Enable SQL vulnerability assessment express configuration for Azure SQL
In brief
The article now has a clearer title and overview, explains express and classic configuration options, adds prerequisites, and notes that an initial scheduled scan must complete before findings appear.
What Defender admins need to know
Administrators can follow the updated setup guidance and set expectations for when vulnerability results become available.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Enable vulnerability assessment (Express)
Overview
In this article, you learn how to enableEnable vulnerability assessment so you canwith the express configuration to find and remediate database vulnerabilities. We recommend that you enable vulnerability assessment using the express configuration so you aren't dependentvulnerabilities without depending on a storage account. You can also enable vulnerability assessment using the classic configuration.
Prerequisites
Before you enable express vulnerability assessment, make sure the following prerequisites are met:
Make sure that Microsoft Defender for Azure SQL is enabled so you can run scans on your Azure SQL databases.
Make sure you've read and understand the differences between the express and classic configuration.
:::image type="content" source="media/sql-azure-vulnerability-assessment-enable/migrate-to-express-vulnerability-assessment-configure.png" alt-text="Screenshot showing the migrate option to switch from classic to express vulnerability assessment configuration in the Microsoft Defender for SQL settings pane.":::
NowAfter you can goenable vulnerability assessment, your databases need to be scanned before results are available. Wait for the SQL databases should have vulnerability findings resolved recommendationinitial scan to complete on each database's scheduled scan time, and then review the findings. To learn more, see the vulnerabilities found in your databases.Review and remediate vulnerabilities. You can also run on-demand vulnerability assessment scans to see the current findings.
@@ -1,25 +1,29 @@ ----title: Enable vulnerability assessment (Express)+title: Enable SQL vulnerability assessment express configuration for Azure SQL description: Learn how to enable the express configuration of SQL vulnerability assessment on Azure SQL Database, Azure SQL Managed Instance, and Azure Synapse Analytics.-ms.date: 05/14/2026+ms.date: 07/03/2026 ms.service: defender-for-cloud ms.topic: how-to-ms.custom: sqldbrb=3, sfi-image-nochange+ms.custom: sqldbrb=3, sfi-image-nochange, msecd-doc-authoring-1013 ai-usage: ai-assisted --- # Enable vulnerability assessment (Express) -In this article, you learn how to enable [vulnerability assessment](sql-azure-vulnerability-assessment-overview.md) so you can find and remediate database vulnerabilities. We recommend that you enable vulnerability assessment using the express configuration so you aren't dependent on a storage account. You can also enable vulnerability assessment using the [classic configuration](sql-azure-vulnerability-assessment-enable-classic.md).+## Overview++Enable [vulnerability assessment](sql-azure-vulnerability-assessment-overview.md) with the express configuration to find and remediate database vulnerabilities without depending on a storage account. You can also enable vulnerability assessment using the [classic configuration](sql-azure-vulnerability-assessment-enable-classic.md). > [!IMPORTANT]-> Express Configuration is generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces. This extends the generally available Microsoft-managed experience for Azure SQL Database, at no additional cost.+> Express Configuration is generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces. Express Configuration availability for these services extends the generally available Microsoft-managed experience for Azure SQL Database, at no additional cost. > -> This release allows you to enable SQL VA without configuring a customer-managed storage account. Express Configuration is the recommended enablement mode and provides the same security value as Classic Configuration with a simplified setup.+> Express Configuration allows you to enable SQL VA without configuring a customer-managed storage account. Express Configuration is the recommended enablement mode and provides the same security value as Classic Configuration with a simplified setup. > > A unified REST API (v2026-04-01-preview) manages SQL VA consistently across Azure SQL Database, SQL Managed Instance, Synapse Workspaces, and SQL on machines (Azure VM and Arc-enabled SQL). ## Prerequisites +Before you enable express vulnerability assessment, make sure the following prerequisites are met:+ - Make sure that [Microsoft Defender for Azure SQL](defender-for-databases-introduction.md) is enabled so you can run scans on your Azure SQL databases. - Make sure you've read and understand the [differences between the express and classic configuration](sql-azure-vulnerability-assessment-overview.md#configuration-model-comparison). @@ -58,7 +62,7 @@ If you have Azure SQL databases with vulnerability assessment disabled, you can :::image type="content" source="media/sql-azure-vulnerability-assessment-enable/migrate-to-express-vulnerability-assessment-configure.png" alt-text="Screenshot showing the migrate option to switch from classic to express vulnerability assessment configuration in the Microsoft Defender for SQL settings pane."::: -Now you can go to the [**SQL databases should have vulnerability findings resolved**](https://ms.portal.azure.com/#view/Microsoft_Azure_Security_AzureDefenderForData/SqlVaServersRecommendationDetailsBlade/assessmentKey/82e20e14-edc5-4373-bfc4-f13121257c37) recommendation to see the vulnerabilities found in your databases. You can also run on-demand vulnerability assessment scans to see the current findings.+After you enable vulnerability assessment, your databases need to be scanned before results are available. Wait for the initial scan to complete on each database's scheduled scan time, and then review the findings. To learn more, see [Review and remediate vulnerabilities](sql-azure-vulnerability-assessment-find.md?tabs=database-level). You can also run on-demand vulnerability assessment scans to see the current findings. > [!NOTE] > Each database is randomly assigned a scan time on a set day of the week. 