Audit Logs

Full Of Tradition 0 Reputation points
2025-10-15T12:20:48.8433333+00:00

Hello!

Beyond the configurable logs available in the portal, cli... if a severe incident is suspected, can Microsoft obtain more detailed information about the events and the associated IP addresses?

Thank you!

Azure SQL Database
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Pratyush Vashistha 4,255 Reputation points Microsoft External Staff Moderator
    2025-10-16T04:43:02.9033333+00:00

    Hello Full Of Tradition,

    Thanks for your question on the Microsoft QnA portal!

    If you're referring to Azure SQL Database and suspect a severe incident—such as unauthorized access or anomalous activity—Microsoft can, under certain support scenarios (like during an active support case or security investigation), access additional diagnostic telemetry beyond what’s exposed in the portal or CLI. This may include internal logs with more granular details, including source IP addresses tied to connections or operations, especially if the activity triggered platform-level alerts or was captured by Microsoft’s internal monitoring systems.

    That said, customer-accessible logs like Azure SQL Auditing, Diagnostic Settings (sent to Log Analytics, Event Hub, or Storage), and Microsoft Defender for Cloud alerts already provide rich information—including client IPs, query texts, and login events—when properly configured. If those aren’t enabled, historical visibility will be limited.

    To help tailor the answer better:

    • Are you currently experiencing a suspected breach or anomalous behavior in your Azure SQL Database?
    • Have you already enabled Auditing or Diagnostic Settings for your database?

    For reference, here’s how to configure auditing (which captures IP addresses): https://free.blessedness.top/en-us/azure/azure-sql/database/auditing-overview

    And here’s how to set up diagnostic logs: https://free.blessedness.top/en-us/azure/azure-sql/database/metrics-diagnostic-telemetry-logging-streaming-export-configure

    Please "Accept as Answer" if the answer provided is useful, so that you can help others in the community looking for remediation for similar issues.

    Thanks

    Pratyush

    User's image


Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.