Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
This article shows how to review Microsoft Defender for SQL alerts. Learn how to spot suspicious activity and take action on affected resources. You can open alerts quickly and follow up with a deeper look when needed.
View and investigate SQL alerts
You can access and review security alerts from Microsoft Defender for SQL. Defender for SQL creates alerts when it detects suspicious database activity or possible weak points. Each alert needs your review.
There are several ways to view Microsoft Defender for SQL alerts in Microsoft Defender for Cloud:
- The Alerts page.
- The affected machine's security page.
- The workload protections dashboard, which shows security coverage across resources.
- Through the direct link provided in the alert's email.
Open SQL security alerts in Defender for Cloud
To view security alerts in Microsoft Defender for Cloud, follow these steps:
Go to the Azure portal and sign in.
Search for and select Microsoft Defender for Cloud.
Select Security alerts.
Select an alert.
Alerts are self-contained and include detailed remediation steps and investigation guidance. For broader investigation, use related Microsoft Defender for Cloud and Microsoft Sentinel capabilities:
Enable SQL Server auditing for deeper investigations. If you use Microsoft Sentinel, you can upload SQL auditing logs from Windows Security Log events to Sentinel for richer investigation. For details, see SQL Server auditing.
To improve your security posture, use Defender for Cloud's recommendations for the host machine indicated in each alert to reduce the risks of future attacks.
For details, see Manage and respond to security alerts.
Related content
For related information, see these resources: