> ## Documentation Index
> Fetch the complete documentation index at: https://www.docusnap.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# Scanning Microsoft SQL Server

> Capturing SQL Server instances and their databases—with credentials of their own or under the gateway's service account.

The *Microsoft SQL Server* scan module captures SQL Server instances and their
databases. It requires a connected [gateway](/docs/en/scan/gateway-install).

## Captured data

The scan creates assets of these two types:

| Type | Groups |
| - | - |
| *SQL Server Instance* | Security (Logins, Authentication, Server Roles), Management (Maintenance Plans, Jobs) |
| *SQL Server Database* | Database Details (Files, Tables, Views), Programmability (Stored Procedures, Functions), Security (Schemas, Roles, Users) |

How the detail pages of the types are structured is described in
[Databases](/docs/en/assets/databases).

## Setting up the job

The wizard follows the standard path *Basics* › *Targets* › *Schedule* ›
*Summary*—see [Creating a Scan Job](/docs/en/scan/create-inventory). The
*Targets* step is what sets this module apart.

Each row carries four columns:

| Column | Content |
| - | - |
| *IP/Hostname* | the name of the server or of the instance |
| *Credentials* | an entry of the type *User Account*—a SQL Server account or a domain user |
| *Authentication* | the kind of sign-in for this target |
| *Also Capture Object Details* | per target, off by default |

The *Credentials* column may stay empty. The scan then runs under the gateway's
service account, and that account needs the rights under
[Permissions](#permissions). An entry in *Credentials for all targets* applies
to every row without an assignment of its own.

The scan captures system databases only when the module setting
*Collect System Databases* is on; it is off by default. Where the module
settings are is described in
[Creating a Scan Job](/docs/en/scan/create-inventory#module-settings).

## Prerequisites

### Ports and protocols

| Protocol | Port | Transport |
| - | - | - |
| SQL Server | 1433 | TCP |
| SQL Server Browser (monitor) | 1434 | TCP/UDP |
| dynamic ports (named instances) | 1024–65535 | TCP/UDP |

### Permissions

* For a complete scan, the account has the sysadmin server role.
* Without sysadmin, the scan captures only parts of the server or the instance.

### Network requirements

* The firewall allows the ports above.
* Database and server allow remote connections.
* The TCP/IP protocol is enabled for the SQL Server or the instance.

## Related

After it is created, the job appears among the jobs; how you watch and adjust
it is in [Managing Jobs](/docs/en/scan/manage-jobs). The ports of all scan modules
are in the [Scan Reference](/docs/en/scan/reference#ports-and-protocols).


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.