Microsoft Defender for Cloud
Architecture and deployment

Deploy vulnerability assessment on your Azure SQL databases (Classic)

In brief

The article now directs administrators to review prerequisites, including enabling Microsoft Defender for Azure SQL, and clarifies that express-configuration vulnerability assessment scans do not require a storage account.

What Defender admins need to know

Review the prerequisites before enabling classic vulnerability assessment; no immediate action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Deploy vulnerability assessment on your Azure SQL databases (Classic)

In this article, you learn how to enable vulnerability assessment classic, so you can find and remediate database vulnerabilities. Before you begin, review the prerequisites, including enabling Microsoft Defender for Azure SQL. We recommend that you enable vulnerability assessment using the express configuration so you aren't dependent on a storage account (generally available for Azure SQL Database, Azure Managed Instance and Azure Synapse Analytics Workspace).

Prerequisites

If your environment still depends on storage-account based scanning, you can enable vulnerability assessment in the classic configuration.

If you have Azure SQL databases with vulnerability assessment enabled in the classic configuration, you can enable the express configuration so that assessmentsvulnerability assessment scans don't require a storage account.

If you have Azure SQL databases with vulnerability assessment disabled, you can enable vulnerability assessment with the classic configuration.