Description
Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.
Rationaleβ
As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.
Impactβ
Agentless discovery for Kubernetes requires licensing and is included in:
- Defender CSPM
- Defender for Containers plans.
Auditβ
From Azure Portalβ
- From the Azure Portal Homepage, selectMicrosoft Defender for Cloud.
- Under ManagementselectEnvironment Settings.
- Select a subscription.
- Under Settings>Defender Plans, clickSettings & monitoring.
- Locate the row for Agentless discovery for Kubernetes.
- Ensure that Onis selected.
Repeat the above for any additional subscriptions.
Default Valueβ
By default, Microsoft Defender for Containers is Off. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.
Referencesβ
- https://docs.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction
- https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-containers
- https://msdn.microsoft.com/en-us/library/mt704062.aspx
- https://msdn.microsoft.com/en-us/library/mt704063.aspx
- https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/list
- https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/create
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-incident-response#ir-2-preparation---setup-incident-notification