The classic SQL vulnerability assessment APIs retire on 16 August 2027. Express configuration is the destination.
Microsoft has published the date, and express configuration removes the customer-managed storage account entirely. It is the recommended enablement mode, provides the same security value with a simplified setup, and extends the Microsoft-managed experience at no additional cost.

- 16 Aug 2027Classic vulnerability assessment API retirement
- No storageExpress needs no customer-managed account
- SQL 2012 to 2022Server versions protected, plus Azure SQL
- Subscription wideExisting and future resources protected
Eight things that decide how much value you get from it.
Coverage across Azure SQL and SQL Server
Read and write replicas of Azure SQL single databases and elastic pools, Azure SQL managed instances and Azure Synapse Analytics dedicated SQL pools, plus SQL Server versions 2012 through 2022, SQL Server on Azure Virtual Machines and SQL Server enabled by Azure Arc.
Enablement that covers what comes next
When you enable the plan, all supported resources in the subscription are protected, and future resources created on the same subscription are protected too. That is what stops coverage decaying as project teams create databases, which is otherwise a permanent gap.
Vulnerability assessment against a rule knowledge base
A scanning service built into Azure SQL that uses a knowledge base of rules flagging security vulnerabilities and deviations from best practice, including misconfigurations, excessive permissions and unprotected sensitive data, at both database and server level.
Baselines, which is where the value actually is
An assessment report can be customised for your environment by setting an acceptable baseline for permission configurations, feature configurations and database settings. Without a baseline, every environment-specific design decision reappears as a finding forever and the report gets ignored.
Threat protection for the attacks that matter
Advanced Threat Protection continuously monitors for potential SQL injection attacks, anomalous database access and query patterns such as an abnormally high number of failed sign-ins with different credentials, and suspicious activity such as access from a computer that contacted a crypto-mining command and control server.
The classic API retirement date
The APIs used for classic vulnerability assessment configuration will be retired on 16 August 2027, together with the classic Defender for SQL Advanced Threat Protection APIs. Organisations still on classic have a known deadline and a documented migration path rather than an open-ended choice.
What express configuration changes
It removes the customer-managed storage account requirement entirely, with Defender for Cloud managing storage and results held in the same Azure region as the logical SQL server. Microsoft calls it the recommended enablement mode with the same security value and a simplified setup.
Baseline behaviour differs between the two models
In express configuration, applying a baseline takes effect without rescanning the database. In classic it takes effect only after rescanning. That single difference changes how quickly a tuning session converges, and it is the most practical argument for express beyond the storage account.
Classic vulnerability assessment and Advanced Threat Protection APIs retire on 16 August 2027.
Microsoft has published both the date and the migration guidance, which makes this one of the easier deadlines to plan around.
- The APIs used for classic vulnerability assessment configuration retire on 16 August 2027, together with the classic Defender for SQL Advanced Threat Protection APIs. Anything automating configuration through those APIs, including infrastructure as code and scripts, needs to move before then.
- Express configuration is the destination and it is already generally available for Azure SQL Managed Instance and Azure Synapse Analytics Workspaces, extending the generally available Microsoft-managed experience for Azure SQL Database at no additional cost.
- The practical gains are immediate rather than deferred. Express removes the customer-managed storage account, simplifies the permissions needed to change settings, supports setting baselines in batch and from the latest scan results, and applies a baseline without requiring a rescan.
- The trade-offs are real and small. Express supports policy scope at subscription and server level rather than database level, caps a single rule scan result at 1 MB where classic is unlimited, and exports to CSV rather than Excel. For almost every estate those are acceptable in exchange for removing the storage dependency.
Four things that make this more than an enabled checkbox.
We baseline before we report
A vulnerability assessment can be customised by setting an acceptable baseline for permission configurations, feature configurations and database settings. Without that, every deliberate design decision in your environment reappears as a finding every scan, and the report becomes noise within two cycles.
We move to express configuration now
Classic vulnerability assessment APIs retire on 16 August 2027 alongside the classic Advanced Threat Protection APIs. Express removes the storage account, simplifies permissions, supports batch baselines and applies them without a rescan. There is no reason to wait for the deadline to collect those benefits.
We include the SQL nobody counts
SQL Server on Azure Virtual Machines and SQL Server enabled by Azure Arc are both protected, and both are routinely missed because the estate inventory was built from the Azure SQL resource list. Those instances frequently hold the older and less well maintained databases.
We make sure somebody receives the alerts
Threat protection detects SQL injection attempts, brute force patterns and access from compromised hosts, with mitigation guidance and a Sentinel investigation path. All of that assumes a named responder. Alerts arriving in an unwatched queue are indistinguishable from no detection at all.
Four phases across roughly four to six weeks.
- 01Week 1
Inventory the SQL estate and enable
Azure SQL databases, elastic pools, managed instances, Synapse dedicated pools, SQL Server on virtual machines and Arc-enabled SQL Server. The plan enabled at subscription level so existing and future resources are covered without anybody remembering to add them.
- SQL estate inventory across subscriptions
- Plan enabled at subscription scope
- Arc-enabled and VM-hosted SQL identified
- Current configuration model established, express or classic
- 02Week 2
Move to express configuration
Migration from classic where it exists, removing the customer-managed storage account dependency and simplifying the permissions needed to change settings. Done now rather than closer to the August 2027 API retirement, because the operational benefits are immediate.
- Express configuration enabled per resource type
- Storage account dependency removed
- Automation using classic APIs identified for migration
- Permissions model updated
- 03Weeks 3 to 4
Baseline the findings against your environment
The phase that determines whether the report is useful. Baselines set for permission configurations, feature configurations and database settings, so environment-specific decisions stop appearing as findings. Express applies baselines without a rescan, which makes this iterative rather than slow.
- Findings triaged with the database team
- Baselines set for accepted configurations
- Genuine findings assigned owners and dates
- Remaining report reviewed for readability
- 04Weeks 5 to 6
Route alerts and connect to investigation
Threat protection alerts routed to whoever responds, with the Sentinel investigation path confirmed, and a recurring review of vulnerability findings so the baseline stays current as the estate changes rather than ossifying.
- Alerts routed to a named responder
- Sentinel investigation path confirmed
- Recurring vulnerability review scheduled
- Baseline maintenance owner assigned
Six situations where the database is the target.
A business with a customer-facing application
Any application accepting input and querying a database is a SQL injection candidate, and Advanced Threat Protection detects potential SQL injection attacks including vulnerabilities where applications generate a faulty SQL statement. That detection is the direct control for the most persistent web application risk.
A regulated firm asked about database configuration
Vulnerability assessment covers database-level and server-level issues including server firewall settings and server-level permissions, with actionable remediation steps and customised scripts where applicable. That produces evidence in the form auditors ask for rather than a general assurance.
An organisation with excessive database permissions
Excessive permissions are one of the categories the rule knowledge base flags explicitly, alongside misconfigurations and unprotected sensitive data. It is also the category that accumulates silently, because permissions get granted during projects and removed almost never.
A provider running older SQL Server versions
Protection covers SQL Server 2012 through 2022, including on Azure Virtual Machines and Arc-enabled instances. For estates carrying older versions because an application requires them, detection and vulnerability assessment are what make that decision manageable rather than simply accepted.
A company still using classic configuration
The classic vulnerability assessment APIs and the classic Advanced Threat Protection APIs both retire on 16 August 2027. Anything automating configuration through them needs to move, and express configuration delivers immediate operational benefits rather than merely satisfying a deadline.
A business whose database estate keeps growing
Enabling the plan protects all supported resources in the subscription and future resources created on the same subscription. For organisations where project teams create databases regularly, that automatic inclusion is worth more than any individual detection.
How UAE organisations secure their SQL estate.
| Feature | Enabled, express, baselined | Enabled, not baselined | Not enabled |
|---|---|---|---|
SQL injection detection | Yes | Yes | No |
Brute force detection | Yes | Yes | No |
Vulnerability findings produced | Yes | Yes | No |
Findings actually triaged | Yes | No | Not applicable |
Environment baselined | Yes | No | Not applicable |
Storage account dependency | None | Likely still present | Not applicable |
Ready for the 2027 API retirement | Yes | Not yet | Not applicable |
Future databases covered | Automatically | Automatically | No |
Alerts routed to a responder | Yes | Sometimes | Not applicable |
Report read next month | Yes | No | Not applicable |
Ten documented differences between the two configuration models.
| Parameter | Express configuration | Classic configuration | |
|---|---|---|---|
| Storage dependency | None, Microsoft managed | A customer-managed Azure storage account | |
| Applying a baseline | Takes effect without rescanning | Takes effect only after rescanning | |
| Baseline settings | Batch, from latest results, or single rule | Single rule only | |
| Recurring scan | Always active | Configurable on or off | |
| Scan scheduling | Internal, not configurable | Internal, not configurable | |
| Policy scope | Subscription and server | Subscription, server and database | |
| Single rule scan result size | Maximum of 1 MB | Unlimited | |
| Scan export | CSV and Azure Resource Graph | Excel format and Azure Resource Graph | |
| Permissions to change settings | SQL Security Manager or security admin | Plus Storage Blob Data Reader and storage account Owner | |
| Data residency | Same region as the logical SQL server | Wherever the storage account is |
Five steps, and the baseline is the one that determines whether it lasts.
- 1
Inventory the whole SQL estate
Azure SQL databases and elastic pools, managed instances, Synapse dedicated pools, plus SQL Server on Azure Virtual Machines and Arc-enabled SQL Server. The last two are supported and routinely missed, and they frequently hold the oldest databases in the environment.
- 2
Enable at subscription level
All supported resources in the subscription are then protected, and so are future resources created on the same subscription. That automatic inclusion is what prevents coverage drifting as teams create databases without telling anybody.
- 3
Move to express configuration
Removing the customer-managed storage account and the additional permissions it requires, ahead of the classic API retirement on 16 August 2027. Express also supports batch baseline setting and applies baselines without requiring a rescan, which makes the next step considerably faster.
- 4
Baseline against your actual environment
Findings triaged with the database team, and acceptable configurations recorded as a baseline for permission configurations, feature configurations and database settings. What remains after that is the genuine finding list, and it gets owners and dates.
- 5
Route alerts and keep the baseline current
Threat protection alerts to a named responder with the Sentinel investigation path confirmed, and a recurring review so the baseline reflects the environment as it changes rather than as it was when somebody last looked at it.
What organisations ask about Defender for SQL.
Fifteen questions about your own SQL estate.
Coverage
- Is the plan enabled at subscription level?Future resources are then covered.
- Is SQL Server on VMs included?Supported, and often forgotten.
- Do we have Arc-enabled SQL Server?Also supported.
- Are Synapse dedicated pools covered?They are in scope.
- Which SQL Server versions do we run?2012 through 2022 are protected.
Vulnerability assessment
- Are we on express or classic?Classic APIs retire in August 2027.
- Do we still have a VA storage account?Express removes the need.
- Has anybody set a baseline?Otherwise findings never clear.
- Who reviews the findings?Name them.
- Do server-level findings have an owner?Firewall and permissions.
Threat protection
- Where do SQL alerts go?A person, not a queue.
- Have we ever received one?Or tested the path.
- Is Sentinel connected for investigation?Alerts support that route.
- Do we automate config with classic APIs?They have a retirement date.
- Who owns database security overall?Often nobody.
Check whether your SQL vulnerability assessment is still on classic configuration.
The classic APIs retire on 16 August 2027, and express removes the storage account, simplifies permissions and applies baselines without a rescan. The benefits of moving arrive well before the deadline does.
Related Services
Explore more solutions that work great with this service
Defender for Cloud
Azure posture, and the free tier almost nobody has enabled
Defender for Servers
Plan 1 versus Plan 2, and the Azure Arc dependency
Azure Security Audit
Subscription audit, starting with the free tier you already own
Defender for Storage
Scanning uploads before they reach anyone
Cloud Security Posture Audit
The real inventory, then configuration and identity
Defender Vulnerability Management
Certificates, browser extensions and firmware, not just patching
Azure Cloud Solutions
Azure landing zone, migration, FinOps, managed
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own