diff --git a/en/azure/sqlserver/sql-server-advanced-threat-protection-enabled.md b/en/azure/sqlserver/sql-server-advanced-threat-protection-enabled.md new file mode 100644 index 000000000..67e0c64bd --- /dev/null +++ b/en/azure/sqlserver/sql-server-advanced-threat-protection-enabled.md @@ -0,0 +1,28 @@ +[![CloudSploit](https://cloudsploit.com/img/logo-new-big-text-100.png "CloudSploit")](https://cloudsploit.com) + +# AZURE / SQL Server / SQL Server Advanced Threat Protection Enabled + +## Quick Info + +| | | +|-|-| +| **Plugin Title** | SQL Server Advanced Threat Protection Enabled | +| **Cloud** | AZURE | +| **Category** | SQL Server | +| **Description** | Ensures that Advanced Threat Protection is enabled on SQL Servers. | +| **More Info** | Azure Defender for SQL is a unified package for advanced SQL security capabilities. | +| **AZURE Link** | https://learn.microsoft.com/en-us/azure/azure-sql/database/azure-defender-for-sql | +| **Recommended Action** | Ensure that ThreatDetectionState is set to Enabled. | + +## Detailed Remediation Steps + +1. Log in to the Microsoft Azure Management Console. +2. Select the "Search resources, services, and docs" option at the top and search for "SQL servers".
+3. On the "SQL server" page, select the SQL server that needs to be examined.
+4. On the selected "SQL server" page, scroll down the left navigation panel and select "Microsoft defender for cloud" under "Security".
+5. On the "Microsoft Defender for Cloud" page, if the "Microsoft Defender for SQL" is "Disabled" then the selected "SQL server" does not ensure that the server data is encrypted and monitored for unusual activity, vulnerabilities and threats.
+6. To ensure that Advanced Threat Protection is enabled for the selected server, on the "Microsoft Defender for Cloud" page, click on "Enabled" button to enable the Microsoft Defender for SQL.
+7. Once the Microsoft Defender is enable , you can see the vulnerabilities and threats.
+8. On the "Microsoft Defender for Cloud" page, click on "Configure" next to Enabled at the subscription-level.
+9. Here we can see by enabling Microsoft Defender for SQL , Vulnerability Assessment and Advanced Threat Protection are also enabled.
+10. Repeat steps number 3 - 6 to ensure that Advanced Threat Protection is enabled for all SQL Servers.
diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step2.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step2.png new file mode 100644 index 000000000..927714083 Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step2.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step3.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step3.png new file mode 100644 index 000000000..ef1ee660f Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step3.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step4.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step4.png new file mode 100644 index 000000000..72f27d9e9 Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step4.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step5.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step5.png new file mode 100644 index 000000000..95f1184a7 Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step5.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step6.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step6.png new file mode 100644 index 000000000..0a0bbdf6e Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step6.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step7.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step7.png new file mode 100644 index 000000000..55436daa9 Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step7.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step8.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step8.png new file mode 100644 index 000000000..860a90bad Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step8.png differ diff --git a/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step9.png b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step9.png new file mode 100644 index 000000000..b71160530 Binary files /dev/null and b/resources/azure/sqlserver/sql-server-advanced-threat-protection-enabled/step9.png differ