Azure SQL databases without Advanced Threat Protection from Defender for SQL
What does ZopNight detect here?
ZopNight flags an Azure SQL database when Advanced Threat Protection, part of Microsoft Defender for SQL, is disabled on its server. Without it Azure raises no alert on SQL injection attempts, anomalous logins or unusual data access. Defender for SQL is a paid plan billed per server, so enabling it adds cost and ZopNight claims no saving.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1332 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | threat protection disabled |
| Source | ZopNight |
| Permissions used | Microsoft.Sql/servers/databases/read · Microsoft.Sql/servers/securityAlertPolicies/read · Microsoft.Sql/servers/advancedThreatProtectionSettings/read |
Where it applies
Attacks on the database go unnoticed without it
SQL Advanced Threat Protection continuously monitors a database for suspicious activity and raises security alerts on potential vulnerabilities, SQL injection attacks and anomalous database access patterns. It is part of Microsoft Defender for SQL, which also includes vulnerability assessment.
Without it, an injection probe from a compromised web tier or a brute-force run against a SQL login produces no alert at all. You find out from the breach, not from the attempt.
Checking a server’s protection
az sql server advanced-threat-protection-setting show --resource-group my-rg --name my-serverstate shows Enabled or Disabled. Defender for SQL can also be enabled for a whole
subscription in Defender for Cloud, in which case every server in it is covered.
One provider-reported flag
ZopNight reads the threat-detection state from the server’s security alert policy as Azure reports it, and applies it to each database on that server. The finding fires only when the state is explicitly disabled. No activity metrics or windows are involved.
Databases left alone
If the policy state was not returned, ZopNight treats it as unknown and raises nothing. Tags describing threat detection are ignored; only the Azure setting counts.
A detection gap, and a Defender bill to close it
There is no saving here. Enabling Defender for SQL is charged at the Defender for Cloud rate per node, where a node is the entire logical server or managed instance, so you pay once for all databases on a server.
Enabling Defender for SQL
- Prefer the subscription level, so new servers are protected automatically: from Defender for Cloud’s menu select Environment Settings, pick the subscription and enable the Defender plan for Azure SQL databases.
- For a single server instead:
az sql server advanced-threat-protection-setting update --resource-group my-rg --name my-server --state Enabled. - Set alert email recipients so alerts reach someone who will act on them.
- Expect a storage account to be created for vulnerability assessment results if the resource group and region do not already have one.
- Review alerts regularly and feed them into your incident process.