Requirements
Supported Target Systems
The SQL instance scan tasks are supported on the following target systems:
- Microsoft Azure SQL Database
- Microsoft Azure SQL Managed Instances
- SQL Server 2025
- SQL Server 2022
- SQL Server 2019
- SQL Server 2017
- SQL Server 2016
- SQL Server 2014
- SQL Server 2012
- SQL Server 2008 R2
- SQL Server 2008
Microsoft Azure SQL Database Access Settings
SQL server management objects are used to obtain information remotely from Microsoft Azure SQL database logical servers.
- Firewall access must allow access to the SQL port on the Microsoft Azure SQL database logical server.
- The credentials configured in the agent settings must have permissions to read the instance configuration and databases.
Microsoft Azure SQL Managed Instance Access Settings
SQL server management objects are used to obtain information remotely from Microsoft Azure SQL managed instances.
- Firewall access must allow access to the SQL port on the Microsoft Azure SQL managed instance.
- The service account, custom credentials, or credentials configured in the agent settings must have sysadmin access rights on the remote SQL Instance. This requirement can be overridden using the tolerance settings.
On-Premises Access Settings
SQL server management objects are used to obtain information remotely from SQL instances, and either WMI or PowerShell remoting is used to obtain host information.
- Firewall access must allow access to the SQL port on the remote SQL instance - by default TCP/1433.
- To obtain host information such as manufacturer and serial number, firewall access must be permitted to the either PowerShell remoting or WMI ports on the remote machine.
- The service account, custom credentials, or credentials configured in the agent settings may require access to Active Directory to resolve an account and its properties when a SQL Server service is configured to use a Managed Service Account (MSA) or Group Managed Service Account (gMSA).
- The service account or custom credentials must have administrator rights on the remote machine to obtain host information using PowerShell remoting or WMI.
- The remote SQL instance must allow remote connections.
- The service account, custom credentials, or credentials configured in the agent settings must have sysadmin access rights on the remote SQL Instance. This requirement can be overridden using the tolerance settings.
Local Service
The SQL instance scan tasks support the local service.
Automatic Detection
SQL instances can be automatically detected and scanned by Windows machine scan tasks.
Clustered SQL instances can be automatically detected and scanned by Microsoft failover cluster scan tasks.