π‘οΈ Microsoft Defender Agentless Discovery for Kubernetes Component is not enabledπ’βͺ
- Contextual name: π‘οΈ Agentless Discovery for Kubernetes Component is not enabledπ’βͺ
- ID:
/ce/ca/azure/microsoft-defender/agentless-discovery-for-kubernetes
- Tags:
- βͺ Impossible policy
- π’ Policy with categories
- π’ Policy with type
- Policy Type:
COMPLIANCE_POLICY
- Policy Categories:
SECURITY
Descriptionβ
Descriptionβ
Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.
Rationaleβ
As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.
Impactβ
Agentless discovery for Kubernetes requires licensing and is included in:
- Defender CSPM
- Defender for Containers plans.
Auditβ
From Azure Portalβ
- From the Azure Portal
Home
page, selectMicrosoft Defender for Cloud
.- Under
Management
selectEnvironment Settings
.- Select a subscription.
- Under
Settings
>Defender Plans
, clickSettings & monitoring
.- Locate the row for
Agentless discovery for Kubernetes
.- Ensure that
On
is selected.Repeat the above for any additional subscriptions.
Default Valueβ
By default, Microsoft Defender for Containers is
Off
. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.Referencesβ
... see more
Remediationβ
Remediationβ
From Azure Portalβ
- From the Azure Portal
Home
page, selectMicrosoft Defender for Cloud
.- Under
Management
selectEnvironment Settings
.- Select a subscription.
- Under
Settings
>Defender Plans
, clickSettings & monitoring
.- Locate the row for
Agentless discovery for Kubernetes
.- Select
On
.- Click
Continue
in the top left.Repeat the above for any additional subscriptions.
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
---|---|---|---|---|---|
πΌ CIS Azure v3.0.0 β πΌ 3.1.4.2 Ensure that 'Agentless discovery for Kubernetes' component status 'On' (Automated) | 1 | no data | |||
πΌ Cloudaware Framework β πΌ Microsoft Defender Configuration | 26 | no data |