How do I eliminate the High Severity alert regarding high volume data extraction for my SQL Server instance?

Gerald Perkins 1 Reputation point
2021-07-12T18:16:09.87+00:00

I receive a High Severity alert which reads "Someone has extracted an unusual amount of potentially sensitive data from your SQL server xxxx".
Normally, the application executing the query returns a few rows but it is acceptable that the client requests a significant number of rows, which triggers this alert.
I cannot find this alert in https://github.com/MicrosoftDocs/azure-docs/blob/master/articles/security-center/alerts-reference.md
I wouldn't mind if this was a "low" or "moderate" alert which didn't frighten those who view it.
Is it possible to tweak something in the Advanced Threat Protection for SQL Server? Can this alert be removed?
THANKS!

Azure SQL Database
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,201 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Tom Phillips 17,716 Reputation points
    2021-07-12T19:05:30.953+00:00

    This is an Azure message, not a SQL Server message. Your question would be better answered on the Azure forum.

    See "PREVIEW - Unusual amount of data extracted from a Cosmos DB account" :

    https://learn.microsoft.com/en-us/azure/security-center/alerts-reference