Microsoft Defender for Cloud
Troubleshooting

Troubleshoot Defender for SQL on Machines configuration

In brief

The article now clarifies its scope for Defender for SQL on Machines in commercial clouds, adds prerequisite guidance, and improves links and wording for enabling protection and resolving instance-level misconfigurations.

What Defender admins need to know

Administrators can use the clarified scope and navigation to troubleshoot configuration and protection issues more efficiently.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Troubleshoot Defender for SQL on Machines configuration

This article helps you identify and resolve configuration and protection issues with Microsoft Defender for SQL on Machines in commercial cloud environments.

Before starting the troubleshooting steps, you must enable Defender for SQL server on Machines at the Azure subscription level or SQL Server resource level.

Step 1: Required resources and enablement process

Step 2: Ensure that you fulfilled the prerequisites

Before troubleshooting, ensure the following prerequisites are met:

  • Subscription permissions: To deploy the plan on a subscription, including Azure Policy, you need Subscription Owner permissions.

  • SQL Server instance permissions: SQL Server service accounts must have the sysadmin fixed server role on each SQL Server instance, which is the default setting. Learn more about the SQL Server service account requirement.

    :::image type="content" source="media/troubleshoot-sql-machines-guide/extension-status.png" alt-text="Screenshot that shows the information screen for the selected extension." lightbox="media/troubleshoot-sql-machines-guide/extension-status.png":::

Based on the unhealthy reason listed, take the appropriate action described in Step 3: Identify and resolve protection misconfigurations to remediate the issue.misconfiguration for that SQL Server instance.

Step 4: Reverify protection status