Ensure that Microsoft Defender for Cloud is enabled for open-source relational databases such as Azure Database for PostgreSQL, Azure Database for MySQL, and Azure Database for MariaDB. Microsoft Defender for Cloud for open-source relational databases includes functionalities for discovering and mitigating potential database vulnerabilities, and detecting anomalous activities that could indicate a threat to your relational databases.
By default, Microsoft Defender for Cloud is disabled for all open-source relational databases. The security service monitors PostgreSQL, MySQL, and MariaDB database servers for threats such as SQL injection, brute-force attacks, and privilege abuse. Microsoft Defender for Cloud provides action-oriented security alerts with details of the suspicious activity and guidance on how to mitigate the security threats.
Audit
To determine if Microsoft Defender for Cloud is enabled for your Azure relational databases, perform the following operations:
Remediation / Resolution
To enable Microsoft Defender for Cloud for the supported open-source relational databases, perform the following operations:
Turning on Microsoft Defender for Cloud for open-source relational databases incurs an additional cost per resource management operation.References
- Azure Official Documentation
- Microsoft Defender for Cloud documentation
- Microsoft Defender for Cloud overview
- Microsoft Defender for Cloud pricing
- Azure PowerShell Documentation
- az account list
- az account set
- az security pricing list
- az security pricing create