Part of Defender for SQL that raises alerts for possible SQL injection, code vulnerable to injection, brute-force attacks and access by unusual principals or from unusual locations.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Advanced Threat Protection in context, with comparison tables and the common traps.
Terms in this definition
- Serverless
Compute tier for single Azure SQL databases that scales automatically, pauses when idle and charges by the second. It is offered in General Purpose and Hyperscale, not Business Critical, and reserved capacity does not apply.
- SQL injection
Smuggling SQL into the input an application accepts. NSGs cannot detect it; WAF managed rule sets, such as those on Application Gateway, stop it at the web tier, and Microsoft Defender for SQL alerts on it.
Related terms
- ForceDefenderPassiveMode
Setting this
REG_DWORDto 1 before a Windows Server is onboarded switches its Defender Antivirus into passive mode; the value lives under HKLM\SOFTWARE\Policies\Microsoft\Windows Advanced Threat Protection. - Microsoft Defender for SQL
Combines SQL vulnerability assessment with Advanced Threat Protection, which alerts on brute force, SQL injection and anomalous access. As a Defender for Cloud plan it detects threats; it doesn't mask or encrypt data.