Book Image

Professional Azure SQL Managed Database Administration - Third Edition

By : Ahmad Osama, Shashikant Shakya
Book Image

Professional Azure SQL Managed Database Administration - Third Edition

By: Ahmad Osama, Shashikant Shakya

Overview of this book

Despite being the cloud version of SQL Server, Azure SQL Database and Azure SQL Managed Instance stands out in various aspects when it comes to management, maintenance, and administration. Updated with the latest Azure features, Professional Azure SQL Managed Database Administration continues to be a comprehensive guide for becoming proficient in data management. The book begins by introducing you to the Azure SQL managed databases (Azure SQL Database and Azure SQL Managed Instance), explaining their architecture, and how they differ from an on-premises SQL server. You will then learn how to perform common tasks, such as migrating, backing up, and restoring a SQL Server database to an Azure database. As you progress, you will study how you can save costs and manage and scale multiple SQL databases using elastic pools. You will also implement a disaster recovery solution using standard and active geo-replication. Finally, you will explore the monitoring and tuning of databases, the key features of databases, and the phenomenon of app modernization. By the end of this book, you will have mastered the key aspects of an Azure SQL database and Azure SQL managed instance, including migration, backup restorations, performance optimization, high availability, and disaster recovery.
Table of Contents (14 chapters)
13
Index

Activity: Audit COPY_ONLY backup events on SQL Managed Instance using audit logs

In the previous activity, we saw the steps to enable a server audit for SQL Managed Instance. In this activity, we will use the server audit to track user-initiated COPY_ONLY database backups.

SQL Managed Instance has the ability to take database backups with the COPY_ONLY option on Azure Blob Storage. By default, all the databases are protected using a service-managed Transparent Data Encryption (TDE) key and COPY_ONLY backups are not allowed.

But there could be scenarios where a user who has higher access on an instance can disable service-managed TDE and take a COPY_ONLY backup of a database. You can track these events using audit logs.

Steps to configure an audit for backup and restore events

We have already seen how to configure a storage container for audit logs in a previous demo. Here we will create a server audit specification to track backup events.

You can skip the following steps...