Azure Database Services Benchmark

Enable Infrastructure Double Encryption on Azure PostgreSQL Single Server for Enhanced Data Protection
Profile Applicability: Level 1 Description:  Enabling Infrastructure double encryption adds an additional layer of encryption to PostgreSQL servers, s...
Mon, 19 May, 2025 at 6:21 AM
Enable SQL Server Auditing on Azure to Monitor and Secure Database Activities
Profile Applicability: Level 1 Description:  Auditing for SQL servers tracks database events and writes them to an audit log in a designated storage a...
Mon, 19 May, 2025 at 6:23 AM
Prevent Azure SQL Database Ingress from 0.0.0.0/0 to Restrict Open Internet Access
Profile Applicability: Level 1 Description:  This check ensures that no Azure SQL Databases have firewall rules that allow ingress from 0.0.0.0/0, wh...
Mon, 19 May, 2025 at 6:26 AM
Enable Transparent Data Encryption with Customer-Managed Keys on Azure SQL Servers for Enhanced Data Security
Profile Applicability: Level 2 Description:  Transparent Data Encryption (TDE) with Customer-managed key support provides increased control over the ...
Mon, 19 May, 2025 at 6:28 AM
Configure Microsoft Entra Authentication for Azure SQL Servers to Enable Centralized Identity Management
Profile Applicability: Level 1 Description: Microsoft Entra authentication allows SQL Server to authenticate users based on identities stored in Micr...
Mon, 19 May, 2025 at 6:30 AM
Enable Transparent Data Encryption (TDE) on Azure SQL Databases to Protect Data at Rest
Profile Applicability: Level 1 Description:  Transparent Data Encryption (TDE) should be enabled on all SQL databases. TDE helps protect against mali...
Mon, 19 May, 2025 at 6:32 AM
Configure Audit Log Retention Greater Than 90 Days on Azure SQL Servers for Compliance and Forensics
Profile Applicability: Level 1 Description:  Audit retention should be configured to retain logs for more than 90 days. This setting ensures that aud...
Mon, 19 May, 2025 at 6:34 AM
Disable Public Network Access to Secure Azure Databases and Resources
Profile Applicability: Level 1 Description:  Disabling Public Network Access ensures that the database or resource is not accessible from public IP a...
Mon, 19 May, 2025 at 6:37 AM