Help Center

Third-party software Contact us

Microsoft SQL server configuration

Configuring Microsoft SQL servers

For seamless synchronization of the Risk analysis module and MSSQL server, administrators must implement the prerequisites stated in the SQL server configuration prerequisites page.

To configure Microsoft SQL server for data discovery scans, follow these steps:

  • Select Risk Analysis from the application drop-down.
  • Go to Configuration > Data Sources > SQL Server.
  • Click +Add SQL Server.
  • Enter Server Name.
  • Enter Instance Name and Port Number.
  • Choose whether you want to encrypt the connection between DataSecurity Plus and the SQL Server.

    Considerations to choose a connection type

    The connection between DataSecurity Plus and SQL Server can be established with or without encryption. The section below outlines the differences between these connection types and provides detailed steps for configuring each one:

    Configuring with an encrypted connection

    An encrypted connection protects data exchanged between DataSecurity Plus and the SQL Server from interception. This is strongly recommended for production environments where the server is accessed over an exposed network. Specify whether the connection should be validated against a server certificate:

    • Validate Server Certificate: Enable this option to verify the identity of the SQL Server before establishing the encrypted connection. While encryption can function without certificate validation, disabling this option makes the connection vulnerable to man-in-the-middle attacks. It is advisable to keep this option enabled in production environments.

      After enabling Validate Server Certificate, click Browse. Select the certificate configured for the SQL Server (either a trusted CA-signed or a self-signed certificate in PEM, CRT, or CER format), then click Install to add it to the DataSecurity Plus trust store. The installed certificate is used to validate the SQL Server's identity during the TLS connection.

    Configuring without an encrypted connection

    An unencrypted connection transmits data in plain text and should only be used in isolated environments, such as local testing setups, and is not recommended for environments handling sensitive data.

  • Choose the Authentication Type.
  • Enter the Username and Password based on the selected authentication type.

    Access requirements for authentication

    The credentials required differ depending on the authentication type selected. The following outlines the requirements for each:

    • Windows authentication: When Encrypt Connection is enabled, DataSecurity Plus automatically uses the credentials of the Windows account under which the product service is running. When encryption is disabled, provide a user account with the Domain Admin credentials required for database access. To avoid using administrative access, refer to the permissions and privileges guide to configure a service account with minimum privileges.
    • SQL Server Authentication: Enter a user account within the target SQL server instance that has at least Read permission on the database being scanned. For more details on configuring a minimum privileged SQL server, refer to the permissions and privileges guide.
  • Under Select Database for Scanning, choose one of the following options:
    • All Databases: Scans and monitors every database available on the SQL Server.
    • Specific Databases: Allows you to select and monitor specific databases.
  • Click Save.

Viewing and editing configured servers

To manage existing data source configurations, follow these steps:

  • Select Risk Analysis from the modules drop-down.
  • Go to Configuration > Data Sources > SQL Server. On the Configured SQL Servers page, you will see a table listing the configured SQL Servers along with details regarding the status of the last data discovery scan and its scan history.
  • Click the Edit Configuration icon in the Actions column next to the SQL Server instance.
  • Review or modify the Encrypt Connection settings as needed. For details on how to enable encryption and validate server certificate, refer to the configuration steps above.
  • Click Fetch Databases to view and add databases within this SQL Server instance. To remove a database, select one from the table below and click the delete icon.
  • Click Update once you have made the required changes.

Running data discovery scans

Once the SQL Server is configured successfully, data discovery scans will be scheduled automatically by DataSecurity Plus.

Note:

Customers who installed DataSecurity Plus prior to build 6050 can only manually schedule data discovery scans. Find the steps to schedule a data discovery scan, from here.

All DataSecurity Plus builds from 6050 will automatically schedule scans and the users can track it's progress regularly.

The time taken to complete a scan depends on the resources allocated for the data discovery scan and the volume of data to be scanned.

Check the status of the data discovery scan for any configured MSSQL server by following these steps:

  • Select Risk Analysis from the application drop-down.
  • Go to Configuration > Data Sources > SQL Server.
  • Click View History under the Execution History column of the server whose scan history you want to analyze.
  • The complete scan history for that server, including scan start time, end time, and current status, will be displayed.

You can manually initiate a scan for any SQL Server instance by clicking the rescan icon on the MSSQL Server Configuration page.

Don't see what you're looking for?

  • Visit our community

    Post your questions in the forum.

     
  • Request additional resources

    Send us your requirements.