Microsoft Defender for Cloud
Cloud and workloads

Enable Microsoft Defender for SQL Servers on Machines government

In brief

The article updates its metadata, clarifies the East US region requirement, and renames setup headings with anchor links, including “Enable Defender for SQL Servers on Machines” and “Select a Log Analytics workspace.”

What Defender admins need to know

Administrators get clearer setup guidance and stable section links. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

| SQL IaaS Extension (IaaS)| - Publisher: Microsoft.SqlServer.Management
- Type: SqlIaaSAgent | | SQL IaaS Extension (Arc)| - Publisher: Microsoft.AzureData
- Type: WindowsAgent.SqlServer| | AMA extension (IaaS and Arc) | - Publisher: Microsoft.Azure.Monitor
- Type: AzureMonitorWindowsAgent | | Region requirement | When you enable the plan, a resource group is created in the East US. Ensure this regionEast US isn't blocked in your environment. | | Resource naming conventions | Defender for SQL uses the following naming convention when creating our resources:
- Data Collection Rule: MicrosoftDefenderForSQL--dcr
- DCRA: /Microsoft.Insights/MicrosoftDefenderForSQL-RulesAssociation
- Resource group: DefaultResourceGroup-
- Log analytics workspace: D4SQL--
- Defender for SQL uses MicrosoftDefenderForSQL as a createdBy database tag.

Ensure that Deny policies don't block thisthe Defender for SQL resource naming convention.convention listed above. | | Supported SQL Server Versions| SQL Server 2012 or later is supported for SQL instances. | | Supported Operating Systems| Windows Server 2012 R2 or later. |

Enable the planDefender for SQL Servers on Machines

  1. In the Azure portal, search for and select Microsoft Defender for Cloud.

  2. Select Continue > Save.

Select a Log Analytics workspace

Select a Log Analytics workspace to work with the Defender for SQL on Machines plan.

As a required final step, verify that all machines are protected. Verification confirms that the deployment completed and that your SQL instances are protected.

Next stepsteps

[!div class="nextstepaction"] Verify that all machines are protected