Skip to content

[Policy]: Add "Azure SQL Database should have Microsoft Entra-only authentication enabled" to "Enforce-Guardrails-SQL" #2030

@bmuellem

Description

@bmuellem

Policy Definition or Initiative

Definition

Built-in/Custom

Built-in

Built-in policy definition or initiative ID

b3a22bc9-66de-45fb-98fa-00f5df42f41a

Custom policy definition or initiative description

N/A

Scope

Intermediate Root

Default Assignment

  • Yes

Comments/thoughts

The Enforce-Guardrails-SQL initiative currently only includes Azure SQL Database should have Microsoft Entra-only authentication enabled during creation. App teams are thus able to disable Entra-only authentication after initial deployment.

Adding the policy Azure SQL Database should have Microsoft Entra-only authentication enabled would close this loophole.

BTW the same situation applies to the initiative "Enforce-Guardrails-CosmosDb", so maybe this is by design?

Thanks for looking into it!

Metadata

Metadata

Assignees

Labels

Type

No type

Projects

No projects

Milestone

No milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions