Permissions
The Azure CIS v2.0.0 - Section 4 - Database Services policy pack requires 20 permissions:
Application.Read.All
Group.Read.All
User.Read.All
microsoft.dbformysql/flexibleservers/configurations/write
microsoft.dbforpostgresql/flexibleservers/configurations/write
microsoft.dbforpostgresql/servers/configurations/write
microsoft.dbforpostgresql/servers/delete
microsoft.dbforpostgresql/servers/write
microsoft.documentdb/databaseaccounts/write
microsoft.sql/servers/administrators/delete
microsoft.sql/servers/administrators/write
microsoft.sql/servers/auditingsettings/write
microsoft.sql/servers/azureadonlyauthentications/delete
microsoft.sql/servers/azureadonlyauthentications/write
microsoft.sql/servers/databases/transparentdataencryption/write
microsoft.sql/servers/firewallrules/delete
microsoft.sql/servers/securityalertpolicies/write
microsoft.sql/servers/vulnerabilityassessments/write
microsoft.storage/storageaccounts/listkeys/action
microsoft.storage/storageaccounts/read