TF 0242 - SymbioticSec/Symbiotic-Vulnerability-Database GitHub Wiki

Security threat alerts go to subcription owners and co-administrators

Property Value
Language terraform
Severity low
Service database
Provider Azure

Description

The security alert policy for Azure SQL servers is not configured to notify subscription owners or administrators via email when security threats are detected. As a result, critical alerts may not reach those responsible for timely incident response.

Impact

If administrators are not promptly alerted to security threats, there may be delays in detecting and responding to potential attacks or breaches, increasing the risk of data loss, service disruption, or unauthorized access.

Resolution

Enable email to subscription owners