False positives for SQL Server Auditing in Azure Defender

Alexandre Ratte 0 Reputation points
2025-07-23T20:02:30.1166667+00:00

Azure Defender shows an Azure SQL Server vulnerability where Auditing should be enabled at the server level. However, when looking at the Auditing section for the affecrted SQL Server resource, it is in fact enabled and correctly configured.

Furthermore, looking at the targeted Storage Account, I see audit logs being written to the sqldbauditlogs container up to today's date for the master database. Only two SQL Servers are affected by this finding out of ~60.

Any clue what could be causing this?

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.