Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Tip
Microsoft Fabric Data Warehouse is an enterprise scale relational warehouse on a data lake foundation, with a future-ready architecture, built-in AI, and new features. If you're new to data warehousing, start with Fabric Data Warehouse. Existing dedicated SQL pool workloads can upgrade to Fabric to access new capabilities across data science, real-time analytics, and reporting.
Here are some recommendations for using Azure Synapse Analytics SQL Auditing in production environments.
Storage key regeneration
In production, you're likely to refresh your storage keys periodically. When writing audit logs to Azure storage, you need to resave your auditing policy when refreshing your keys. The process is as follows:
Open Advanced properties under Storage. In the Storage Access Key section, select Secondary. Then select Save at the top of the auditing configuration page.
Go to the Azure Storage account that holds the key, and navigate to Access keys. Select the refresh icon button to regenerate the primary access key.
Go back to the auditing configuration page, switch the storage access key from secondary to primary, and then select OK. Then select Save at the top of the auditing configuration page.
Go back to the storage configuration page and regenerate the secondary access key (in preparation for the next key's refresh cycle).
Storage account encrypted with Azure Key Vault
When you configure auditing with a storage account as the target, which is encrypted using a key vault behind a firewall, you must set up an access policy for the key vault. Navigate to the Azure Key Vault access policy, add a new policy with the necessary key permissions, enable the unwrap key option, and select the appropriate principal (such as the storage account) to grant access.