通过PowerShell Az模块配置Azure SQL服务器与数据库级别的定期Vulnerability Assessment Scan
Great question! Since you're already leveraging Az PowerShell modules in your projects, you'll only need the Az.Sql module to configure scheduled vulnerability assessment scans at both the SQL Server and database levels. This module is purpose-built for managing all Azure SQL-related operations, including vulnerability assessment policies and recurring scans.
Prerequisite: Ensure Az.Sql is Installed
First, make sure you have the latest version of the module installed (if you don't already):
Install-Module -Name Az.Sql -Force -AllowClobber
Don't forget to connect to your Azure account first with Connect-AzAccount.
1. Configure Server-Level Scheduled Vulnerability Assessment
At the server level, you'll first set up the storage account where scan results will be stored, then enable recurring scans. This configuration can be inherited by databases under the server (if you don't override it at the database level).
Example Script:
# Define your resources $resourceGroupName = "your-resource-group-name" $serverName = "your-sql-server-name" $storageAccountName = "your-storage-account-name" $storageResourceGroup = "your-storage-resource-group" # Can match the server's RG # Get the storage account object $storageAccount = Get-AzStorageAccount -ResourceGroupName $storageResourceGroup -Name $storageAccountName # Set server-level VA settings with recurring scans Set-AzSqlServerVulnerabilityAssessmentSetting ` -ResourceGroupName $resourceGroupName ` -ServerName $serverName ` -StorageAccountName $storageAccount.StorageAccountName ` -ScanResultsContainerName "va-scan-results" ` # Container to store scan reports -RecurringScansInterval Weekly ` # Can be "Weekly" or "Monthly" -EmailSubscriptionAdmins $true ` # Send alerts to subscription admins -NotificationEmail @("team-admin@example.com", "security@example.com") # Additional recipients
To manually trigger a server-level scan (optional):
Start-AzSqlServerVulnerabilityAssessmentScan -ResourceGroupName $resourceGroupName -ServerName $serverName
2. Configure Database-Level Scheduled Vulnerability Assessment
If you need granular control for specific databases (e.g., different scan intervals or notification recipients), use the database-specific commands. You can either inherit the server's storage settings or define a separate storage account.
Example Script (Inherit Server Storage, Customize Scans):
$databaseName = "your-target-database" Set-AzSqlDatabaseVulnerabilityAssessmentSetting ` -ResourceGroupName $resourceGroupName ` -ServerName $serverName ` -DatabaseName $databaseName ` -RecurringScansInterval Monthly ` # Override server's weekly interval -EmailSubscriptionAdmins $false ` -NotificationEmail @("db-owner@example.com")
To manually trigger a database-level scan (optional):
Start-AzSqlDatabaseVulnerabilityAssessmentScan -ResourceGroupName $resourceGroupName -ServerName $serverName -DatabaseName $databaseName
Key Commands Recap
All operations rely on these core Az.Sql cmdlets:
Set-AzSqlServerVulnerabilityAssessmentSetting: Configures server-level VA and recurring scansSet-AzSqlDatabaseVulnerabilityAssessmentSetting: Configures database-level VA and recurring scansStart-AzSqlServerVulnerabilityAssessmentScan/Start-AzSqlDatabaseVulnerabilityAssessmentScan: Manually triggers on-demand scans
Quick Notes
- The storage account must be in the same Azure region as your SQL Server, or you'll need to configure appropriate cross-region access permissions.
- Recurring scans run automatically on the schedule you set—no need to set up separate Azure Automation jobs for this (the feature handles scheduling internally).
内容的提问来源于stack exchange,提问作者Ian Carrick

