News

Microsoft Brings Advanced Threat Protection to Azure SQL

The latest addition to Microsoft's sprawling Advanced Threat Protection (ATP) product line, SQL ATP, is now available for Azure SQL Database users.

Described by Microsoft as "a new security package," SQL ATP has three main capabilities: "Data Discovery and Classification," "Threat Detection" and "Vulnerability Assessment." While the Data Discovery and Classification segment is still at the preview stage, the latter two capabilities are now production-ready, with Vulnerability Assessment having reached "general availability" status this week.

SQL ATP can be accessed through the Azure Portal or the Azure Security Center. Microsoft charges for using SQL ATP, although there's a 60-day free trial. Pricing for SQL ATP seemed to be unlisted at press time. However, this Microsoft overview article suggested that the costs are similar to Azure Security Center pricing.

"ATP pricing aligns with Azure Security Center standard tier at $15/node/month, where each protected SQL Database server is counted as one node," the article stated.

It also appears that some of the three SQL ATP capabilities, which are built into the Azure SQL Database service, can be used by organizations running SQL Server "on-premises" (that is, on their own infrastructure and not using Azure services). The capabilities are available through SQL Server Management Studio (SSMS). For instance, Microsoft's announcement explained that "VA [Vulnerability Assessment] is available for Azure SQL Database customers as well as for on-premises SQL Server customers via SSMS."

Microsoft is touting the Vulnerability Assessment segment of SQL ATP as being a useful means for meeting compliance standards, including the European Union's General Data Protection Regulation (GDPR) privacy stipulations, which will become enforceable law on May 25. Vulnerability Assessment is based on Microsoft best practices and will run a scan for "misconfigurations, excessive permissions and unprotected sensitive data," per Microsoft's documentation. Users get a report plus "actionable steps to resolve each issue," along with "customized remediation scripts where applicable."

Threat Detection performs continuous monitoring of databases. It provides users with alerts about "suspicious database activities, potential vulnerabilities, and SQL injection attacks, as well as anomalous database access patterns," according to Microsoft's documentation. It also provides recommended actions to take.

The Data Discovery and Classification segment provides a means for scanning and identifying sensitive data within databases. Microsoft also touts it as being useful for staying compliant with the GDPR. Users can add metadata labels to classify the data. Details show up in a dashboard view.

About the Author

Kurt Mackie is senior news producer for 1105 Media's Converge360 group.

Featured

  • Microsoft Dismantles RedVDS Cybercrime Marketplace Linked to $40M in Phishing Fraud

    In a coordinated action spanning the United States and the United Kingdom, Microsoft’s Digital Crimes Unit (DCU) and international law enforcement collaborators have taken down RedVDS, a subscription based cybercrime platform tied to an estimated $40 million in fraud losses in the U.S. since March 2025.

  • Sound Wave Illustration

    CrowdStrike's Acquisition of SGNL Aims to Strengthen Identity Security

    CrowdStrike signs definitive agreement to purchase SGNL, an identity security specialist, in a deal valued at about $740 million.

  • Microsoft Acquires Osmos, Automating Data Engineering inside Fabric

    In a strategic move to reduce time-consuming manual data preparation, Microsoft has acquired Seattle-based startup Osmos, specializing in agentic AI for data engineering.

  • Linux Foundation Unites Major Tech Firms to Launch Agentic AI Foundation

    The Linux Foundation today announced the creation of a new collaborative initiative — the Agentic AI Foundation (AAIF) — bringing together major AI and cloud players such as Microsoft, OpenAI, Anthropic and other major tech companies.