Microsoft Defender for Cloud
Cloud and workloads

Enable SQL vulnerability assessment express configuration for Azure SQL

In brief

The article now has a clearer title and overview, explains express and classic configuration options, adds prerequisites, and notes that an initial scheduled scan must complete before findings appear.

What Defender admins need to know

Administrators can follow the updated setup guidance and set expectations for when vulnerability results become available.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable vulnerability assessment (Express)

Overview

In this article, you learn how to enableEnable vulnerability assessment so you canwith the express configuration to find and remediate database vulnerabilities. We recommend that you enable vulnerability assessment using the express configuration so you aren't dependentvulnerabilities without depending on a storage account. You can also enable vulnerability assessment using the classic configuration.

Prerequisites

Before you enable express vulnerability assessment, make sure the following prerequisites are met:

  • Make sure that Microsoft Defender for Azure SQL is enabled so you can run scans on your Azure SQL databases.

  • Make sure you've read and understand the differences between the express and classic configuration.

    :::image type="content" source="media/sql-azure-vulnerability-assessment-enable/migrate-to-express-vulnerability-assessment-configure.png" alt-text="Screenshot showing the migrate option to switch from classic to express vulnerability assessment configuration in the Microsoft Defender for SQL settings pane.":::
    

NowAfter you can goenable vulnerability assessment, your databases need to be scanned before results are available. Wait for the SQL databases should have vulnerability findings resolved recommendationinitial scan to complete on each database's scheduled scan time, and then review the findings. To learn more, see the vulnerabilities found in your databases.Review and remediate vulnerabilities. You can also run on-demand vulnerability assessment scans to see the current findings.