How to turn on Auditing & Threat Detection for Azure SQL Database in ARM Template?

Viewed 3116

Azure SQL Database Threat Detection feature has been in General Preview since November 2015.

https://azure.microsoft.com/en-us/blog/threat-detection-public-preview/

However, I could not find out how can one turn on this feature and its dependency (Azure SQL Database Auditing) in the ARM template, neither in the Azure Quickstart Templates nor Azure Resource Manager Schema GitHubs links.

azure-quickstart-templates

azure-resource-manager-schemas

Appreciate if anyone who knows can answer on this. Thanks very much.

3 Answers

The answer from Jack Zeng was close, but (at this point in time) you need auditingSettings to point to blob storage, since security alerting doesn't work with table storage. So add the following auditingSettings and securityAlertPolicies as child resources of the Microsoft.Sql/servers resource.

    {
        "$schema": "https://schema.management.azure.com/schemas/2015-01-01/deploymentTemplate.json#",
        "contentVersion": "1.0.0.0",
        "parameters": {},
        "variables": {},
        "resources": [
            {
                "name": "[parameters('sqlserverName')]",
                "type": "Microsoft.Sql/servers",
                "location": "[resourceGroup().location]",
                "apiVersion": "2014-04-01-preview",
                "properties": {},
                "resources": [
                    {
                        "apiVersion": "2015-05-01-preview",
                        "type": "auditingSettings",
                        "name": "Default",
                        "dependsOn": [
                            "[parameters('sqlserverName')]",
                            "[concat('Microsoft.Storage/storageAccounts/', parameters('storageAccountName'))]"
                        ],
                        "properties": {
                            "State": "Enabled",
                            "storageEndpoint": "[concat('https://', parameters('storageAccountName'), '.blob.core.windows.net/')]",
                            "storageAccountAccessKey": "[listKeys(resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName')), providers('Microsoft.Storage', 'storageAccounts').apiVersions[0]).keys[0].value]",
                            "storageAccountSubscriptionId": "[subscription().subscriptionId]",
                            "eventTypesToAudit": "All"
                        }
                    },
                    {
                        "apiVersion": "2015-05-01-preview",
                        "type": "securityAlertPolicies",
                        "name": "DefaultSecurityAlert",
                        "dependsOn": [
                            "[parameters('sqlserverName')]",
                            "[concat('Microsoft.Storage/storageAccounts/', parameters('storageAccountName'))]",
                            "[concat('Microsoft.Sql/servers/', parameters('sqlserverName'), '/auditingSettings/Default')]"
                        ],
                        "properties": {
                            "state": "Enabled",
                            "disabledAlerts": "",
                            "emailAddresses": "[parameters('securityAlertPolicyEmails')]",
                            "emailAccountAdmins": "Enabled",
                            "retentionDays": "10",
                            "storageEndpoint": "[concat('https://', parameters('storageAccountName'), '.blob.core.windows.net/')]",
                            "storageAccountAccessKey": "[listKeys(resourceId('Microsoft.Storage/storageAccounts', parameters('storageAccountName')), providers('Microsoft.Storage', 'storageAccounts').apiVersions[0]).keys[0].value]"
                        }
                    }
                ]
            }
        ]
    }

Sources:

The blob storage auditing config is from here: https://blogs.msdn.microsoft.com/azuresqldbsupport/2017/01/11/arm-template-turning-on-blob-auditing/

The threat detection resource config is from here (note that the storage auditing config from this example didn't work for me): https://blogs.msdn.microsoft.com/azuresqldbsupport/2017/01/11/arm-template-to-deploy-server-with-auditing-and-threat-detection-turned-on/

Related