Edit

Write audit logs to a storage account behind a virtual network and firewall in Azure Synapse Analytics

Tip

Microsoft Fabric Data Warehouse is an enterprise scale relational warehouse on a data lake foundation, with a future-ready architecture, built-in AI, and new features. If you're new to data warehousing, start with Fabric Data Warehouse. Existing dedicated SQL pool workloads can upgrade to Fabric to access new capabilities across data science, real-time analytics, and reporting.

Azure Synapse Analytics auditing supports writing database events to an Azure Storage account behind a virtual network or firewall.

Important

When a storage account is behind a virtual network or firewall, you must use managed identity authentication (Storage Blob Data Contributor role), not storage access keys. The Azure portal configures this authentication automatically when you save your auditing settings. If you configure auditing by using REST API or PowerShell, don't specify a storageAccountAccessKey. The server's managed identity authenticates to the storage account instead.

Background

Azure Virtual Network (VNet) is the fundamental building block for your private network in Azure. VNet enables many types of Azure resources, such as Azure Virtual Machines (VM), to securely communicate with each other, the internet, and on-premises networks. VNet is similar to a traditional network in your own data center, but it brings additional benefits of Azure infrastructure such as scale, availability, and isolation.

To learn more about the VNet concepts, best practices, and more, see What is Azure Virtual Network.

To learn more about how to create a virtual network, see Quickstart: Create a virtual network using the Azure portal.

Prerequisites

  • Use a general-purpose v2 storage account or a premium BlockBlobStorage account. To update an older account, see Upgrade to a general-purpose v2 storage account.
  • Premium storage with BlockBlobStorage is supported.
  • Place the storage account in the same tenant and region as the Synapse SQL server.
  • On the storage account networking page, enable Allow Azure services on the trusted services list to access this storage account.
  • Grant the server's system-assigned managed identity the Storage Blob Data Contributor role on the storage account. You need Microsoft.Authorization/roleAssignments/write permission to create the role assignment.

If you enabled auditing before the storage account was behind a firewall, save the auditing settings again so that audit logs can resume writing to the account.

Configure auditing in the Azure portal

  1. In the Azure portal, open the Synapse SQL server or SQL pool resource.

  2. Under Security, select Auditing, and then enable auditing.

  3. Select Storage, and choose the storage account that meets the prerequisites.

  4. Open Storage details and verify that the portal indicates that managed identity authentication is used.

    Note

    If the selected storage account is behind a virtual network, you see the following message:

    You selected a storage account that's behind a firewall or in a virtual network. Using this storage requires to enable 'Allow trusted Microsoft services to access this storage account' on the storage account and creates a server managed identity with 'storage blob data contributor' RBAC.

    If you don't see this message, the storage account isn't behind a virtual network.

  5. Select a retention period, and then save the auditing settings.

When you save the settings, the portal grants the system-assigned identity the required storage role if you have permission to create role assignments.

Configure auditing programmatically

When you configure auditing through PowerShell or the REST API, don't supply a storage account access key. Omitting the key causes the audit policy to use the server's system-assigned managed identity.

For details about identity behavior, see Auditing using managed identity in Azure Synapse Analytics.