Tag: Defender for Databases

Configure Defender for Databases protection across Azure database services (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure storage, databases, and networking (25–30%)
   --> Implement security for databases
      --> Configure Defender for Databases protection across Azure database services


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Microsoft Defender for Databases is a set of security capabilities within Microsoft Defender for Cloud that helps protect database services from vulnerabilities, suspicious activity, and potential attacks.

The service combines database security monitoring with vulnerability assessment and security recommendations. It is designed to help security teams identify weaknesses, detect threats, investigate alerts, and improve the security posture of database workloads.

For the SC-500 exam, important concepts include:

  • Enabling Defender for Databases
  • Understanding the database-specific protection plans
  • Protecting Azure SQL databases and managed instances
  • Protecting SQL Server running on machines
  • Protecting open-source relational databases
  • Protecting Azure Cosmos DB
  • Using vulnerability assessment
  • Understanding advanced threat protection
  • Reviewing security alerts and recommendations
  • Monitoring coverage across subscriptions and resources

Microsoft Defender for Databases is managed through Microsoft Defender for Cloud.


What Defender for Databases Protects

The Defender for Databases plan contains four primary offerings:

  1. Microsoft Defender for Azure SQL Databases
  2. Microsoft Defender for SQL Servers on Machines
  3. Microsoft Defender for Open-Source Relational Databases
  4. Microsoft Defender for Azure Cosmos DB

Each offering targets different database platforms and has different capabilities. The plans are priced separately, and enabling the overall Databases plan activates the supported database protection offerings for the selected environment.


Microsoft Defender for Azure SQL Databases

Microsoft Defender for Azure SQL Databases protects supported Azure SQL workloads, including:

  • Azure SQL Database
  • Azure SQL elastic pools
  • Azure SQL Managed Instance
  • Azure Synapse Analytics dedicated SQL pools
  • Supported SQL Server workloads running on Azure virtual machines
  • Supported SQL Server workloads enabled through Azure Arc

The service helps identify database vulnerabilities and detect anomalous activity that may indicate an attack.

Examples of suspicious activity include:

  • Potential SQL injection
  • Unusual database access patterns
  • Abnormally high numbers of failed sign-in attempts
  • Brute-force attempts
  • Access from an unusual location
  • Access by an unfamiliar principal
  • Activity associated with a potentially compromised application or computer

Defender for Azure SQL Databases provides security alerts with details about the suspicious activity and guidance for investigation or mitigation.


Microsoft Defender for SQL Servers on Machines

Microsoft Defender for SQL Servers on Machines protects SQL Server installations running on:

  • Azure virtual machines
  • On-premises servers
  • Azure Arc-enabled servers
  • Other supported cloud environments, including AWS and Google Cloud

This offering is useful for hybrid and multicloud environments because it extends SQL security monitoring beyond Azure-native database services.

It provides two major capabilities:

  • Vulnerability assessment
  • Advanced threat protection

The service can identify potential SQL injection, unusual access locations, unfamiliar principals, suspicious applications, and brute-force activity. It can also provide security recommendations and detailed alerts.


Microsoft Defender for Open-Source Relational Databases

This offering provides protection for supported open-source database services, including:

  • Azure Database for PostgreSQL
  • Azure Database for MySQL
  • Supported Amazon RDS database engines, such as PostgreSQL, MySQL, MariaDB, and Aurora variants

Capabilities can include:

  • Threat detection
  • Suspicious activity alerts
  • Sensitive data discovery
  • Security posture recommendations
  • Identification of database configuration weaknesses

The exact capabilities depend on the database engine, deployment environment, and supported Defender features. Defender for Databases is not a single identical feature set across every database platform.


Microsoft Defender for Azure Cosmos DB

Microsoft Defender for Azure Cosmos DB provides protection for Azure Cosmos DB workloads.

Its primary purpose is to detect suspicious database activity and provide security alerts that can help organizations respond to potential threats.

Cosmos DB protection should be considered separately from SQL-specific protection because Cosmos DB is a NoSQL database service and does not use the same SQL vulnerability assessment and threat-detection model as Azure SQL.


Main Defender for Databases Capabilities

Vulnerability Assessment

Vulnerability assessment evaluates database configurations and security settings to identify potential weaknesses.

For supported Azure SQL services, vulnerability assessment can identify issues such as:

  • Excessive permissions
  • Insecure database configurations
  • Weak security settings
  • Unprotected sensitive data
  • Database-level security problems
  • Server-level security problems
  • Deviations from recommended security practices

The results include findings and remediation guidance.

Vulnerability assessment is intended to help organizations proactively improve security rather than waiting for an attack to occur.

Vulnerability assessment is not penetration testing

Vulnerability assessment generally evaluates configurations and known security conditions. It should not be confused with:

  • A full penetration test
  • A simulated attack
  • A replacement for secure application development
  • A replacement for access control
  • A guarantee that the database is free from vulnerabilities

It is one component of a broader database security program.


Vulnerability Assessment for Azure SQL

SQL vulnerability assessment is supported for:

  • Azure SQL Database
  • Azure SQL Managed Instance
  • Azure Synapse Analytics

The scanner uses a collection of security rules to identify vulnerabilities and deviations from recommended practices.

For supported configurations, scans are lightweight, read-only, and do not make changes to the database. Vulnerability assessment scans for SQL servers on machines occur approximately every 12 hours.

Vulnerability assessment findings

A finding typically provides:

  • The security issue
  • The affected resource
  • The severity or risk context
  • Evidence supporting the finding
  • Recommended remediation steps

Security teams can review findings through Defender for Cloud and use them to prioritize remediation.

Baselines

A baseline can be used when a finding is acceptable for a particular environment.

For example, an organization may intentionally allow a configuration because of a documented application dependency. Establishing a baseline prevents the same accepted condition from being repeatedly treated as a new failure.

Baselines should be used carefully. They should not be used to hide unresolved vulnerabilities without documented justification, ownership, and periodic review.

Express and classic configuration

SQL vulnerability assessment supports different configuration models.

Express configuration uses Microsoft-managed storage for scan results and simplifies deployment.

Classic configuration uses a customer-managed storage account and provides additional configuration control.

The available configuration model depends on the database service and current service support. Express configuration is the recommended simplified approach for supported services.


Advanced Threat Protection

Advanced threat protection continuously monitors database activity for patterns that may indicate malicious or suspicious behavior.

Examples include:

  • SQL injection attempts
  • Brute-force login activity
  • Unusual query patterns
  • Access from unfamiliar locations
  • Access by unfamiliar users or applications
  • Suspicious database activity associated with compromised systems
  • Unusual data-access behavior

Advanced threat protection is focused on detecting potentially harmful activity, whereas vulnerability assessment focuses on identifying security weaknesses and misconfigurations.

Vulnerability assessment versus threat protection

CapabilityPrimary purpose
Vulnerability assessmentIdentify weaknesses and configuration problems
Advanced threat protectionDetect suspicious or potentially malicious activity
Security recommendationsExplain how to improve security posture
Security alertsNotify responders about possible threats
Microsoft Sentinel integrationCorrelate and investigate security events across systems

Both vulnerability assessment and threat protection should be enabled when supported and appropriate for the workload.


Enabling Defender for Databases

Prerequisites

Before enabling Defender for Databases, ensure that:

  • Microsoft Defender for Cloud is available for the Azure subscription.
  • You have sufficient permissions to modify Defender for Cloud settings.
  • The relevant database resources are supported.
  • Any required agents, extensions, managed identities, or workspace dependencies are configured.
  • The organization understands the cost implications of the selected plans.

For hybrid or multicloud database protection, the relevant AWS accounts, Google Cloud projects, or non-Azure machines must be connected to Defender for Cloud as required.


Enable the Databases Plan

A typical portal-based process is:

  1. Sign in to the Azure portal.
  2. Open Microsoft Defender for Cloud.
  3. Select Environment settings.
  4. Select the relevant Azure subscription or connected cloud environment.
  5. Open the Defender plans page.
  6. Locate the Databases plan.
  7. Turn the plan on.
  8. Review and configure the individual database offerings.
  9. Save the configuration.
  10. Verify protection coverage.

Enabling the Databases plan activates the supported database protection offerings for the selected environment.


Configuring Specific Database Plans

After enabling the Databases plan, review the individual offerings.

Defender for Azure SQL Databases

Use this plan for supported Azure SQL Database, Azure SQL Managed Instance, and related SQL workloads.

Verify:

  • The correct subscription is selected.
  • Supported SQL resources are covered.
  • Threat protection is enabled.
  • Vulnerability assessment is configured.
  • Alerts are being generated and delivered as expected.

Defender for SQL Servers on Machines

Use this plan for SQL Server running on Azure virtual machines, on-premises machines, or other supported connected environments.

Verify:

  • The machines are connected to Azure through the appropriate mechanism.
  • SQL Server discovery is working.
  • Required extensions or agents are healthy.
  • Vulnerability assessment is enabled.
  • The Log Analytics workspace is configured where required.

Defender for Open-Source Relational Databases

Use this plan for supported PostgreSQL and MySQL database services.

Review the supported database engines and deployment types before enabling the plan. Do not assume that every open-source database service has identical monitoring or assessment capabilities.

Defender for Azure Cosmos DB

Use this plan for supported Azure Cosmos DB resources.

Review the protection coverage and available alerts for the specific Cosmos DB configuration.


Monitoring Protection Coverage

Defender for Cloud provides coverage information that helps administrators determine which subscriptions and resources are protected.

Coverage reviews should identify:

  • Subscriptions with the Databases plan enabled
  • Database services that are protected
  • Resources that are not covered
  • Unsupported database types
  • Resources with configuration problems
  • Workloads that require separate plan activation
  • Hybrid or multicloud environments that are not connected

Coverage should be reviewed regularly because new databases may be created after the initial security configuration.

For supported resources, enabling the relevant plan at the subscription level can protect existing resources and future supported resources created in that subscription.


Security Alerts

Defender for Databases generates alerts when activity appears suspicious or potentially harmful.

An alert may contain:

  • The affected database or server
  • The time of the activity
  • The type of suspicious behavior
  • The source or principal involved
  • Relevant evidence
  • Severity information
  • Recommended investigation or mitigation steps

Examples of alerts include:

  • Possible SQL injection
  • Brute-force database access
  • Access from an unusual location
  • Access by an unfamiliar principal
  • Suspicious query patterns
  • Activity associated with a potentially compromised application

Security alerts should be investigated rather than automatically assumed to be confirmed attacks. Some alerts may represent legitimate but unusual administrative or application activity.


Integrating with Microsoft Sentinel

Microsoft Sentinel can provide centralized investigation and correlation for Defender for Databases alerts.

A typical integration can correlate database alerts with:

  • Microsoft Entra sign-in events
  • Privileged Identity Management activity
  • Azure Activity Log events
  • Virtual machine alerts
  • Network security events
  • Application logs
  • Endpoint security events
  • Other database activity

For example, a suspicious database access alert may become more serious when it occurs shortly after:

  • A risky sign-in
  • A privilege escalation
  • A new service principal credential
  • A change to a firewall rule
  • A compromised virtual machine alert

Defender for Databases alerts can include options for continuing investigations through Microsoft Sentinel.


Roles and Permissions

Managing Defender for Databases requires appropriate Azure permissions.

The permissions needed depend on the task, such as:

  • Viewing Defender for Cloud recommendations
  • Viewing security alerts
  • Enabling Defender plans
  • Configuring vulnerability assessment
  • Viewing scan results
  • Managing storage for scan results
  • Accessing Log Analytics data
  • Managing connected machines

The ability to manage Azure resources does not necessarily mean that a user can read all database data. Similarly, the ability to view database security alerts does not automatically grant access to the underlying database.

Use least privilege when assigning administrative and monitoring roles.


Important Security Distinctions

Defender for Databases does not replace access control

Defender for Databases detects threats and vulnerabilities. It does not replace:

  • Microsoft Entra authentication
  • Database users and roles
  • Azure RBAC
  • Network security controls
  • Private endpoints
  • Firewall rules
  • Encryption
  • Application security
  • Secure coding practices

A database can have Defender protection enabled and still be insecure if users have excessive permissions or the database is exposed unnecessarily.

Defender for Databases does not guarantee prevention

Threat protection may detect suspicious activity and generate alerts, but detection is not the same as prevention.

Organizations must define response procedures, which may include:

  • Blocking a user or application
  • Revoking credentials
  • Disabling a compromised identity
  • Restricting network access
  • Isolating a virtual machine
  • Changing database permissions
  • Investigating related resources

Not every database service has identical capabilities

The term “Defender for Databases” covers multiple database protection offerings. Features differ by:

  • Database engine
  • Azure service
  • Deployment model
  • Region
  • Supported plan
  • Configuration model

Always verify the capabilities for the specific database platform being protected.


Best Practices

  1. Enable the appropriate Defender database plan for each supported database platform.
  2. Review coverage regularly across subscriptions and connected environments.
  3. Enable vulnerability assessment where supported.
  4. Review and remediate high-severity findings.
  5. Use baselines only for documented and approved exceptions.
  6. Monitor security alerts continuously.
  7. Integrate alerts with Microsoft Sentinel when centralized investigation is required.
  8. Correlate database alerts with identity, network, and endpoint events.
  9. Protect Log Analytics workspaces and scan-result storage with least privilege.
  10. Review the cost of each database protection plan.
  11. Confirm that hybrid and multicloud database resources are properly connected.
  12. Do not assume that enabling Defender automatically fixes vulnerabilities.
  13. Continue using strong authentication, authorization, encryption, and network controls.
  14. Test alert routing and incident-response procedures.
  15. Review new database resources to ensure they are included in protection coverage.

Common SC-500 Exam Traps

  • Vulnerability assessment identifies weaknesses; it does not primarily detect active attacks.
  • Advanced threat protection detects suspicious activity; it does not replace database permissions.
  • Defender for Databases is a collection of database-specific offerings, not one identical feature set.
  • Azure SQL Database and SQL Server on machines use different protection configurations.
  • Azure Cosmos DB requires its own Defender for Cosmos DB offering.
  • Enabling the Databases plan does not eliminate the need to review coverage.
  • A security recommendation is not the same as a security alert.
  • A vulnerability finding is not automatically proof that an attack is occurring.
  • A baseline should represent an approved exception, not an ignored security issue.
  • Microsoft Sentinel is used for centralized correlation and investigation, not as a prerequisite for every Defender database feature.

Practice Exam Questions

Question 1

An organization wants to identify insecure database configurations and excessive permissions in its Azure SQL databases. Which Defender for Databases capability should it use?

A. Vulnerability assessment
B. Advanced threat protection
C. Microsoft Entra Conditional Access
D. Azure Firewall

Correct answer: A

Explanation: Vulnerability assessment evaluates database configurations and security settings to identify potential weaknesses, such as excessive permissions and insecure configurations.


Question 2

A security analyst receives an alert indicating that a database was accessed from an unfamiliar location and that the activity may be suspicious. Which capability most likely generated the alert?

A. Azure Policy
B. Vulnerability assessment
C. Azure Backup
D. Advanced threat protection

Correct answer: D

Explanation: Advanced threat protection continuously monitors database activity for anomalous or potentially harmful behavior, including access from unusual locations.


Question 3

A company has Azure SQL Database, Azure SQL Managed Instance, and Azure Cosmos DB resources. Which approach provides the most appropriate protection coverage?

A. Enable only Defender for Azure SQL Databases
B. Enable the Databases plan and configure the relevant database-specific offerings
C. Enable Defender for Servers only
D. Configure Azure SQL auditing and assume all database services are protected

Correct answer: B

Explanation: Defender for Databases includes separate offerings for Azure SQL, SQL Servers on Machines, open-source relational databases, and Azure Cosmos DB. The relevant offerings must be enabled and reviewed for the database types in use.


Question 4

An organization runs SQL Server on an Azure virtual machine and on an on-premises server connected through Azure Arc. Which Defender offering is designed for these workloads?

A. Defender for Azure Cosmos DB
B. Defender for Open-Source Relational Databases
C. Defender for SQL Servers on Machines
D. Defender for Azure SQL Databases only

Correct answer: C

Explanation: Defender for SQL Servers on Machines protects supported SQL Server installations running on Azure virtual machines, on-premises servers, and other connected environments.


Question 5

A database administrator establishes a vulnerability assessment baseline for a finding that is an approved exception in the organization’s environment. What is the purpose of the baseline?

A. To permanently disable all vulnerability assessment scans
B. To treat the accepted condition as a passing result in later assessments
C. To grant the database administrator unrestricted database access
D. To convert the finding into a security alert

Correct answer: B

Explanation: A baseline records an accepted security state or finding so that it is not repeatedly reported as a failure. Baselines should be documented and reviewed periodically.


Question 6

A security team wants to correlate a suspicious database access alert with a risky Microsoft Entra sign-in and a virtual machine compromise alert. Which service is most appropriate?

A. Microsoft Sentinel
B. Azure Storage Explorer
C. Azure Resource Graph only
D. Azure Cost Management

Correct answer: A

Explanation: Microsoft Sentinel can correlate database alerts with identity, endpoint, network, and other security events to support centralized investigation.


Question 7

Which statement best describes the relationship between vulnerability assessment and advanced threat protection?

A. Vulnerability assessment detects active attacks, while advanced threat protection only checks configuration
B. Both capabilities perform exactly the same function
C. Advanced threat protection replaces the need for database permissions
D. Vulnerability assessment identifies weaknesses, while advanced threat protection detects suspicious activity

Correct answer: D

Explanation: Vulnerability assessment focuses on security weaknesses and configuration issues. Advanced threat protection monitors activity for suspicious or potentially malicious behavior.


Question 8

An organization enables Defender for Databases but discovers that several newly created database resources are not protected. What should the administrator do first?

A. Disable all database services
B. Replace Microsoft Entra authentication with SQL authentication
C. Review Defender for Cloud coverage and confirm that the relevant database plan supports those resources
D. Delete and recreate the subscription

Correct answer: C

Explanation: The administrator should review coverage, supported resource types, subscription settings, and the relevant database-specific plan. Not every database service is covered by the same offering.


Question 9

Which statement about Defender for Databases is accurate?

A. It replaces database authentication and authorization
B. It guarantees that all database attacks will be prevented
C. It provides database security capabilities such as vulnerability assessment and threat detection
D. It automatically encrypts every database column

Correct answer: C

Explanation: Defender for Databases helps identify vulnerabilities and suspicious activity. It does not replace authentication, authorization, encryption, or other security controls.


Question 10

A security team wants to protect PostgreSQL and MySQL database services in Azure. Which Defender offering should it investigate?

A. Defender for Open-Source Relational Databases
B. Defender for SQL Servers on Machines only
C. Defender for Azure Cosmos DB
D. Defender for Containers

Correct answer: A

Explanation: Defender for Open-Source Relational Databases is designed to provide protection for supported PostgreSQL and MySQL database services, along with supported related environments.


Go to the SC-500 Exam Prep Hub main page