Configure Advanced Threat Protection in Azure SQL Database managed instance

Advanced Threat Protection for a managed instance detects anomalous activities indicating unusual and potentially harmful attempts to access or exploit databases. Advanced Threat Protection can identify Potential SQL injection, Access from unusual location or data center, Access from unfamiliar principal or potentially harmful application, and Brute force SQL credentials - see more details in Advanced Threat Protection alerts.

You can receive notifications about the detected threats via email notifications or Azure portal

Advanced Threat Protection is part of the advanced data security (ADS) offering, which is a unified package for advanced SQL security capabilities. Advanced Threat Protection can be accessed and managed via the central SQL ADS portal.

Set up Advanced Threat Protection in the Azure portal

  1. Launch the Azure portal at https://portal.azure.com.

  2. Navigate to the configuration page of the managed instance you want to protect. In the Settings page, select Advanced Data Security.

  3. In the Advanced Data Security configuration page

    • Turn ON Advanced Data Security.
    • Configure the list of emails to receive security alerts upon detection of anomalous database activities.
    • Select the Azure storage account where anomalous threat audit records are saved.
    • Select the Advanced Threat Protection types that you would like configured. Learn more about Advanced Threat Protection alerts.
  4. Click Save to save the new or updated Advanced Data Security policy.

    Advanced Threat Protection

    Note

    Prices in screenshots does not always reflect the current price, and are an example.

Next steps