More Info:

Ensure that Microsoft Defender for Cloud is enabled for SQL database servers.

Risk Level

High

Address

Security, Operational Maturity

Compliance Standards

CISAZURE, CBP

Triage and Remediation

Remediation

To remediate the misconfiguration of enabling Microsoft Defender for Cloud for Azure SQL Database Servers in Azure using Azure console, please follow the below steps:

  1. Login to the Azure portal (https://portal.azure.com/)
  2. Navigate to the Azure SQL Database Server for which you want to enable Microsoft Defender for Cloud
  3. Click on the “Security” tab on the left-hand side of the screen
  4. Under the “Threat detection” section, click on “Advanced Threat Protection”
  5. Click on “Enable” to enable Microsoft Defender for Cloud for the selected SQL Database Server
  6. A new window will open to configure the settings for Microsoft Defender for Cloud. You can choose the settings as per your requirement and click on “Save” once you are done.
  7. Microsoft Defender for Cloud will now be enabled for the selected Azure SQL Database Server.

Note: Microsoft Defender for Cloud is a paid service, so you will need to have a valid subscription to enable it.