Sensitive Data by Database

Overview

The Sensitive Data by Database report is the instance view of the database level Sensitive Data page. It answers which databases on this instance hold card numbers or Social Security numbers, and are they classified?

Where to find it

An instance-level report. Right-click an instance, open the instance reports menu and choose Sensitive Data by Database.

Reading the grid

Column What it is
Database One row per user database.
Classified Columns with a sensitivity classification.
Suggested Columns that look sensitive and are not classified (dismissed ones are not counted).
High Unclassified Of those, the ones with High confidence. A database with any is shown in red.
Card Columns, SSN Columns Columns classified or suggested as Credit Card or SSN.
Last Scanned When the counts were taken.
TDE Whether the database is encrypted with Transparent Data Encryption.
Status Not scanned yet, Scanned, Suggestions to review, Partial scan, or Not scanned: database not accessible for a database that is offline, restoring or cannot be opened by this login.

Double-click a database to open its Sensitive Data page.

The toolbar

Button What it does
Scan All Databases Scans every database that can be opened, names always and values when sampling is on in Options, with a progress line and Cancel.
Options ... The same options as the Sensitive Data page.
Refresh Reloads the list.

Where the data comes from

sys.databases for the list and TDE, and the last scan of each database: from dbo.SensitiveColumnScan in the history database when there is one, and from this session otherwise. Only metadata and counts are stored; sampled values never are.