High - Microsoft Defender for Cloud, Azure SQL Server Vulnerability Assessment - Microsoft primary source
Microsoft Defender for Cloud Security Recommendations and Alerts Updates
Microsoft Defender for Cloud announced significant updates including deprecation of legacy grouped recommendations starting July 31, 2026, and the general availability release of granular, database-level SQL Server security recommendations transitioning from server-level grouped assessments on July 26, 2026. These changes improve security visibility and control for SQL Server environments.
What changed
The retirement of legacy grouped (sub-assessment) recommendations commenced, removing their API accessibility and eventual portal reflection delays. Defender for Cloud introduced multiple individual security recommendations targeting SQL Server databases, replacing broader server-level grouped recommendations. This provides detailed guidance on permissions, authentication, auditing, encryption, configuration, and unnecessary features for SQL Servers and databases.
Why it matters operationally
Organizations using Defender for Cloud must transition to the new individual database-level recommendations for SQL Vulnerability Assessment and update any automated processes or scripts relying on deprecated grouped recommendations' data. Security posture management should leverage the granular controls for improved risk identification and mitigation in SQL Server environments.
What the SOC should check
Validate affected Microsoft products, confirm whether controls or detections need tuning, and record any change-management or monitoring actions.
Recommended actions
- Review the list of new SQL Server database-level recommendations and implement applicable security controls.
- Modify scripts or tools that depend on deprecated grouped recommendations data from the Defender for Cloud API.
- Monitor the Azure portal and Azure Resource Graph for updated recommendations visibility as the changes propagate.
- Educate security and database teams about the enhanced and more granular recommendations for SQL Server security.
- Ensure SQL Server instances are audited and configured according to the new recommendations to reduce risk exposure.
Source links
https://learn.microsoft.com/en-us/azure/defender-for-cloud/release-notes-recommendations-alerts