Microsoft Defender for Cloud
Troubleshooting

Troubleshoot Defender for SQL on Machines deployment in government clouds

In brief

The guide updates its title and wording, clarifies the remediation-task process and script link, and adds troubleshooting guidance for extension-related policy and DCRA misconfigurations.

What Defender admins need to know

Administrators can use the revised guidance to navigate remediation and troubleshoot affected subscriptions more clearly. No action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

After identifying misconfigurations, start by fixing DCR issues, then workspace issues, and finally identity issues at the subscription level.

Fix misconfigurations in the correct order. DCR resolution relies on workspace resolution, and workspace resolution relies on identity resolution. If you try to resolve these misconfigurations out of order, theythe misconfigurations aren't resolved.

  1. Navigate to Policy > Compliance.

  2. Select Remediate.

  3. Repeat these stepsthe remediation-task process for each noncompliant policy and subscription.

Input custom values with PowerShell deployment script

If you couldn't resolve subscription issues with the workbook, Defender for SQL Servers on Machines provides a PowerShell deployment script that enables you to input your own values for workspace, DCR, and user Identity. To use the PowerShell script, follow the instructions in Enable Defender for SQL at scale.

Step 7: Resolve misconfigurations at the resource level

Troubleshoot extension misconfigurations

Use the following steps to troubleshoot extension-related policy misconfigurations.

  1. In the Azure portal, navigate to Policy > Compliance.

  2. Select Scope.

Troubleshoot DCRA misconfigurations

Use the following steps to troubleshoot DCRA misconfigurations for the affected subscription.

  1. In the Azure portal, Search for and select Data collection rules.

  2. Select Subscription equals > select the relevant subscription.