Skip to content

5571927: [sql] Update the Azure-cli auditing APIs to support selective fields auditing. - #34166

Open
janardhanrh wants to merge 1 commit into
Azure:devfrom
janardhanrh:selective_fields_support
Open

janardhanrh wants to merge 1 commit into
Azure:devfrom
janardhanrh:selective_fields_support

Conversation

@janardhanrh

Copy link
Copy Markdown

Update the Azure-cli Auditing APIs to support selective fields auditing. to support this feature, a new parameter reuiredFields is introduced in the audit-policy update APIs which accepts the list of required fields to be set in the audit record.

The update APIs include
az sql server audit-policy update
az sql db audit-policy update
az sql server audit-policy show
az sql db audit-policy show

The update APIs take an additional parameter --requiredFields which is the list of field names that are required in the audit record.

Related command
sql db audit-policy update
sql server audit-policy update
sql db audit-policy show
sql server audit-policy show

Description
Update the Azure-cli Auditing APIs to support selective fields auditing. To support this feature, a new parameter requiredFields is introduced in the audit-policy update APIs which accepts the list of required fields to be set in the audit record.
This parameter enables the user to specify the fields that need to be configured to be present in the audit records.

Testing Guide
Test steps below configure auditing for an Azure SQL database and server to enable selective fields auditing:
Server-level auditing:

(env) Q:\src\azure-cli>az sql server audit-policy update --name jrh-final-validation -g jhungund_rg_new --state Enabled --actions BATCH_COMPLETED_GROUP --lats Enabled --lawri "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.OperationalInsights/workspaces/jhungund-la" --required-fields statement action_id action_name database_name
(env) Q:\src\azure-cli>az sql server audit-policy show --name jrh-final-validation -g jhungund_rg_new
{
"auditActionsAndGroups": [
"BATCH_COMPLETED_GROUP"
],
"blobStorageTargetState": "Disabled",
"eventHubTargetState": "Disabled",
"id": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.Sql/servers/jrh-final-validation/auditingSettings/Default",
"isAzureMonitorTargetEnabled": true,
"isDevopsAuditEnabled": null,
"isManagedIdentityInUse": false,
"isStorageSecondaryKeyInUse": null,
"logAnalyticsTargetState": "Enabled",
"logAnalyticsWorkspaceResourceId": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.OperationalInsights/workspaces/jhungund-la",
"name": "Default",
"queueDelayMs": null,
"requiredFields": [
"statement",
"action_id",
"action_name",
"database_name"
],
"resourceGroup": "jhungund_rg_new",
"retentionDays": 0,
"state": "Enabled",
"storageAccountAccessKey": null,
"storageAccountSubscriptionId": "00000000-0000-0000-0000-000000000000",
"storageEndpoint": "",
"type": "Microsoft.Sql/servers/auditingSettings"
}

(env) Q:\src\azure-cli>az sql server audit-policy show --name jrh-final-validation -g jhungund_rg_new
{
"auditActionsAndGroups": [
"BATCH_COMPLETED_GROUP"
],
"blobStorageTargetState": "Disabled",
"eventHubTargetState": "Disabled",
"id": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.Sql/servers/jrh-final-validation/auditingSettings/Default",
"isAzureMonitorTargetEnabled": true,
"isDevopsAuditEnabled": null,
"isManagedIdentityInUse": false,
"isStorageSecondaryKeyInUse": null,
"logAnalyticsTargetState": "Enabled",
"logAnalyticsWorkspaceResourceId": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.OperationalInsights/workspaces/jhungund-la",
"name": "Default",
"queueDelayMs": null,
"requiredFields": [
"statement",
"action_id",
"action_name",
"database_name"
],
"resourceGroup": "jhungund_rg_new",
"retentionDays": 0,
"state": "Enabled",
"storageAccountAccessKey": null,
"storageAccountSubscriptionId": "00000000-0000-0000-0000-000000000000",
"storageEndpoint": "",
"type": "Microsoft.Sql/servers/auditingSettings"
}

DB-level auditing:

(env) Q:\src\azure-cli>az sql db audit-policy update --server jrh-final-validation --name jrhDB -g jhungund_rg_new --state Enabled --actions BATCH_COMPLETED_GROUP --lats Enabled --lawri "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.OperationalInsights/workspaces/jhungund-la" --required-fields statement action_id action_name database_name
{
"auditActionsAndGroups": [
"BATCH_COMPLETED_GROUP"
],
"id": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.Sql/servers/jrh-final-validation/databases/jrhDB/auditingSettings/Default",
"isAzureMonitorTargetEnabled": true,
"isManagedIdentityInUse": false,
"isStorageSecondaryKeyInUse": false,
"kind": null,
"name": "Default",
"queueDelayMs": null,
"requiredFields": [
"statement",
"action_id",
"action_name",
"database_name"
],
"resourceGroup": "jhungund_rg_new",
"retentionDays": 0,
"state": "Enabled",
"storageAccountAccessKey": null,
"storageAccountSubscriptionId": "00000000-0000-0000-0000-000000000000",
"storageEndpoint": null,
"type": "Microsoft.Sql/servers/databases/auditingSettings"
}

(env) Q:\src\azure-cli>az sql db audit-policy show --name jrhDB --server jrh-final-validation -g jhungund_rg_new
{
"auditActionsAndGroups": [
"BATCH_COMPLETED_GROUP"
],
"blobStorageTargetState": "Disabled",
"eventHubTargetState": "Disabled",
"id": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.Sql/servers/jrh-final-validation/databases/jrhDB/auditingSettings/Default",
"isAzureMonitorTargetEnabled": true,
"isManagedIdentityInUse": false,
"isStorageSecondaryKeyInUse": null,
"kind": null,
"logAnalyticsTargetState": "Enabled",
"logAnalyticsWorkspaceResourceId": "/subscriptions/857355f0-57d5-4754-b91a-0393dbff9afc/resourceGroups/jhungund_rg_new/providers/Microsoft.OperationalInsights/workspaces/jhungund-la",
"name": "Default",
"queueDelayMs": null,
"requiredFields": [
"statement",
"action_id",
"action_name",
"database_name"
],
"resourceGroup": "jhungund_rg_new",
"retentionDays": 0,
"state": "Enabled",
"storageAccountAccessKey": null,
"storageAccountSubscriptionId": "00000000-0000-0000-0000-000000000000",
"storageEndpoint": "",
"type": "Microsoft.Sql/servers/databases/auditingSettings"
}

History Notes

…ds auditing.

Update the Azure-cli Auditing APIs to support selective fields auditing.
to support this feature, a new parameter reuiredFields is introduced in
the audit-policy update APIs which accepts the list of required fields
to be set in the audit record.

The update APIs include
az sql server audit-policy update
az sql db audit-policy update
az sql server audit-policy show
az sql db audit-policy show

The update APIs take an additional parameter --requiredFields which is
the list of field names that are required in the audit record.
@janardhanrh
janardhanrh requested a review from a team as a code owner October 5, 2026 06:45
Copilot AI balanced review requested due to automatic review settings October 5, 2026 06:45
@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
There may be pipelines that require an authorized user to comment /azp run to run.

Copilot AI left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Copilot review overview

🟡 Changes recommended

Generic updates can discard existing required fields, and unchanged scenario recordings will fail against the new API version.

Review effort: Balanced
Findings: 1 High severity · 2 Medium severity

Open (3)
What changed in this PR

Adds selective-field auditing support for SQL database and server audit policies.

Changes:

  • Adds --required-fields parameters and help examples.
  • Uses the preview auditing API to preserve unsupported SDK fields.
  • Adds focused unit tests for serialization, routing, and validation.
File Description
sql/​tests/​latest/​test_sql_audit_policy.py Tests selective-field auditing behavior.
sql/​custom.py Implements preview API handling and validation.
sql/​commands.py Registers custom audit-policy setters.
sql/​_params.py Defines the new CLI parameter.
sql/​_help.py Adds usage examples.

💡 Add a code-review agent skill or configure MCP servers for context-aware, tailored reviews. Learn more in the docs.

# sql db audit-policy & threat-policy
#####

_AUDITING_API_VERSION = '2026-08-01-preview'
Comment on lines +2376 to +2379
def db_audit_policy_set(cmd, client, resource_group_name, server_name, database_name, parameters):
if hasattr(parameters, 'required_fields'):
return _set_audit_policy_preview(
cmd, client, parameters, resource_group_name, server_name, database_name)
Comment on lines +2387 to +2390
def server_audit_policy_set(cmd, client, resource_group_name, server_name, parameters, no_wait=False):
if hasattr(parameters, 'required_fields'):
return _set_audit_policy_preview(
cmd, client, parameters, resource_group_name, server_name, no_wait=no_wait)
@a0x1ab

Copy link
Copy Markdown
Member

/azp run

@azure-pipelines

Copy link
Copy Markdown
Azure Pipelines:
Successfully started running 3 pipeline(s).

@yonzhan

Copy link
Copy Markdown
Collaborator

Please fix CI issues

This branch has not been deployed

No deployments
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Projects

None yet

Development

Successfully merging this pull request may close these issues.

5 participants