Review and remediate SQL vulnerability assessment findings
In brief
The instructions now explain how to open vulnerability summaries from SQL server or database resources, use Resource Health to start scans, and review findings from the Microsoft Defender for Cloud page. Screenshots, links, and metadata were also updated.
What Defender admins need to know
Administrators can use the updated portal paths to locate scan results, recommendations, and security alerts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Review and remediate SQL vulnerability assessment findings
To run an on-demand scan:
Sign into the Azure portal.
Open your SQL
Databaseserver or SQL database resource.Under the Security heading, select Microsoft Defender for Cloud.
Open the database's Vulnerability Assessment page:
- From a SQL database resource, select View database vulnerability summary.
- From a SQL server resource, select View server vulnerability summary, and then select a database.
Select
View additional findings inScan.
Alternatively, from a SQL database resource, select Open resource health page. In the SQL Vulnerability Assessment results section, select Scan now.
:::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.assessment-find/scan-now-from-resource-health.png" alt-text="Screenshot of opening the scanResource health page with Scan now highlighted in the SQL Vulnerability Assessment results and manual scan options.section." lightbox="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.assessment-find/scan-now-from-resource-health.png":::
:::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png" alt-text="Screenshot of selecting scan to run an on-demand
View the vulnerability assessment scan of your SQL resource." lightbox="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png":::
Review and remediate Vulnerability Assessment findingsresults
After a scan completes, the Vulnerability Assessment page shows a full view of your database security. This includes:
- A severity summary of risks
- A list of findings for investigation
Review findings from the SQL resource's Defender for Cloud page
You can reach SQL Vulnerability Assessment findings directly from the Microsoft Defender for Cloud page on a SQL server or SQL database resource. This page shows the Defender for SQL enablement status, a summary of detected vulnerabilities, and the security recommendations and alerts reported on the resource.
To open the page:
- Sign in to the Azure portal.
- Open your SQL server or SQL database resource.
- Under the Security heading, select Microsoft Defender for Cloud.
From the top of the page you can select Go to Defender for Cloud Overview or Open resource health page. The Microsoft Defender for SQL card shows the current enablement status and a Settings link to the Defender for SQL configuration.
SQL server
On a SQL server resource:
The Vulnerabilities on related databases card summarizes the number of vulnerabilities detected by SQL Vulnerability Assessment on the server's underlying databases and provides two ways to review them:
- View server vulnerability summary: opens the server-level SQL Vulnerability Assessment summary. This is the same summary that the now-deprecated SQL databases should have vulnerability findings resolved and SQL servers on machines should have vulnerability findings resolved recommendations used to open.
- View in recommendations page: opens the Defender for Cloud Recommendations page filtered by the SQL Vulnerability Assessment scanner, with the current server set as the Parent resource.
The Security findings on this SQL server section lists the Recommendations and Security Alerts reported on the server resource. Database-level SQL Vulnerability Assessment recommendations aren't listed here, because they're reported on the individual databases. The deprecated aggregated recommendations might still appear in the Recommendations tab until they're fully retired.
:::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png" alt-text="Screenshot of a SQL server's Microsoft Defender for Cloud page showing vulnerabilities on related databases and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png":::
SQL database
On a SQL database resource:
The Vulnerabilities on this database card summarizes the vulnerabilities detected on the database and provides two ways to review them:
- View database vulnerability summary: opens the SQL Vulnerability Assessment page for the database.
- View in recommendations page: opens the Defender for Cloud Recommendations page filtered by this database resource and the SQL Vulnerability Assessment scanner.
The Security findings section lists the recommendations reported on the database. SQL Vulnerability Assessment recommendations appear in the Recommendations tab and can be identified by the Scanner column value SQL Vulnerability Assessment.
:::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png" alt-text="Screenshot of a SQL database's Microsoft Defender for Cloud page showing vulnerabilities on the database and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png":::
Review and remediate vulnerabilities (Azure portal)
Use the Azure portal to review findings, remediate issues, and manage baselines. Choose the tab that matches your experience.
Database-level recommendations experience
In the database-level recommendations experience:
- SQL Vulnerability Assessment findings follow the same recommendation structure used across Microsoft Defender for Cloud.
- Each SQL Vulnerability Assessment rule corresponds to its own recommendation.
Select the Recommendations by risk view.
Adjust the view:
- Use the By Resource filter to list all instances of the assessment by reported resource. :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png" alt-text="Screenshot of the Defender for Cloud Recommendations page in the Azure portal, showing View per resource and filtering Scanner to SQL Vulnerability Assessment." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png":::
- Use the By Title filter to aggregate all instances of the assessment under one value.
Select the Scanner filter and from the options, select SQL Vulnerability Assessment.
Review findings (By Resource only):
Select a recommendation.
:::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png" alt-text="Screenshot of a SQL Vulnerability Assessment recommendation details page in the Azure portal, highlighting Manage query results and remediation and the option to add query results as baseline." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png":::
In the database’s Resource health page, review the recommendations generated for the resource, trigger a SQL VA scan, or go to the SQL VA scan history page.
:::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png" alt-text="Screenshot of the Resource health page in the Azure portal showing the SQL Vulnerability Assessment results section with Scan now and Scan history." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png":::
Review findings (By Title only):
Select a recommendation.
Scroll to the right to reach the Actions column under Affected resources.
Select Show query and results for each affected database to set up baselines at scale.
Verify that the remediated findings appear as healthy. In the express configuration, baseline approval takes effect immediately. In the classic configuration, baseline approval takes effect the next scan.
Legacy experience
InThis refers to the server-level experience,proprietary SQL Vulnerability Assessment findingsexperiences that are shown as subassessments directly in the SQL Database resource.still available without change.
Sign in to the Azure portal.
Under the Security heading, select Microsoft Defender for Cloud.
Select View
additional findings in Vulnerability Assessmentdatabase vulnerability summary.Review scan results to identifyIdentify security issues relevant to yourenvironment.environment by reviewing the Findings tab.Select an unhealthy finding to review details and remediation guidance.
Review and remediate vulnerabilities (Defender portal)
In the Microsoft Defender portal experience:
SQL Vulnerability Assessment findings follow the same recommendation structure used across Microsoft Defender for Cloud.
Each SQL Vulnerability Assessment rule corresponds to its own recommendation.
Learn more about Microsoft Defender for Azure SQL.
Learn more about data discovery and classification.
Learn more about storing vulnerability assessment scan results in a storage account accessible behind firewalls and VNets.\ No newline at end of fileLearn more about storing vulnerability assessment scan results in a storage account accessible behind firewalls and VNets.
@@ -1,10 +1,11 @@ --- title: Review and remediate SQL vulnerability assessment findings description: Learn how to find, review, and remediate SQL vulnerability assessment findings in Microsoft Defender for Cloud for Azure SQL Database, Azure SQL Managed Instance, and Azure Synapse Analytics.-ms.date: 05/07/2026+ms.date: 07/03/2026 ms.service: defender-for-cloud ms.topic: how-to ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1013 --- # Review and remediate SQL vulnerability assessment findings@@ -14,7 +15,7 @@ Microsoft Defender for Cloud provides [SQL Vulnerability Assessment](sql-azure-v > [!IMPORTANT] > Express Configuration is generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces. This extends the generally available Microsoft-managed experience for Azure SQL Database, at no additional cost. > -> This release allows you to enable SQL VA without configuring a customer-managed storage account. Express Configuration is the recommended enablement mode and provides the same security value as Classic Configuration with a simplified setup.+> Express Configuration allows you to enable SQL VA without configuring a customer-managed storage account. Express Configuration is the recommended enablement mode and provides the same security value as Classic Configuration with a simplified setup. > > A unified REST API (v2026-04-01-preview) manages SQL VA consistently across Azure SQL Database, SQL Managed Instance, Synapse Workspaces, and SQL on machines (Azure VM and Arc-enabled SQL). @@ -57,22 +58,23 @@ Run a read-only, on-demand Vulnerability Assessment scan to refresh findings ins To run an on-demand scan: 1. Sign into the [Azure portal](https://portal.azure.com/).--1. Open your SQL Database resource.-+1. Open your SQL server or SQL database resource. 1. Under the **Security** heading, select **Microsoft Defender for Cloud**.+1. Open the database's Vulnerability Assessment page: -1. Select **View additional findings in Vulnerability Assessment**.- - :::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.png" alt-text="Screenshot of opening the scan results and manual scan options." lightbox="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.png":::+ - From a SQL database resource, select **View database vulnerability summary**.+ - From a SQL server resource, select **View server vulnerability summary**, and then select a database. 1. Select **Scan**. - :::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png" alt-text="Screenshot of selecting scan to run an on-demand vulnerability assessment scan of your SQL resource." lightbox="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png":::+ [](media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png#lightbox)++Alternatively, from a SQL database resource, select **Open resource health page**. In the **SQL Vulnerability Assessment results** section, select **Scan now**. -1. [Review and remediate vulnerabilities](#review-and-remediate-vulnerability-assessment-findings).+:::image type="content" source="media/sql-azure-vulnerability-assessment-find/scan-now-from-resource-health.png" alt-text="Screenshot of the Resource health page with Scan now highlighted in the SQL Vulnerability Assessment results section." lightbox="media/sql-azure-vulnerability-assessment-find/scan-now-from-resource-health.png"::: -## Review and remediate Vulnerability Assessment findings+<a name="review-and-remediate-vulnerability-assessment-findings"></a>+## View the vulnerability assessment scan results After a scan completes, the **Vulnerability Assessment** page shows a full view of your database security. This includes: @@ -81,14 +83,54 @@ After a scan completes, the **Vulnerability Assessment** page shows a full view - A severity summary of risks - A list of findings for investigation +## Review findings from the SQL resource's Defender for Cloud page++You can reach SQL Vulnerability Assessment findings directly from the **Microsoft Defender for Cloud** page on a SQL server or SQL database resource. This page shows the Defender for SQL enablement status, a summary of detected vulnerabilities, and the security recommendations and alerts reported on the resource.++To open the page:++1. Sign in to the [Azure portal](https://portal.azure.com/).+1. Open your SQL server or SQL database resource.+1. Under the **Security** heading, select **Microsoft Defender for Cloud**.++From the top of the page you can select **Go to Defender for Cloud Overview** or **Open resource health page**. The **Microsoft Defender for SQL** card shows the current enablement status and a **Settings** link to the Defender for SQL configuration.++# [SQL server](#tab/server)++On a SQL server resource:++1. The **Vulnerabilities on related databases** card summarizes the number of vulnerabilities detected by SQL Vulnerability Assessment on the server's underlying databases and provides two ways to review them:++ - **View server vulnerability summary**: opens the server-level SQL Vulnerability Assessment summary. This is the same summary that the now-deprecated **SQL databases should have vulnerability findings resolved** and **SQL servers on machines should have vulnerability findings resolved** recommendations used to open.+ - **View in recommendations page**: opens the Defender for Cloud **Recommendations** page filtered by the **SQL Vulnerability Assessment** scanner, with the current server set as the **Parent resource**.+1. The **Security findings on this SQL server** section lists the **Recommendations** and **Security Alerts** reported on the server resource. Database-level SQL Vulnerability Assessment recommendations aren't listed here, because they're reported on the individual databases. The deprecated aggregated recommendations might still appear in the **Recommendations** tab until they're fully retired.++:::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png" alt-text="Screenshot of a SQL server's Microsoft Defender for Cloud page showing vulnerabilities on related databases and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png":::++# [SQL database](#tab/database)++On a SQL database resource:++1. The **Vulnerabilities on this database** card summarizes the vulnerabilities detected on the database and provides two ways to review them:++ - **View database vulnerability summary**: opens the SQL Vulnerability Assessment page for the database.+ - **View in recommendations page**: opens the Defender for Cloud **Recommendations** page filtered by this database resource and the **SQL Vulnerability Assessment** scanner.+1. The **Security findings** section lists the recommendations reported on the database. SQL Vulnerability Assessment recommendations appear in the **Recommendations** tab and can be identified by the **Scanner** column value **SQL Vulnerability Assessment**.++:::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png" alt-text="Screenshot of a SQL database's Microsoft Defender for Cloud page showing vulnerabilities on the database and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png":::++---+ ## Review and remediate vulnerabilities (Azure portal) +Use the Azure portal to review findings, remediate issues, and manage baselines. Choose the tab that matches your experience.+ # [Database-level recommendations experience](#tab/database-level) > [!NOTE]-> This experience is currently in preview. The existing server-level (aggregated) experience remains available during preview.+> The database-level recommendations experience is currently in preview. The existing server-level (aggregated) experience remains available during preview. -In this experience:+In the database-level recommendations experience: - SQL Vulnerability Assessment findings follow the same recommendation structure used across Microsoft Defender for Cloud. - Each SQL Vulnerability Assessment rule corresponds to its own recommendation.@@ -101,14 +143,14 @@ In this experience: 1. Select the **Recommendations by risk** view. -1. Adjust the view: - - Use the **View per resource** filter to list all instances of the assessment by reported resource.- :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png" alt-text="Screenshot of the Defender for Cloud Recommendations page in the Azure portal, showing View per resource and filtering Scanner to SQL Vulnerability Assessment." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png":::- - Use the **View by title** filter to aggregate all instances of the assessment under one value.+1. Adjust the view:+ - Use the **By Resource** filter to list all instances of the assessment by reported resource.+ :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png" alt-text="Screenshot of the Defender for Cloud Recommendations page in the Azure portal, showing View per resource and filtering Scanner to SQL Vulnerability Assessment." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png":::+ - Use the **By Title** filter to aggregate all instances of the assessment under one value. 1. Select the **Scanner** filter and from the options, select **SQL Vulnerability Assessment**. -1. Review findings (**View by resource** only):+1. Review findings (**By Resource** only): 1. Select a recommendation. @@ -121,10 +163,10 @@ In this experience: :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png" alt-text="Screenshot of a SQL Vulnerability Assessment recommendation details page in the Azure portal, highlighting Manage query results and remediation and the option to add query results as baseline." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png"::: 1. In the database’s **Resource health** page, review the recommendations generated for the resource, trigger a SQL VA scan, or go to the SQL VA scan history page.- + :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png" alt-text="Screenshot of the Resource health page in the Azure portal showing the SQL Vulnerability Assessment results section with Scan now and Scan history." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png":::- -1. Review findings (**View by title** only): ++1. Review findings (**By Title** only): 1. Select a recommendation. @@ -135,12 +177,16 @@ In this experience: 1. Scroll to the right to reach the **Actions** column under **Affected resources**. 1. Select **Show query and results** for each affected database to set up baselines at scale.- + 1. Verify that the remediated findings appear as healthy. In the express configuration, baseline approval takes effect immediately. In the classic configuration, baseline approval takes effect the next scan. -# [Server-level (aggregated) experience](#tab/server-level)+> [!TIP]+> You can set baselines at scale by using the **By Title** recommendations view and selecting a SQL Vulnerability Assessment recommendation. On the page that opens, scroll to the right in the **Affected resources** section and select **Show query and results** for each row to view and set baselines where applicable.+> :::image type="content" source="media/sql-azure-vulnerability-assessment-find/show-query-results-for-affected-resources.png" alt-text="Screenshot of an aggregated SQL Vulnerability Assessment recommendation with Affected resources and Show query and results highlighted." lightbox="media/sql-azure-vulnerability-assessment-find/show-query-results-for-affected-resources.png":::++# [Legacy experience](#tab/legacy-experience) -In the server-level experience, SQL Vulnerability Assessment findings are shown as subassessments directly in the SQL Database resource.+This refers to the proprietary SQL Vulnerability Assessment experiences that are still available without change. 1. Sign in to the [Azure portal](https://portal.azure.com/). @@ -148,9 +194,9 @@ In the server-level experience, SQL Vulnerability Assessment findings are shown 1. Under the **Security** heading, select **Microsoft Defender for Cloud**. -1. Select **View additional findings in Vulnerability Assessment**.+1. Select **View database vulnerability summary**. -1. Review scan results to identify security issues relevant to your environment.+1. Identify security issues relevant to your environment by reviewing the **Findings** tab. 1. Select an unhealthy finding to review details and remediation guidance. @@ -173,9 +219,9 @@ In the server-level experience, SQL Vulnerability Assessment findings are shown ## Review and remediate vulnerabilities (Defender portal) > [!NOTE]-> This experience is currently in preview. The existing server-level (aggregated) experience remains available in the Azure portal during preview.+> The Microsoft Defender portal experience is currently in preview. The existing server-level (aggregated) experience remains available in the Azure portal during preview. -In this experience:+In the Microsoft Defender portal experience: - SQL Vulnerability Assessment findings follow the same recommendation structure used across Microsoft Defender for Cloud. - Each SQL Vulnerability Assessment rule corresponds to its own recommendation.@@ -232,4 +278,4 @@ Use this table to resolve common issues when working with SQL Vulnerability Asse - Learn more about [Microsoft Defender for Azure SQL](defender-for-sql-introduction.md). - Learn more about [data discovery and classification](/azure/azure-sql/database/data-discovery-and-classification-overview).-- Learn more about [storing vulnerability assessment scan results in a storage account accessible behind firewalls and VNets](/azure/azure-sql/database/sql-database-vulnerability-assessment-storage).\ No newline at end of file+- Learn more about [storing vulnerability assessment scan results in a storage account accessible behind firewalls and VNets](/azure/azure-sql/database/sql-database-vulnerability-assessment-storage). 
