Skip to main content
compliance · azure

Azure SQL databases without Advanced Threat Protection from Defender for SQL

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags an Azure SQL database when Advanced Threat Protection, part of Microsoft Defender for SQL, is disabled on its server. Without it Azure raises no alert on SQL injection attempts, anomalous logins or unusual data access. Defender for SQL is a paid plan billed per server, so enabling it adds cost and ZopNight claims no saving.

Signal and threshold

How ZopNight evaluates Azure SQL databases without Advanced Threat Protection from Defender for SQL.
Field Value
Rule IDsRC-1332
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdthreat protection disabled
SourceZopNight
Permissions usedMicrosoft.Sql/servers/databases/read · Microsoft.Sql/servers/securityAlertPolicies/read · Microsoft.Sql/servers/advancedThreatProtectionSettings/read

Attacks on the database go unnoticed without it

SQL Advanced Threat Protection continuously monitors a database for suspicious activity and raises security alerts on potential vulnerabilities, SQL injection attacks and anomalous database access patterns. It is part of Microsoft Defender for SQL, which also includes vulnerability assessment.

Without it, an injection probe from a compromised web tier or a brute-force run against a SQL login produces no alert at all. You find out from the breach, not from the attempt.

Checking a server’s protection

Terminal window
az sql server advanced-threat-protection-setting show --resource-group my-rg --name my-server

state shows Enabled or Disabled. Defender for SQL can also be enabled for a whole subscription in Defender for Cloud, in which case every server in it is covered.

One provider-reported flag

ZopNight reads the threat-detection state from the server’s security alert policy as Azure reports it, and applies it to each database on that server. The finding fires only when the state is explicitly disabled. No activity metrics or windows are involved.

Databases left alone

If the policy state was not returned, ZopNight treats it as unknown and raises nothing. Tags describing threat detection are ignored; only the Azure setting counts.

A detection gap, and a Defender bill to close it

There is no saving here. Enabling Defender for SQL is charged at the Defender for Cloud rate per node, where a node is the entire logical server or managed instance, so you pay once for all databases on a server.

Enabling Defender for SQL

  1. Prefer the subscription level, so new servers are protected automatically: from Defender for Cloud’s menu select Environment Settings, pick the subscription and enable the Defender plan for Azure SQL databases.
  2. For a single server instead: az sql server advanced-threat-protection-setting update --resource-group my-rg --name my-server --state Enabled.
  3. Set alert email recipients so alerts reach someone who will act on them.
  4. Expect a storage account to be created for vulnerability assessment results if the resource group and region do not already have one.
  5. Review alerts regularly and feed them into your incident process.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·