Regarding Microsoft Defender Recommendation query

Suresh Babu SA 0 Reputation points
2026-08-21T10:09:11.5066667+00:00

In June 2026 Microsoft Defender report we noticed the following, however we generate the new report the following deviation not listed and we have not perform any remediation activity.

SQL servers on machines should have vulnerability findings resolved

SQL databases should have vulnerability findings resolved

 =========

I would like to know why its not listed now, is there any filtering need to do to get the appropriate report?

Can you advice to proceed further.

If you are Ok. you can ping me MS Teams with the below ID.

******@kyndryl.com

Appreciate your prompt response.

Regards,

B.Suresh

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-21T10:09:33.4233333+00:00

    Those two recommendations are being phased out and replaced, which is why they might no longer appear in a newly generated report even though no remediation was performed.

    As of July 31, 2026, Defender for Cloud is deprecating these grouped recommendations:

    • SQL databases should have vulnerability findings resolved
    • SQL servers on machines should have vulnerability findings resolved

    They are being replaced by individual recommendations for SQL vulnerability assessment findings.

    To check the current findings in the portal:

    1. Sign in to the Azure portal.
    2. Open the relevant SQL server or SQL database resource.
    3. Under Security, select Microsoft Defender for Cloud.
    4. Review:
      • Vulnerabilities on related databases
      • View server vulnerability summary
      • View in recommendations page

    Important behavior to expect:

    • On a SQL server resource, database-level SQL Vulnerability Assessment recommendations are not listed under Security findings on this SQL server because they are reported on the individual databases.
    • The deprecated aggregated recommendations might still appear in the Recommendations tab until they are fully retired.
    • If using Express Configuration, scan history is available from the database resource under Security > Defender for Cloud > Scan History.

    How to proceed:

    1. Stop relying only on the old grouped recommendation names in reports.
    2. Review findings from the SQL resource’s Microsoft Defender for Cloud page and from the Recommendations page filtered for SQL Vulnerability Assessment.
    3. For each finding, decide whether to:
      • Fix the misconfiguration
      • Approve it as a baseline if the state is expected by design
      • Create an exemption if the recommendation is not relevant for the organization
    4. If a finding is intentionally to be ignored rather than remediated, and the environment uses supported SQL VA scenarios, specific findings can also be disabled through Defender for Cloud policy-based disable rules where applicable.

    There is no context indicating that an extra report filter is required to make those exact deprecated recommendation names reappear. The supported explanation is the transition from grouped recommendations to individual recommendations and the fact that findings can now surface at the database level or through the SQL Vulnerability Assessment views instead of the old aggregated entries.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.