Microsoft Defender for Cloud
Cloud and workloads

Review and remediate SQL vulnerability assessment findings

In brief

The instructions now explain how to open vulnerability summaries from SQL server or database resources, use Resource Health to start scans, and review findings from the Microsoft Defender for Cloud page. Screenshots, links, and metadata were also updated.

What Defender admins need to know

Administrators can use the updated portal paths to locate scan results, recommendations, and security alerts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review and remediate SQL vulnerability assessment findings

To run an on-demand scan:

  1. Sign into the Azure portal.

  2. Open your SQL Databaseserver or SQL database resource.

  3. Under the Security heading, select Microsoft Defender for Cloud.

  4. Open the database's Vulnerability Assessment page:

    • From a SQL database resource, select View database vulnerability summary.
    • From a SQL server resource, select View server vulnerability summary, and then select a database.
  5. Select View additional findings inScan.

    Screenshot of selecting Scan to run an on-demand vulnerability assessment scan of a SQL database.

Alternatively, from a SQL database resource, select Open resource health page. In the SQL Vulnerability Assessment results section, select Scan now.

:::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.assessment-find/scan-now-from-resource-health.png" alt-text="Screenshot of opening the scanResource health page with Scan now highlighted in the SQL Vulnerability Assessment results and manual scan options.section." lightbox="media/defender-for-sql-azure-vulnerability-assessment/view-additional-findings-link.assessment-find/scan-now-from-resource-health.png":::

  • Select Scan.

    :::image type="content" source="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png" alt-text="Screenshot of selecting scan to run an on-demand

    View the vulnerability assessment scan of your SQL resource." lightbox="media/defender-for-sql-azure-vulnerability-assessment/on-demand-vulnerability-scan.png":::

  • Review and remediate vulnerabilities.

  • Review and remediate Vulnerability Assessment findingsresults

    After a scan completes, the Vulnerability Assessment page shows a full view of your database security. This includes:

    • A severity summary of risks
    • A list of findings for investigation

    Review findings from the SQL resource's Defender for Cloud page

    You can reach SQL Vulnerability Assessment findings directly from the Microsoft Defender for Cloud page on a SQL server or SQL database resource. This page shows the Defender for SQL enablement status, a summary of detected vulnerabilities, and the security recommendations and alerts reported on the resource.

    To open the page:

    1. Sign in to the Azure portal.
    2. Open your SQL server or SQL database resource.
    3. Under the Security heading, select Microsoft Defender for Cloud.

    From the top of the page you can select Go to Defender for Cloud Overview or Open resource health page. The Microsoft Defender for SQL card shows the current enablement status and a Settings link to the Defender for SQL configuration.

    SQL server

    On a SQL server resource:

    1. The Vulnerabilities on related databases card summarizes the number of vulnerabilities detected by SQL Vulnerability Assessment on the server's underlying databases and provides two ways to review them:

      • View server vulnerability summary: opens the server-level SQL Vulnerability Assessment summary. This is the same summary that the now-deprecated SQL databases should have vulnerability findings resolved and SQL servers on machines should have vulnerability findings resolved recommendations used to open.
      • View in recommendations page: opens the Defender for Cloud Recommendations page filtered by the SQL Vulnerability Assessment scanner, with the current server set as the Parent resource.
    2. The Security findings on this SQL server section lists the Recommendations and Security Alerts reported on the server resource. Database-level SQL Vulnerability Assessment recommendations aren't listed here, because they're reported on the individual databases. The deprecated aggregated recommendations might still appear in the Recommendations tab until they're fully retired.

    :::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png" alt-text="Screenshot of a SQL server's Microsoft Defender for Cloud page showing vulnerabilities on related databases and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-server-security-findings.png":::

    SQL database

    On a SQL database resource:

    1. The Vulnerabilities on this database card summarizes the vulnerabilities detected on the database and provides two ways to review them:

      • View database vulnerability summary: opens the SQL Vulnerability Assessment page for the database.
      • View in recommendations page: opens the Defender for Cloud Recommendations page filtered by this database resource and the SQL Vulnerability Assessment scanner.
    2. The Security findings section lists the recommendations reported on the database. SQL Vulnerability Assessment recommendations appear in the Recommendations tab and can be identified by the Scanner column value SQL Vulnerability Assessment.

    :::image type="content" source="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png" alt-text="Screenshot of a SQL database's Microsoft Defender for Cloud page showing vulnerabilities on the database and security findings." lightbox="media/sql-azure-vulnerability-assessment-find/sql-database-security-findings.png":::


    Review and remediate vulnerabilities (Azure portal)

    Use the Azure portal to review findings, remediate issues, and manage baselines. Choose the tab that matches your experience.

    Database-level recommendations experience

    In the database-level recommendations experience:

    • SQL Vulnerability Assessment findings follow the same recommendation structure used across Microsoft Defender for Cloud.
    • Each SQL Vulnerability Assessment rule corresponds to its own recommendation.
    1. Select the Recommendations by risk view.

    2. Adjust the view:

      • Use the By Resource filter to list all instances of the assessment by reported resource. :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png" alt-text="Screenshot of the Defender for Cloud Recommendations page in the Azure portal, showing View per resource and filtering Scanner to SQL Vulnerability Assessment." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendations-filter-sql-va.png":::
      • Use the By Title filter to aggregate all instances of the assessment under one value.
    3. Select the Scanner filter and from the options, select SQL Vulnerability Assessment.

    4. Review findings (By Resource only):

      1. Select a recommendation.

        :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png" alt-text="Screenshot of a SQL Vulnerability Assessment recommendation details page in the Azure portal, highlighting Manage query results and remediation and the option to add query results as baseline." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-recommendation-details-manage-query-results.png":::

      2. In the database’s Resource health page, review the recommendations generated for the resource, trigger a SQL VA scan, or go to the SQL VA scan history page.

        :::image type="content" source="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png" alt-text="Screenshot of the Resource health page in the Azure portal showing the SQL Vulnerability Assessment results section with Scan now and Scan history." lightbox="media/sql-azure-vulnerability-assessment-find/database-level-resource-health-sql-va-results.png":::

    5. Review findings (By Title only):

      1. Select a recommendation.

      2. Scroll to the right to reach the Actions column under Affected resources.

      3. Select Show query and results for each affected database to set up baselines at scale.

    6. Verify that the remediated findings appear as healthy. In the express configuration, baseline approval takes effect immediately. In the classic configuration, baseline approval takes effect the next scan.

    Legacy experience

    InThis refers to the server-level experience,proprietary SQL Vulnerability Assessment findingsexperiences that are shown as subassessments directly in the SQL Database resource.still available without change.

    1. Sign in to the Azure portal.

    2. Under the Security heading, select Microsoft Defender for Cloud.

    3. Select View additional findings in Vulnerability Assessmentdatabase vulnerability summary.

    4. Review scan results to identifyIdentify security issues relevant to your environment.environment by reviewing the Findings tab.

    5. Select an unhealthy finding to review details and remediation guidance.

    Review and remediate vulnerabilities (Defender portal)

    In the Microsoft Defender portal experience: