Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
There are several ways to view Microsoft Defender for SQL alerts in Microsoft Defender for Cloud:
The Alerts page.
The machine's security page.
Through the direct link provided in the alert's email.
Sign in to the Azure portal.
Search for and select Microsoft Defender for Cloud.
Select Security alerts.
Select an alert.
Alerts are designed to be self-contained, with detailed remediation steps and investigation information in each one. You can investigate further by using other Microsoft Defender for Cloud and Microsoft Sentinel capabilities for a broader view:
Enable SQL Server's auditing feature for further investigations. If you're a Microsoft Sentinel user, you can upload the SQL auditing logs from the Windows Security Log events to Sentinel and enjoy a rich investigation experience. Learn more about SQL Server Auditing.
To improve your security posture, use Defender for Cloud's recommendations for the host machine indicated in each alert to reduce the risks of future attacks.
Learn more about managing and responding to alerts.
For related information, see these resources: