We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Defender for SQL
Microsoft Defender for SQL, UAE

The classic SQL vulnerability assessment APIs retire on 16 August 2027. Express configuration is the destination.

Microsoft has published the date, and express configuration removes the customer-managed storage account entirely. It is the recommended enablement mode, provides the same security value with a simplified setup, and extends the Microsoft-managed experience at no additional cost.

Book a SQL security reviewSee what it covers
Microsoft Defender for SQL for UAE organisations
  • 16 Aug 2027Classic vulnerability assessment API retirement
  • No storageExpress needs no customer-managed account
  • SQL 2012 to 2022Server versions protected, plus Azure SQL
  • Subscription wideExisting and future resources protected
What Defender for SQL does

Eight things that decide how much value you get from it.

Defender for SQL does two distinct jobs: it finds configuration weaknesses in your databases, and it detects attacks against them. Most organisations enable it and use only the second, because the first requires a baseline nobody set.

Coverage across Azure SQL and SQL Server

Read and write replicas of Azure SQL single databases and elastic pools, Azure SQL managed instances and Azure Synapse Analytics dedicated SQL pools, plus SQL Server versions 2012 through 2022, SQL Server on Azure Virtual Machines and SQL Server enabled by Azure Arc.

Enablement that covers what comes next

When you enable the plan, all supported resources in the subscription are protected, and future resources created on the same subscription are protected too. That is what stops coverage decaying as project teams create databases, which is otherwise a permanent gap.

Vulnerability assessment against a rule knowledge base

A scanning service built into Azure SQL that uses a knowledge base of rules flagging security vulnerabilities and deviations from best practice, including misconfigurations, excessive permissions and unprotected sensitive data, at both database and server level.

Baselines, which is where the value actually is

An assessment report can be customised for your environment by setting an acceptable baseline for permission configurations, feature configurations and database settings. Without a baseline, every environment-specific design decision reappears as a finding forever and the report gets ignored.

Threat protection for the attacks that matter

Advanced Threat Protection continuously monitors for potential SQL injection attacks, anomalous database access and query patterns such as an abnormally high number of failed sign-ins with different credentials, and suspicious activity such as access from a computer that contacted a crypto-mining command and control server.

The classic API retirement date

The APIs used for classic vulnerability assessment configuration will be retired on 16 August 2027, together with the classic Defender for SQL Advanced Threat Protection APIs. Organisations still on classic have a known deadline and a documented migration path rather than an open-ended choice.

What express configuration changes

It removes the customer-managed storage account requirement entirely, with Defender for Cloud managing storage and results held in the same Azure region as the logical SQL server. Microsoft calls it the recommended enablement mode with the same security value and a simplified setup.

Baseline behaviour differs between the two models

In express configuration, applying a baseline takes effect without rescanning the database. In classic it takes effect only after rescanning. That single difference changes how quickly a tuning session converges, and it is the most practical argument for express beyond the storage account.

A dated migration, not an optional one

Classic vulnerability assessment and Advanced Threat Protection APIs retire on 16 August 2027.

Microsoft has published both the date and the migration guidance, which makes this one of the easier deadlines to plan around.

  • The APIs used for classic vulnerability assessment configuration retire on 16 August 2027, together with the classic Defender for SQL Advanced Threat Protection APIs. Anything automating configuration through those APIs, including infrastructure as code and scripts, needs to move before then.
  • Express configuration is the destination and it is already generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces, extending the generally available Microsoft-managed experience for Azure SQL Database at no additional cost.
  • The practical gains are immediate rather than deferred. Express removes the customer-managed storage account, simplifies the permissions needed to change settings, supports setting baselines in batch and from the latest scan results, and applies a baseline without requiring a rescan.
  • The trade-offs are real and small. Express supports policy scope at subscription and server level rather than database level, caps a single rule scan result at 1 MB where classic is unlimited, and exports to CSV rather than Excel. For almost every estate those are acceptable in exchange for removing the storage dependency.
Ask us to plan the express migration
How we approach it

Four things that make this more than an enabled checkbox.

Defender for SQL produces value in two directions and organisations reliably capture only one. The vulnerability assessment half is where the effort is and where the durable improvement comes from.

We baseline before we report

A vulnerability assessment can be customised by setting an acceptable baseline for permission configurations, feature configurations and database settings. Without that, every deliberate design decision in your environment reappears as a finding every scan, and the report becomes noise within two cycles.

We move to express configuration now

Classic vulnerability assessment APIs retire on 16 August 2027 alongside the classic Advanced Threat Protection APIs. Express removes the storage account, simplifies permissions, supports batch baselines and applies them without a rescan. There is no reason to wait for the deadline to collect those benefits.

We include the SQL nobody counts

SQL Server on Azure Virtual Machines and SQL Server enabled by Azure Arc are both protected, and both are routinely missed because the estate inventory was built from the Azure SQL resource list. Those instances frequently hold the older and less well maintained databases.

We make sure somebody receives the alerts

Threat protection detects SQL injection attempts, brute force patterns and access from compromised hosts, with mitigation guidance and a Sentinel investigation path. All of that assumes a named responder. Alerts arriving in an unwatched queue are indistinguishable from no detection at all.

How an engagement runs

Four phases across roughly four to six weeks.

Enablement is quick because it applies subscription wide. The time goes into baselining, which is what turns a long list of findings into a report somebody will read next month.
  1. 01
    Week 1

    Inventory the SQL estate and enable

    Azure SQL databases, elastic pools, managed instances, Synapse dedicated pools, SQL Server on virtual machines and Arc-enabled SQL Server. The plan enabled at subscription level so existing and future resources are covered without anybody remembering to add them.

    • SQL estate inventory across subscriptions
    • Plan enabled at subscription scope
    • Arc-enabled and VM-hosted SQL identified
    • Current configuration model established, express or classic
  2. 02
    Week 2

    Move to express configuration

    Migration from classic where it exists, removing the customer-managed storage account dependency and simplifying the permissions needed to change settings. Done now rather than closer to the August 2027 API retirement, because the operational benefits are immediate.

    • Express configuration enabled per resource type
    • Storage account dependency removed
    • Automation using classic APIs identified for migration
    • Permissions model updated
  3. 03
    Weeks 3 to 4

    Baseline the findings against your environment

    The phase that determines whether the report is useful. Baselines set for permission configurations, feature configurations and database settings, so environment-specific decisions stop appearing as findings. Express applies baselines without a rescan, which makes this iterative rather than slow.

    • Findings triaged with the database team
    • Baselines set for accepted configurations
    • Genuine findings assigned owners and dates
    • Remaining report reviewed for readability
  4. 04
    Weeks 5 to 6

    Route alerts and connect to investigation

    Threat protection alerts routed to whoever responds, with the Sentinel investigation path confirmed, and a recurring review of vulnerability findings so the baseline stays current as the estate changes rather than ossifying.

    • Alerts routed to a named responder
    • Sentinel investigation path confirmed
    • Recurring vulnerability review scheduled
    • Baseline maintenance owner assigned
Where this matters

Six situations where the database is the target.

The pattern is an organisation with good network and endpoint controls whose databases were secured once at deployment and not examined since.

A business with a customer-facing application

Any application accepting input and querying a database is a SQL injection candidate, and Advanced Threat Protection detects potential SQL injection attacks including vulnerabilities where applications generate a faulty SQL statement. That detection is the direct control for the most persistent web application risk.

A regulated firm asked about database configuration

Vulnerability assessment covers database-level and server-level issues including server firewall settings and server-level permissions, with actionable remediation steps and customised scripts where applicable. That produces evidence in the form auditors ask for rather than a general assurance.

An organisation with excessive database permissions

Excessive permissions are one of the categories the rule knowledge base flags explicitly, alongside misconfigurations and unprotected sensitive data. It is also the category that accumulates silently, because permissions get granted during projects and removed almost never.

A provider running older SQL Server versions

Protection covers SQL Server 2012 through 2022, including on Azure Virtual Machines and Arc-enabled instances. For estates carrying older versions because an application requires them, detection and vulnerability assessment are what make that decision manageable rather than simply accepted.

A company still using classic configuration

The classic vulnerability assessment APIs and the classic Advanced Threat Protection APIs both retire on 16 August 2027. Anything automating configuration through them needs to move, and express configuration delivers immediate operational benefits rather than merely satisfying a deadline.

A business whose database estate keeps growing

Enabling the plan protects all supported resources in the subscription and future resources created on the same subscription. For organisations where project teams create databases regularly, that automatic inclusion is worth more than any individual detection.

Three positions

How UAE organisations secure their SQL estate.

The middle column is the most common: the plan is enabled, alerts arrive, and the vulnerability assessment report has never been triaged because nobody baselined it.
SQL injection detection
Enabled, express, baselinedYes
Enabled, not baselinedYes
Not enabledNo
Brute force detection
Enabled, express, baselinedYes
Enabled, not baselinedYes
Not enabledNo
Vulnerability findings produced
Enabled, express, baselinedYes
Enabled, not baselinedYes
Not enabledNo
Findings actually triaged
Enabled, express, baselinedYes
Enabled, not baselinedNo
Not enabledNot applicable
Environment baselined
Enabled, express, baselinedYes
Enabled, not baselinedNo
Not enabledNot applicable
Storage account dependency
Enabled, express, baselinedNone
Enabled, not baselinedLikely still present
Not enabledNot applicable
Ready for the 2027 API retirement
Enabled, express, baselinedYes
Enabled, not baselinedNot yet
Not enabledNot applicable
Future databases covered
Enabled, express, baselinedAutomatically
Enabled, not baselinedAutomatically
Not enabledNo
Alerts routed to a responder
Enabled, express, baselinedYes
Enabled, not baselinedSometimes
Not enabledNot applicable
Report read next month
Enabled, express, baselinedYes
Enabled, not baselinedNo
Not enabledNot applicable
Feature
Enabled, express, baselined
Enabled, not baselined
Not enabled
SQL injection detection
YesYesNo
Brute force detection
YesYesNo
Vulnerability findings produced
YesYesNo
Findings actually triaged
YesNoNot applicable
Environment baselined
YesNoNot applicable
Storage account dependency
NoneLikely still presentNot applicable
Ready for the 2027 API retirement
YesNot yetNot applicable
Future databases covered
AutomaticallyAutomaticallyNo
Alerts routed to a responder
YesSometimesNot applicable
Report read next month
YesNoNot applicable
Express against classic

Ten documented differences between the two configuration models.

Taken from the published comparison table. The baseline rows are the ones that change day to day work, and the storage row is the one that changes the architecture.
ParameterExpress configurationClassic configuration
Storage dependencyNone, Microsoft managedA customer-managed Azure storage account
Applying a baselineTakes effect without rescanningTakes effect only after rescanning
Baseline settingsBatch, from latest results, or single ruleSingle rule only
Recurring scanAlways activeConfigurable on or off
Scan schedulingInternal, not configurableInternal, not configurable
Policy scopeSubscription and serverSubscription, server and database
Single rule scan result sizeMaximum of 1 MBUnlimited
Scan exportCSV and Azure Resource GraphExcel format and Azure Resource Graph
Permissions to change settingsSQL Security Manager or security adminPlus Storage Blob Data Reader and storage account Owner
Data residencySame region as the logical SQL serverWherever the storage account is
How an engagement runs

Five steps, and the baseline is the one that determines whether it lasts.

Enablement takes minutes and covers everything present and future. Making the findings useful takes a fortnight and is the difference between a control and a report.
  1. 1

    Inventory the whole SQL estate

    Azure SQL databases and elastic pools, managed instances, Synapse dedicated pools, plus SQL Server on Azure Virtual Machines and Arc-enabled SQL Server. The last two are supported and routinely missed, and they frequently hold the oldest databases in the environment.

  2. 2

    Enable at subscription level

    All supported resources in the subscription are then protected, and so are future resources created on the same subscription. That automatic inclusion is what prevents coverage drifting as teams create databases without telling anybody.

  3. 3

    Move to express configuration

    Removing the customer-managed storage account and the additional permissions it requires, ahead of the classic API retirement on 16 August 2027. Express also supports batch baseline setting and applies baselines without requiring a rescan, which makes the next step considerably faster.

  4. 4

    Baseline against your actual environment

    Findings triaged with the database team, and acceptable configurations recorded as a baseline for permission configurations, feature configurations and database settings. What remains after that is the genuine finding list, and it gets owners and dates.

  5. 5

    Route alerts and keep the baseline current

    Threat protection alerts to a named responder with the Sentinel investigation path confirmed, and a recurring review so the baseline reflects the environment as it changes rather than as it was when somebody last looked at it.

Straight answers

What organisations ask about Defender for SQL.

Read and write replicas of Azure SQL single databases and elastic pools, Azure SQL managed instances and Azure Synapse Analytics dedicated SQL pools. It also protects SQL Server versions 2012 through 2022, SQL Server on Azure Virtual Machines, and SQL Server enabled by Azure Arc.

No. When you enable Defender for Azure SQL Databases, all supported resources within the subscription are protected, and future resources created on the same subscription are protected too. That automatic inclusion is one of the stronger arguments for subscription level enablement.

Potential SQL injection attacks, including cases where an application generates a faulty SQL statement. Anomalous database access and query patterns, such as an abnormally high number of failed sign-in attempts with different credentials. And suspicious activity such as a legitimate user connecting from a machine that contacted a crypto-mining command and control server.

Express has Defender for Cloud manage storage for scan results, so no customer-managed storage account is required, and results are stored in the same Azure region as the logical SQL server. Classic stores results in a storage account you configure and control. Microsoft describes express as the recommended enablement mode with the same security value.

Yes. The APIs used for classic vulnerability assessment configuration retire on 16 August 2027, together with the classic Defender for SQL Advanced Threat Protection APIs. Microsoft publishes migration guidance, and anything automating configuration through those APIs needs to move before that date.

Three documented things, all minor for most estates. Policy scope is subscription and server rather than including database level. A single rule scan result is capped at 1 MB where classic is unlimited. And scan export is CSV rather than Excel format, with Azure Resource Graph available in both.

Because nobody has set a baseline. An assessment report can be customised for your environment by setting an acceptable baseline for permission configurations, feature configurations and database settings. Without one, deliberate design decisions in your environment are reported as findings on every scan indefinitely.

It depends on the configuration model, and the difference is significant. In express configuration, applying a baseline takes effect without rescanning the database. In classic configuration it takes effect only after rescanning. That makes baseline tuning much faster on express.

Not the schedule. In both models, scan scheduling is internal and not configurable. What differs is that recurring scan is always active in express, whereas classic lets you turn recurring scanning on or off. Manual scans are available in both.

A knowledge base flagging security vulnerabilities and deviations from best practice, including misconfigurations, excessive permissions and unprotected sensitive data. Rules cover both database-level issues and server-level security issues such as server firewall settings and server-level permissions.

Viewing results in Defender for Cloud recommendations needs Security Admin or Security Reader in both models. Changing settings needs SQL Security Manager or security admin in express, whereas classic additionally requires Storage Blob Data Reader and Owner on the storage account, which is a meaningfully wider grant.

In express configuration, in the same Azure region as the logical SQL server, with data collected and stored only when SQL vulnerability assessment is enabled. In classic, in the Azure storage account you configure, so the storage account location determines data residency.

Yes. Alerts include details of the suspicious activity, guidance on mitigating the threat, and options for continuing investigations using Microsoft Sentinel. For organisations already running Sentinel, that keeps database alerts in the same investigative workflow as everything else.

Yes, both SQL Server on Azure Virtual Machines and SQL Server enabled by Azure Arc. Those are the instances most often missing from a SQL estate inventory, because that inventory usually starts from the Azure SQL resource list rather than from where databases actually run.

We scope by the number of subscriptions and the size of the SQL estate, including Arc-enabled and VM-hosted instances. The free first step: check whether your vulnerability assessment is on classic configuration. If it is, you have a dated migration ahead and immediate benefits available from doing it early.

Yes, and that is one of the stronger reasons to enable at subscription level. When you enable Defender for Azure SQL Databases, all supported resources within the subscription are protected, and future resources created on the same subscription are protected too, without anybody remembering to add them.

A knowledge base of rules flagging security vulnerabilities and deviations from best practice, focused on the issues that present the biggest risks to the database and its data. It covers database-level issues and server-level security issues such as server firewall settings and server-level permissions.

Both. Scan results include actionable steps to resolve each issue and provide customised remediation scripts where applicable. That is what makes the output usable by a database team directly, rather than requiring a security engineer to translate each finding into an action first.

Alerts are action oriented and include details of the suspicious activity, guidance on mitigating the threat, and options for continuing investigations using Microsoft Sentinel. For organisations already running Sentinel, database alerts land in the same investigative workflow as everything else rather than in a separate console.

Express configuration is generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces, extending the generally available Microsoft-managed experience for Azure SQL Database. A unified REST API also manages SQL vulnerability assessment across those plus SQL on machines, covering Azure VM and Arc-enabled SQL.

Yes, and this is the step that makes reports usable. An assessment report can be customised by setting an acceptable baseline for permission configurations, feature configurations and database settings, so deliberate design decisions in your environment stop being reported as findings on every scan.

Security vulnerabilities and deviations from best practice, including misconfigurations, excessive permissions and unprotected sensitive data. The rules are based on Microsoft best practices and focus on the issues presenting the biggest risks to the database and its data, at both database and server level.
Configuration review

Fifteen questions about your own SQL estate.

The middle group is where most of the value sits, because a vulnerability assessment nobody has baselined is a report nobody reads.

Coverage

  • Is the plan enabled at subscription level?
    Future resources are then covered.
  • Is SQL Server on VMs included?
    Supported, and often forgotten.
  • Do we have Arc-enabled SQL Server?
    Also supported.
  • Are Synapse dedicated pools covered?
    They are in scope.
  • Which SQL Server versions do we run?
    2012 through 2022 are protected.

Vulnerability assessment

  • Are we on express or classic?
    Classic APIs retire in August 2027.
  • Do we still have a VA storage account?
    Express removes the need.
  • Has anybody set a baseline?
    Otherwise findings never clear.
  • Who reviews the findings?
    Name them.
  • Do server-level findings have an owner?
    Firewall and permissions.

Threat protection

  • Where do SQL alerts go?
    A person, not a queue.
  • Have we ever received one?
    Or tested the path.
  • Is Sentinel connected for investigation?
    Alerts support that route.
  • Do we automate config with classic APIs?
    They have a retirement date.
  • Who owns database security overall?
    Often nobody.
Related reading

The pages around this one.

Microsoft Defender for Cloud

The parent product and the other workload protection plans.

Learn more

Defender for Servers

Protecting the machines these databases run on.

Learn more

Azure security audit

The wider review of an Azure environment.

Learn more
Next step

Check whether your SQL vulnerability assessment is still on classic configuration.

The classic APIs retire on 16 August 2027, and express removes the storage account, simplifies permissions and applies baselines without a rescan. The benefits of moving arrive well before the deadline does.

Book a SQL security reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Defender for Cloud

Azure posture, and the free tier almost nobody has enabled

Learn more

Defender for Servers

Plan 1 versus Plan 2, and the Azure Arc dependency

Learn more

Azure Security Audit

Subscription audit, starting with the free tier you already own

Learn more

Defender for Storage

Scanning uploads before they reach anyone

Learn more

Cloud Security Posture Audit

The real inventory, then configuration and identity

Learn more

Defender Vulnerability Management

Certificates, browser extensions and firmware, not just patching

Learn more

Azure Cloud Solutions

Azure landing zone, migration, FinOps, managed

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy