You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
title: Microsoft Defender for open-source relational databases
2
+
title: What is Defender for open-source databases
3
3
description: Learn about the benefits and features of Microsoft Defender for open-source relational databases such as PostgreSQL, MySQL, and MariaDB
4
-
ms.date: 06/19/2022
4
+
ms.date: 04/02/2024
5
5
ms.topic: overview
6
6
ms.author: dacurwin
7
7
author: dcurwin
8
+
#customer intent: As a reader, I want to understand the purpose and features of Microsoft Defender for open-source relational databases so that I can make informed decisions about its usage.
8
9
---
9
10
10
-
# Overview of Microsoft Defender for open-source relational databases
11
+
# What is Microsoft Defender for open-source relational databases
11
12
12
13
This plan brings threat protections for the following open-source relational databases:
13
14
@@ -19,15 +20,22 @@ Defender for Cloud detects anomalous activities indicating unusual and potential
19
20
20
21
## Availability
21
22
22
-
| Aspect | Details |
23
-
|--|:-|
24
-
| Release state: | General availability (GA) |
25
-
| Pricing: |**Microsoft Defender for open-source relational databases** is billed as shown on the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/)|
| Protected versions of PostgreSQL: | Single Server - General Purpose and Memory Optimized. Learn more in [PostgreSQL Single Server pricing tiers](../postgresql/concepts-pricing-tiers.md). Flexible Server - all pricing tiers (enablement is currently only supported at resource level).|
28
-
| Protected versions of MySQL: | Single Server - General Purpose and Memory Optimized. Learn more in [MySQL pricing tiers](../mysql/concepts-pricing-tiers.md). |
29
-
| Protected versions of MariaDB: | General Purpose and Memory Optimized. Learn more in [MariaDB pricing tiers](../mariadb/concepts-pricing-tiers.md). |
Check out the [pricing page](https://azure.microsoft.com/pricing/details/defender-for-cloud/) for pricing information for Microsoft Defender for open-source relational databases.
24
+
25
+
Defender for open-source relational database is supported on PaaS environments and not on Azure Arc-enabled machines.
26
+
27
+
**Protected versions of PostgreSQL include**:
28
+
- Single Server - General Purpose and Memory Optimized. Learn more in [PostgreSQL Single Server pricing tiers](../postgresql/concepts-pricing-tiers.md).
29
+
- Flexible Server - all pricing tiers.
30
+
31
+
**Protected versions of MySQL include**:
32
+
- Single Server - General Purpose and Memory Optimized. Learn more in [MySQL pricing tiers](../mysql/concepts-pricing-tiers.md).
33
+
- Flexible Server - all pricing tiers.
34
+
35
+
**Protected versions of MariaDB include**:
36
+
- General Purpose and Memory Optimized. Learn more in [MariaDB pricing tiers](../mariadb/concepts-pricing-tiers.md).
37
+
38
+
View [cloud availability](support-matrix-cloud-environment.md#cloud-support) for Defender for open-source relational databases
31
39
32
40
## What are the benefits of Microsoft Defender for open-source relational databases?
33
41
@@ -48,16 +56,14 @@ These alerts appear in Defender for Cloud's security alerts page and include:
48
56
49
57
Threat intelligence enriched security alerts are triggered when there are:
50
58
51
-
-**Anomalous database access and query patterns** - For example, an abnormally high number of failed sign-in attempts with different credentials (a brute force attempt)
52
-
-**Suspicious database activities** - For example, a legitimate user accessing an SQL Server from a breached computer which communicated with a crypto-mining C&C server
53
-
-**Brute-force attacks** – With the ability to separate simple brute force from brute force on a valid user or a successful brute force
59
+
-**Anomalous database access and query patterns** - For example, an abnormally high number of failed sign-in attempts with different credentials (a brute force attempt).
60
+
-**Suspicious database activities** - For example, a legitimate user accessing an SQL Server from a breached computer which communicated with a crypto-mining C&C server.
61
+
-**Brute-force attacks** – With the ability to separate simple brute force or a successful brute force.
54
62
55
63
> [!TIP]
56
64
> View the full list of security alerts for database servers [in the alerts reference page](alerts-reference.md#alerts-for-open-source-relational-databases).
57
65
58
-
## Next steps
59
-
60
-
In this article, you learned about Microsoft Defender for open-source relational databases.
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/defender-for-databases-usage.md
+9-8Lines changed: 9 additions & 8 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -1,11 +1,13 @@
1
1
---
2
-
title: Setting up and responding to alerts from Microsoft Defender for open-source relational databases
3
-
description: Learn how to configure Microsoft Defender for open-source relational databases to detect anomalous database activities indicating potential security threats to the database.
4
-
ms.date: 11/09/2021
2
+
title: Microsoft Defender for open-source relational databases
3
+
description: Configure Microsoft Defender for open-source relational databases to detect potential security threats.
4
+
ms.date: 04/02/2024
5
5
ms.topic: how-to
6
6
ms.author: dacurwin
7
7
author: dcurwin
8
+
#customer intent: As a reader, I want to learn how to configure Microsoft Defender for open-source relational databases to enhance the security of my databases.
8
9
---
10
+
9
11
# Enable Microsoft Defender for open-source relational databases and respond to alerts
10
12
11
13
Microsoft Defender for Cloud detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases for the following services:
@@ -59,13 +61,12 @@ Defender for Cloud sends email notifications when it detects anomalous database
59
61
60
62
1. For additional details and recommended actions for investigating the current threat and remediating future threats, select a specific alert.
61
63
62
-
:::image type="content" source="media/defender-for-databases-usage/specific-alert-details.png" alt-text="Details of a specific alert." lightbox="media/defender-for-databases-usage/specific-alert-details.png":::
64
+
:::image type="content" source="media/defender-for-databases-usage/specific-alert-details.png" alt-text="Screenshot that shows the details of a specific alert." lightbox="media/defender-for-databases-usage/specific-alert-details.png":::
63
65
64
66
> [!TIP]
65
67
> For a detailed tutorial on how to handle your alerts, see [Manage and respond to alerts](tutorial-security-incident.md).
66
68
67
-
## Next steps
69
+
## Next step
68
70
69
-
-[Automate responses to Defender for Cloud triggers](workflow-automation.md)
70
-
-[Stream alerts to a SIEM, SOAR, or ITSM solution](export-to-siem.md)
71
-
-[Suppress alerts from Defender for Cloud](alerts-suppression-rules.md)
71
+
> [!div class="nextstepaction"]
72
+
> [Automate responses to Defender for Cloud triggers](workflow-automation.md)
| April 3 |[Defender for open-source relational databases updates](#defender-for-open-source-relational-databases-updates)|
27
28
| April 2 |[Update to recommendations to align with Azure AI Services resources](#update-to-recommendations-to-align-with-azure-ai-services-resources)|
28
29
| April 2 |[Deprecation of Cognitive Services recommendation](#deprecation-of-cognitive-services-recommendation)|
29
30
| April 2 |[Containers multicloud recommendations (GA)](#containers-multicloud-recommendations-ga)|
30
31
32
+
### Defender for open-source relational databases updates
33
+
34
+
April 3, 2024
35
+
36
+
**Defender for PostgreSQL Flexible Servers post-GA updates** - The update enables customers to enforce protection for existing PostgreSQL flexible servers at the subscription level, allowing complete flexibility to enable protection on a per-resource basis or for automatic protection of all resources at the subscription level.
37
+
38
+
**Defender for MySQL Flexible Servers Availability and GA** - Defender for Cloud expanded its support for Azure open-source relational databases by incorporating MySQL Flexible Servers.
39
+
40
+
This release includes:
41
+
42
+
- Alert compatibility with existing alerts for Defender for MySQL Single Servers.
43
+
- Enablement of individual resources.
44
+
- Enablement at the subscription level.
45
+
46
+
If you're already protecting your subscription with Defender for open-source relational databases, your flexible server resources are automatically enabled, protected, and billed.
47
+
48
+
Specific billing notifications have been sent via email for affected subscriptions.
49
+
50
+
Learn more about [Microsoft Defender for open-source relational databases](defender-for-databases-introduction.md).
51
+
52
+
> [!NOTE]
53
+
> Updates for Azure Database for MySQL flexible servers are rolling out over the next few weeks. If you see the error message `The server <servername> is not compatible with Advanced Threat Protection`, you can either wait for the update to roll out, or open a support ticket to update the server sooner to a supported version.
54
+
31
55
### Update to recommendations to align with Azure AI Services resources
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/upcoming-changes.md
+2-22Lines changed: 2 additions & 22 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -2,7 +2,7 @@
2
2
title: Important upcoming changes
3
3
description: Upcoming changes to Microsoft Defender for Cloud that you might need to be aware of and for which you might need to plan.
4
4
ms.topic: overview
5
-
ms.date: 04/01/2024
5
+
ms.date: 04/03/2024
6
6
---
7
7
8
8
# Important upcoming changes to Microsoft Defender for Cloud
@@ -27,7 +27,6 @@ If you're looking for the latest release notes, you can find them in the [What's
27
27
|--|--|--|
28
28
|[Deprecating of virtual machine recommendation](#deprecating-of-virtual-machine-recommendation)| April 2, 2024 | April 30, 2024 |
29
29
|[General Availability of Unified Disk Encryption recommendations](#general-availability-of-unified-disk-encryption-recommendations)| March 28, 2024 | April 30, 2024 |
30
-
|[Defender for open-source relational databases updates](#defender-for-open-source-relational-databases-updates)| March 6, 2024 | April, 2024 |
31
30
|[Changes in where you access Compliance offerings and Microsoft Actions](#changes-in-where-you-access-compliance-offerings-and-microsoft-actions)| March 3, 2024 | September 30, 2025 |
32
31
|[Microsoft Security Code Analysis (MSCA) is no longer operational](#microsoft-security-code-analysis-msca-is-no-longer-operational)| February 26, 2024 | February 26, 2024 |
33
32
|[Decommissioning of Microsoft.SecurityDevOps resource provider](#decommissioning-of-microsoftsecuritydevops-resource-provider)| February 5, 2024 | March 6, 2024 |
@@ -45,6 +44,7 @@ If you're looking for the latest release notes, you can find them in the [What's
45
44
|[Deprecating two security incidents](#deprecating-two-security-incidents)|| November 2023 |
46
45
|[Defender for Cloud plan and strategy for the Log Analytics agent deprecation](#defender-for-cloud-plan-and-strategy-for-the-log-analytics-agent-deprecation)|| August 2024 |
47
46
47
+
48
48
## Deprecating of virtual machine recommendation
49
49
50
50
**Announcement date: April 2, 2024**
@@ -74,26 +74,6 @@ The recommendations depend on [Guest Configuration](/azure/governance/machine-co
74
74
75
75
These recommendations will replace the recommendation "Virtual machines should encrypt temp disks, caches, and data flows between Compute and Storage resources."
76
76
77
-
## Defender for open-source relational databases updates
78
-
79
-
**Announcement date: March 6, 2024**
80
-
81
-
**Estimated date for change: April, 2024**
82
-
83
-
**Defender for PostgreSQL Flexible Servers post-GA updates** - The update enables customers to enforce protection for existing PostgreSQL flexible servers at the subscription level, allowing complete flexibility to enable protection on a per-resource basis or for automatic protection of all resources at the subscription level.
84
-
85
-
**Defender for MySQL Flexible Servers Availability and GA** - Defender for Cloud is set to expand its support for Azure open-source relational databases by incorporating MySQL Flexible Servers.
86
-
This release will include:
87
-
88
-
- Alert compatibility with existing alerts for Defender for MySQL Single Servers.
89
-
- Enablement of individual resources.
90
-
- Enablement at the subscription level.
91
-
92
-
If you're already protecting your subscription with Defender for open-source relational databases, your flexible server resources are automatically enabled, protected, and billed.
93
-
Specific billing notifications have been sent via email for affected subscriptions.
94
-
95
-
Learn more about [Microsoft Defender for open-source relational databases](defender-for-databases-introduction.md).
96
-
97
77
## Changes in where you access Compliance offerings and Microsoft Actions
0 commit comments