ports, protocols, and/or services, as defined in the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL) and vulnerability assessments.
SV-276247r1150045_ruleAzure SQL Managed Instance must uniquely identify and authenticate organizational users (or processes acting on behalf of organizational users).
SV-276248r1150096_ruleAzure SQL Managed Instance must map the PKI-authenticated identity to an associated user account.
SV-276249r1149656_ruleAzure SQL Managed Instance must uniquely identify and authenticate nonorganizational users (or processes acting on behalf of nonorganizational users).
SV-276250r1150065_ruleAzure SQL Managed Instance must separate user functionality (including user interface services) from database management functionality.
SV-276251r1149662_ruleAzure SQL Managed Instance must protect the confidentiality and integrity of all information at rest.
SV-276252r1149665_ruleAzure SQL Managed Instance must be able to allocate audit record storage capacity in accordance with organization-defined audit record storage requirements.
SV-276253r1150067_ruleAzure SQL Managed Instance must provide a warning to appropriate support staff when allocated audit record storage volume reaches 75 percent of maximum audit record storage capacity.
SV-276254r1149671_ruleAzure SQL Managed Instance must generate audit records when security objects are modified.
SV-276255r1149674_ruleAzure SQL Managed Instance must generate audit records when attempts to modify categorized information (e.g., classification levels/security levels) occur.
SV-276256r1149677_ruleAzure SQL Managed Instance must include additional, more detailed, organization-defined information in the audit records for audit events identified by type, location, or subject.
SV-276257r1150023_ruleAzure SQL Managed Instance must generate audit records when attempts to delete security objects occur.
SV-276258r1150024_ruleAzure SQL Managed Instance must generate audit records when attempts to delete categories of information (e.g., classification levels/security levels) occur.
SV-276259r1150012_ruleAzure SQL Managed Instance must generate audit records when logon or connection attempts occur.
SV-276260r1149689_ruleAzure SQL Managed Instance must generate audit records for all privileged activities or other system-level access.
SV-276261r1150068_ruleAzure SQL Managed Instance must generate audit records showing starting and ending time for user access to the database(s).
SV-276262r1149695_ruleAzure SQL Managed Instance must generate audit records when concurrent logons/connections by the same user from different workstations occur.
SV-276263r1150070_ruleAzure SQL Managed Instance must be able to generate audit records when access to objects occur.
SV-276264r1149701_ruleAzure SQL Managed Instance must generate audit records for all direct access to the database(s).
SV-276265r1149704_ruleAzure SQL Managed Instance must store audit records in an immutable blob storage container for an organizationally defined period of time.
SV-276267r1150098_ruleAzure SQL Managed Instance must implement the capability to centrally review and analyze audit records from multiple components within the system using a service such as Azure Log Analytics.
SV-276268r1149713_ruleAzure SQL Server Managed Instance must alert organization-defined personnel or roles upon detection of unauthorized access, modification, or deletion of audit information.
SV-276269r1149716_ruleAzure SQL Managed Instance must prevent the installation of organization-defined software and firmware components without verification that the component has been digitally signed using a certificate recognized and approved by the organization.
SV-276276r1149737_ruleAzure SQL Server Managed Instance must, for password-based authentication, require immediate selection of a new password upon account recovery.
SV-276285r1149764_ruleAzure SQL Managed Instance must limit privileges to change software modules, to include stored procedures, functions, and triggers.
SV-276286r1149767_ruleAzure SQL Managed Instance must limit privileges to change software modules, to include schema ownership.
SV-276287r1149770_ruleThe database master key (DMK) encryption password for Azure SQL Server Managed Instance must meet DOD password complexity requirements.
SV-276288r1150072_ruleThe database master key (DMK) for Azure SQL Server Managed Instance must be encrypted by the service master key (SMK), where a DMK is required and another encryption method has not been specified.
SV-276289r1149776_ruleThe Certificate used for encryption for Azure SQL Managed Instance must be backed up, stored offline and off-site.
SV-276290r1149779_ruleAzure SQL Managed Instance must isolate security functions from nonsecurity functions.
SV-276291r1150014_ruleAzure SQL Managed Instance must check the validity of all data inputs except those specifically identified by the organization.
SV-276293r1149788_ruleAzure SQL Managed Instance must enforce approved authorizations for logical access to information and system resources in accordance with applicable access control policies.
SV-276294r1149791_ruleAzure SQL Managed Instance must protect against a user falsely repudiating by ensuring databases are not in a trust relationship.
SV-276295r1149794_ruleAzure SQL Managed Instance must be configured to generate audit records for DOD-defined auditable events within all DBMS/database components.
SV-276296r1150100_ruleAzure SQL Managed Instance must allow only documented and approved individuals or roles to select which auditable events are to be audited.
SV-276297r1150073_ruleAzure SQL Managed Instance must have an audit defined to track Microsoft Support Operations.
SV-276298r1150102_ruleThe audit information produced by Azure SQL Managed Instance must be protected from unauthorized access.
SV-276299r1149806_ruleAzure SQL Managed Instance must protect its audit configuration from unauthorized access, modification, and deletion.
SV-276300r1149809_ruleAccess to xp_cmdshell must be disabled for Azure SQL Server Managed Instance unless specifically required and approved.
SV-276301r1149812_ruleAccess to CLR code must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved.
SV-276302r1149815_ruleAccess to linked servers must be disabled or restricted for Azure SQL Server Managed Instance, unless specifically required and approved.
SV-276303r1150104_ruleIf DBMS authentication using passwords is employed, Azure SQL Managed Instance must enforce the DOD standards for password complexity and lifetime.
SV-276304r1149821_ruleAzure SQL Server Managed Instance contained databases must use Microsoft Entra or native Windows principals.
SV-276305r1150105_ruleIf passwords are used for authentication, Azure SQL Server Managed Instance must transmit only encrypted representations of passwords.
SV-276306r1150025_ruleAzure SQL Managed Instance must reveal detailed error messages only to the information system security officer (ISSO), information system security manager (ISSM), system administrator (SA), and database administrator (DBA).
SV-276307r1150107_ruleAzure SQL Managed Instance must prevent nonprivileged users from executing privileged functions, to include disabling, circumventing, or altering implemented security safeguards/countermeasures.
SV-276308r1149833_ruleAzure SQL Managed Instance must enforce access restrictions associated with changes to the configuration of the instance.
SV-276309r1149836_ruleAzure Resource Manager must enforce access restrictions associated with changes to the configuration of Azure SQL Managed Instance.
SV-276310r1150016_ruleAzure SQL Managed Instance must produce audit records of its enforcement of access restrictions associated with changes to the configuration of Azure SQL Managed Instance or database(s).
SV-276311r1149842_ruleAzure SQL Managed Instance must maintain a separate execution domain for each executing process.
SV-276312r1150026_ruleAzure SQL Managed Instance must be able to generate audit records when attempts to access security objects occur.
SV-276313r1149848_ruleAzure SQL Managed Instance must generate audit records when attempts to access categorized information (e.g., classification levels/security levels) occur.
SV-276314r1149851_ruleAzure SQL Managed Instance must generate audit records when attempts to add privileges/permissions occur.
SV-276315r1149854_ruleAzure SQL Managed Instance must generate audit records when attempts to modify privileges/permissions occur.
SV-276316r1150060_ruleAzure SQL Managed Instance must generate audit records when attempts to delete privileges/permissions occur.
SV-276317r1150033_ruleThe Azure SQL Managed Instance default [sa] account must be disabled.
SV-276318r1150020_ruleAzure SQL Managed Instance default [sa] account must have its name changed.
SV-276319r1150018_ruleThe Allow Filesystem Enumeration feature must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved.
SV-276320r1149869_ruleThe CLR Strict Security feature must be enabled for Azure SQL Server Managed Instance, unless specifically required and approved.
SV-276321r1149872_ruleThe Hadoop Connectivity feature must be disabled for Azure SQL Server Managed Instance, unless specifically required and approved.
SV-276322r1150027_ruleAzure SQL Server Managed Instance Replication Xps feature must be disabled, unless specifically required and approved.
SV-276323r1149878_ruleWhen using command-line tools with Azure SQL Server Managed Instance, such as SQLCMD, in a mixed-mode authentication environment, users must use a logon method that does not expose the password.
SV-276324r1150034_ruleApplications connecting to Azure SQL Server Managed Instance must obscure feedback of authentication information during the authentication process to protect the information from possible exploitation/use by unauthorized individuals.