Microsoft Defender for Cloud
Cloud and workloads

Enable Microsoft Defender for SQL Servers on Machines

In brief

The article now uses updated metadata, clarifies that administrators should verify all machines are protected before enabling the plan, and adds a named anchor with a pluralized “Next steps” heading.

What Defender admins need to know

The clearer verification wording and anchor improve setup guidance and linking; no product configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you enable the plan, make sure the following prerequisites are met:

  • Subscription permissions: To deploy the plan on a subscription, including Azure Policy, you need Subscription Owner permissions.

  • SQL Server instance permissions: SQL Server service accounts must be a member of the sysadmin fixed server role on each SQL Server instance, which is the default setting. Learn more about the SQL Server service account requirement.

Verify that your machines are protected

Depending on your environment, it can take a few hours to discover and protect SQL instances. As a final step, you should verify that all machines are protected.

Next stepsteps

[!div class="nextstepaction"] Verify that all machines are protected