Edit

Auditing policy in Azure Synapse Analytics

Tip

Microsoft Fabric Data Warehouse is an enterprise scale relational warehouse on a data lake foundation, with a future-ready architecture, built-in AI, and new features. If you're new to data warehousing, start with Fabric Data Warehouse. Existing dedicated SQL pool workloads can upgrade to Fabric to access new capabilities across data science, real-time analytics, and reporting.

You can define an auditing policy for an individual database or as the default policy for a logical server.

Define server-level and database-level auditing policies

Define an auditing policy for a specific database or as a default server policy in Azure:

  • A server-level policy applies to all existing and newly created databases on the server.

  • If you enable server-level auditing, it applies to a database regardless of that database's auditing setting.

  • A database-level policy doesn't override the server-level policy. If both are enabled, the database is audited twice.

  • Enabling auditing on the database in addition to enabling auditing on the server doesn't override or change any of the settings of the server auditing. Both audits exist side by side. In other words, the database is audited twice in parallel; once by the server policy and once by the database policy.

    Note

    Avoid enabling both server auditing and database blob auditing together, unless:

    • You want to use a different storage account, retention period, or Log Analytics Workspace for a specific database.
    • You want to audit event types or categories for a specific database that differ from the rest of the databases on the server. For example, you might have table inserts that need to be audited only for a specific database.

    Otherwise, enable only server-level auditing and leave the database-level auditing disabled for all databases.