Ensure default connection policy is not in use for Azure SQL Server

LOW

Description

Azure SQL Server instances use default connection policy, this goes against standard security compliance requirements.

Remediation

In Azure Console -

  1. Open the Azure Portal and go to SQL servers.
  2. Choose the SQL server you wish to edit.
  3. Under Networking, Under Connectivity, set Connection policy as Redirect.
  4. Select Save

In Terraform -

  1. In the azurerm_sql_server resource, set connection_policy to Redirect.

References:
https://learn.microsoft.com/en-us/azure/azure-sql/database/connectivity-settings?view=azuresql&tabs=azure-portal
https://registry.terraform.io/providers/hashicorp/azurerm/latest/docs/resources/sql_server

Policy Details

Rule Reference ID: AC_AZURE_0258
CSP: Azure
Remediation Available: Yes
Resource Category: Database
Resource Type: SQL Server

Frameworks