Defender for Cloud の「Azure Monitoring Agent for SQL Servers on Machines」がグレーアウトして有効化できない

碧海 山口 20 評価のポイント
2026-09-29T05:28:40.23+00:00

お世話になっております。

Microsoft Defender for Cloud で、「設定と監視」画面の「Azure Monitoring Agent for SQL Servers on Machines」がグレーアウトしていて、オン/オフを切り替えられません。これが想定どおりの動作かどうか教えていただけますでしょうか。

■ 環境

  • クラウド:Azure 商用クラウド(政府機関向けクラウドではありません)
  • 対象:1 つのサブスクリプション
  • SQL 仮想マシンと Azure Arc SQL Server インスタンスは、現在どちらもありません
  • 操作したアカウントの権限:サブスクリプションの所有者

■ 現在の設定([環境設定] > 対象サブスクリプション > [Defender プラン])

  • データベースプラン:オン
  • リソースの種類:「選択済み:4 個中 4 個」(マシン上の SQL Server を含む)
  • 監視対象:「完全」

■ 事象

  • [Defender プラン] 画面の上部にある [設定と監視] を開きます
  • 「Azure Monitoring Agent for SQL Servers on Machines」のトグルだけがグレーアウトしていて、操作できません
  • 同じ画面にある「Kubernetes API アクセス」「レジストリ アクセス」「機密データ検出」などは、問題なく切り替えられます

■ 確認したドキュメント

■ 質問

  1. 商用クラウドでは、新しいエージェント アーキテクチャへの移行によって、このトグルは使われなくなり、グレーアウト表示になるという理解で合っていますか。
  2. 対象の SQL Server(SQL VM や Arc SQL Server)がサブスクリプションにないことが、グレーアウトの原因になることはありますか。

以上、よろしくお願いいたします。

Azure SQL Database
Azure SQL Database

Azure リレーショナル データベース サービス。

0 件のコメント コメントはありません

1 件の回答

並べ替え方法: 最も役に立つ
  1. Smaran Thoomu 35,875 評価のポイント Microsoft 外部スタッフ モデレーター
    2026-10-04T18:44:08.6533333+00:00

    Hello Bikai Yamaguchi

    Thank you for providing the detailed environment and configuration information.

    Based on the current Microsoft documentation, the behavior you are seeing is expected for Azure commercial cloud.

    Defender for SQL Servers on Machines is transitioning to an enhanced agent architecture. For supported resources in commercial cloud, the solution uses the existing SQL infrastructure and does not require customers to configure or deploy the SQL-targeted Azure Monitor Agent through the previous AMA toggle. As a result, the“Azure Monitoring Agent for SQL Servers on Machines” option may appear grayed out and cannot be changed manually.

    Regarding your questions:

    1. Is the toggle obsolete in commercial cloud? Yes. The AMA migration procedure referenced in the first article applies only to government clouds. It should not be used for an Azure commercial-cloud subscription. In commercial cloud, enablement is managed through the Defender for Databases plan and the SQL Servers on Machines resource type rather than through the AMA toggle.
    2. Does the absence of SQL VM or Azure Arc SQL Server resources cause the toggle to be grayed out? The supported targets for this plan are SQL virtual machines and Azure Arc-enabled SQL Server instances. Since the subscription currently contains neither resource type, there are no eligible SQL Server machines to onboard or protect. However, the current documentation does not identify the absence of these resources as the direct reason for the AMA toggle being disabled. The disabled toggle is primarily consistent with the commercial-cloud architecture transition.

    Your current configuration, with Defender for Databases enabled and SQL Servers on Machines selected, is the relevant subscription-level configuration. No action is required on the grayed-out AMA toggle at this time.

    After an eligible SQL VM or Azure Arc-enabled SQL Server instance is added, Defender for SQL Servers on Machines should detect and onboard the supported resource automatically. Resource discovery and protection status might require some time to appear in the portal.

    For reference:

    Please let us know if the option remains unavailable after an eligible SQL VM or Azure Arc-enabled SQL Server instance is added, or if the new resource does not reach a protected status. In that case, please share a screenshot of the plan configuration and the affected SQL resource so that we can investigate further.

    Best regards, Microsoft Support


    Japanese

    山口様

    詳細な環境情報および設定内容をご共有いただき、ありがとうございます。

    現在の Microsoft の公開ドキュメントに基づくと、Azure 商用クラウドにおいて今回確認されている動作は想定されたものと考えられます。

    Defender for SQL Servers on Machines は、新しいエージェント アーキテクチャへ移行しています。商用クラウドのサポート対象リソースでは、既存の SQL インフラストラクチャを使用するため、従来の AMA トグルから SQL Server 向け Azure Monitor Agent を構成または展開する必要はありません。そのため、「Azure Monitoring Agent for SQL Servers on Machines」 がグレーアウトされ、手動で変更できない場合があります。

    ご質問について、以下のとおり回答いたします。

    1. 商用クラウドでは、このトグルは使用されなくなったという理解でよいでしょうか。 はい。ご確認いただいた AMA 移行手順のドキュメントは、政府機関向けクラウドにのみ適用されます。そのため、Azure 商用クラウドのサブスクリプションでは、この移行手順を実施する必要はありません。商用クラウドでは、AMA トグルではなく、Defender for Databases プランおよびマシン上の SQL Serverリソースの種類を通じて有効化されます。
    2. サブスクリプション内に SQL VM または Azure Arc SQL Server が存在しないことが、グレーアウトの原因でしょうか。 このプランのサポート対象は、SQL 仮想マシンおよび Azure Arc 対応 SQL Server インスタンスです。現在のサブスクリプションには、いずれのリソースも存在しないため、現時点では保護対象として検出またはオンボードされる SQL Server リソースはありません。ただし、現在のドキュメントでは、対象リソースが存在しないこと自体が AMA トグルのグレーアウトの直接的な原因であるとは明記されていません。今回のグレーアウトは、主に商用クラウドにおける新しいアーキテクチャへの移行と整合する動作です。

    現在設定されている、Defender for Databases がオンで、リソースの種類としてマシン上の SQL Server が選択されている状態が、サブスクリプション レベルで必要となる設定です。現時点では、グレーアウトしている AMA トグルに対して追加の操作は必要ありません。

    今後、対象となる SQL VM または Azure Arc 対応 SQL Server インスタンスを追加すると、Defender for SQL Servers on Machines によって、対応リソースが自動的に検出およびオンボードされます。リソースの検出および保護状態がポータルに反映されるまで、時間がかかる場合があります。

    参考資料:

    対象となる SQL VM または Azure Arc 対応 SQL Server インスタンスを追加した後も保護が有効にならない場合は、Defender プランの設定画面および対象 SQL リソースの画面のスクリーンショットをご共有ください。引き続き確認いたします。

    この回答は役に立ちましたか?

    0 件のコメント コメントはありません

お客様の回答

質問作成者は回答に "承認済み"、モデレーターは "推奨" とマークできます。これにより、ユーザーは作成者の問題が回答によって解決したことを把握できます。