Skip to main content

Posts

Showing posts from November, 2018

Enable Audit on Azure SQL Server (for all Databases)

To enable Azure SQL Server audit: - in Azure Portal Enable Audit for the SQL Server (and select the destination, e.g. Storage Account) - Start the shell from within the Portal - run this command (replace the names in yellow with your names): Set-AzureRmSqlServerAuditing -State Enabled -ResourceGroupName " rg-bdocloudops " -ServerName " bdocloudops " -AuditActionGroup APPLICATION_ROLE_CHANGE_PASSWORD_GROUP, DATABASE_OBJECT_CHANGE_GROUP, DATABASE_OBJECT_OWNERSHIP_CHANGE_GROUP, DATABASE_OBJECT_PERMISSION_CHANGE_GROUP, DATABASE_PERMISSION_CHANGE_GROUP, DATABASE_PRINCIPAL_CHANGE_GROUP, DATABASE_PRINCIPAL_IMPERSONATION_GROUP, DATABASE_ROLE_MEMBER_CHANGE_GROUP, FAILED_DATABASE_AUTHENTICATION_GROUP, SCHEMA_OBJECT_CHANGE_GROUP, SCHEMA_OBJECT_OWNERSHIP_CHANGE_GROUP, SCHEMA_OBJECT_PERMISSION_CHANGE_GROUP, USER_CHANGE_PASSWORD_GROUP, DATABASE_OPERATION_GROUP Check if the last group (DATABASE_OPERATION_GROUP) causes too many events and