Description
Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.
Rationaleβ
As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.
Impactβ
Agentless discovery for Kubernetes requires licensing and is included in:
- Defender CSPM
- Defender for Containers plans.
Auditβ
From Azure Portalβ
- From the Azure Portal
Home
page, selectMicrosoft Defender for Cloud
. - Under
Management
selectEnvironment Settings
. - Select a subscription.
- Under
Settings
>Defender Plans
, clickSettings & monitoring
. - Locate the row for
Agentless discovery for Kubernetes
. - Ensure that
On
is selected.
Repeat the above for any additional subscriptions.
Default Valueβ
By default, Microsoft Defender for Containers is Off
. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.
Referencesβ
- https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction
- https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-containers
- https://msdn.microsoft.com/en-us/library/mt704062.aspx
- https://msdn.microsoft.com/en-us/library/mt704063.aspx
- https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/list
- https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/create
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-incident-response#ir-2-preparation---setup-incident-notification