> For the complete documentation index, see [llms.txt](https://cortex-docs.paloaltonetworks.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-25.md).

# Azure SQL database Transparent Data Encryption (TDE) encryption disabled misconfiguration detected i

## Rule Details

|                        |                                      |
| ---------------------- | ------------------------------------ |
| Cortex AppSec Rule ID  | APPSEC2\_AZURE\_25                   |
| Category - Subcategory | Storage - Encryption                 |
| Provider               | AZURE                                |
| Severity               | LOW                                  |
| Framework              | Terraform, Terraform Plan            |
| Mapped CSPM/KSPM Rule  | 5a772daf-17c0-4a20-a689-2b3ab3f33779 |

## Impact

This rule is checking to make sure that Transparent Data Encryption (TDE) is enabled for Azure SQL databases. TDE is a security feature that provides real-time encryption and decryption of data and log files to protect information at rest. If TDE is not enabled, the data stored in the Azure SQL Database could be at risk for unauthorized access or data breaches. Therefore, enabling TDE helps in maintaining the confidentiality and integrity of the data by ensuring that it can only be accessed, read or modified by authorized entities.

## How to Fix

*Resource:* azurerm\_mssql\_database

* *Arguments:* transparent\_data\_encryption\_enabled

To fix the issue of Transparent Data Encryption (TDE) not being enabled on your Azure SQL database, you just need to set the argument `transparent_data_encryption` to `enabled` in your Terraform script.

Secure code example:

## The above Terraform code is secure based on the rule because it enables Transparent Data Encryption on the database by setting `transparent_data_encryption_enabled` to `true`. This means data stored on the SQL server will be automatically encrypted, helping to protect against the threat of malicious activity, ensuring data privacy, and meeting regulatory compliance. \[source,go]

## resource "azurerm\_mssql\_database" "tde" { ... transparent\_data\_encryption\_enabled = true ... }


---

# Agent Instructions
This documentation is published with GitBook. GitBook is the documentation platform designed so that both humans and AI agents can read, navigate, and reason over technical content effectively. Learn more at gitbook.com.

## Querying This Documentation
If you need additional information that is not directly available in this page, you can query the documentation dynamically by asking a question.

Perform an HTTP GET request on the current page URL with the `ask` query parameter, and the optional `goal` query parameter:

```
GET https://cortex-docs.paloaltonetworks.com/appsec-rules/iac-security/storage/appsec2-azure-25.md?ask=<question>&goal=<endgoal>
```

`ask` is the immediate question: it should be specific, self-contained, and written in natural language.
`goal` is optional and describes the broader end goal you are ultimately trying to accomplish on behalf of the user. GitBook uses it to tailor the answer towards what is most useful for that goal.

The response will contain a direct answer to the question and relevant excerpts and sources from the documentation.

Use this mechanism when the answer is not explicitly present in the current page, you need clarification or additional context, or you want to retrieve related documentation sections.
