Ensure that Microsoft Defender for Cloud is enabled for your Azure SQL database servers. Defender for Cloud for SQL database servers includes functionalities for discovering and mitigating potential database vulnerabilities, and detecting anomalous activities that could indicate a threat to your SQL databases. Defender for Cloud protects Azure SQL managed database instances and dedicated SQL pools in Azure Synapse.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
By default, Microsoft Defender for Cloud is disabled for all your SQL database servers. Defender for Cloud monitors your SQL database servers for threats such as SQL injection, brute-force attacks, and privilege abuse. The security service provides action-oriented security alerts with details of the suspicious activity and guidance on how to mitigate the security threats.
Audit
To determine if the Microsoft Defender for Cloud security service is enabled for your Azure SQL database servers, perform the following operations:
Remediation / Resolution
To enable Microsoft Defender for Cloud for your Azure SQL database servers, perform the following operations:
Note: Turning on Defender for Cloud for the specified resource type (i.e. SQL databases) incurs an additional cost per resource.References
- Azure Official Documentation
- Microsoft Defender for Cloud documentation
- What is Microsoft Defender for Cloud?
- Microsoft Defender for Cloud pricing
- Microsoft Defender for Cloud's enhanced security features
- Introduction to Microsoft Defender for SQL
- CIS Microsoft Azure Foundations
- Azure Command Line Interface (CLI) Documentation
- az
- az account get-access-token