Ensure that your Amazon SQL database servers are configured with the email addresses of the concerned data owners, admins or stakeholders in order to receive Vulnerability Assessment (VA) scan reports and alerts for critical events. This setting is only available for SQL servers using the classic SQL Vulnerability Assessment configuration. For new, express configuration, email notifications are enabled by default and cannot be customized.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
optimisation
After configuring email addresses, Microsoft Defender for SQL will send Vulnerability Assessment (VA) scan reports and alerts to the specified addresses. This can help your security team to reduce the time required for identifying risks and help take corrective measures.
Audit
To determine if there are email addresses configured to receive Vulnerability Assessment (VA) scan reports and alerts for SQL database servers, perform the following operations:
Remediation / Resolution
To configure one or more email addresses for receiving Vulnerability Assessment (VA) scan reports and alerts from your Azure SQL database servers with classic VA configuration, perform the following operations:
References
- Azure Official Documentation
- SQL vulnerability assessment helps you identify database vulnerabilities
- Manage vulnerability findings in your Azure SQL databases
- Azure PowerShell Documentation
- Get-AzSqlServer
- Get-AzSqlServerVulnerabilityAssessmentSetting
- Update-AzSqlServerVulnerabilityAssessmentSetting