Skip to main content Link Menu Expand (external link) Document Search Copy Copied

Task 01 - Review Microsoft Defender

Introduction

Tailspin Toys is migrating their on-premises SQL Server database to Azure SQL Managed Instance. In this task, you will review some security information in Microsoft Defender, security alerts, and recommendations.

Description

In this task, you will review some security information in Microsoft Defender, security alerts, and recommendations.

The key tasks are as follows:

  1. Enable Microsoft Defender for Cloud.
  2. Review the security alerts in Microsoft Defender.
  3. Review Microsoft Defender Recommendations

Success Criteria

  • Successfully reviewed Defender alerts, and recommendations.

Solution

Expand this section to view the solution
  1. Return to the Azure portal and navigate to the resource group where you have the Azure SQL MI instance for your lab deployed.

  2. Select your SQL managed instance resource.

  3. On the SQL managed instance blade, expand Security in the left navigation menu select Microsoft Defender for Cloud.

  4. In the Microsoft Defender for SQL page, select Enable to enable Microsoft Defender for SQL for your SQL MI instance.

    Defender

    NOTE: Selecting the Microsoft Defender for Cloud option on the left menu of the SQL MI resource blade may take you to the Microsoft Defender for Cloud page. To get back to the Microsoft Defender for SQL specific to your SQL MI instance, select the tailspin<uniqueid>-sqlmi|Microsoft Defender for Cloud breadcrumb at the top of the page. From there, you can select Enable to enable Microsoft Defender for SQL for that SQL MI instance.

  5. After a couple of minutes, the enabling of the Microsoft Defender for SQL will complete successfully. Notice the 3 sections for Recommendations, Security incidents and alerts and Vulerability assessment finding. This is where you can view the content to investigate further any alerts, incidents or vulnerability assessments for your SQL MI instance.

    Security Alerts

  6. One of the recommendations will display Microsoft Defender for SQL should be enabled for unprotected SQL Managed Instances and it will be of severity HIGH. Select that recommendation to view its content.

    Unprotected SQL MI