π‘οΈ Microsoft Defender Agentless Scanning for Machines Component is not enabledπ’βͺ
- Contextual name: π‘οΈ Agentless Scanning for Machines Component is not enabledπ’βͺ
- ID:
/ce/ca/azure/microsoft-defender/agentless-scanning-for-machines - Tags:
- βͺ Impossible policy
- π’ Policy with categories
- π’ Policy with type
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Descriptionβ
Descriptionβ
Using disk snapshots, the agentless scanner scans for installed software, vulnerabilities, and plain text secrets.
Rationaleβ
The Microsoft Defender for Cloud agentless machine scanner provides threat detection, vulnerability detection, and discovery of sensitive information.
Impactβ
Agentless scanning for machines requires licensing and is included in these plans:
- Defender CSPM
- Defender for Servers plan 2
Auditβ
From Azure Portalβ
- From the Azure Portal
Homepage, selectMicrosoft Defender for Cloud.- Under
ManagementselectEnvironment Settings.- Select a subscription.
- Under
Settings>Defender Plans, clickSettings & monitoring.- Under the Component column, locate the row for
Agentless scanning for machines.- Ensure that
Onis selected.Repeat the above for any additional subscriptions.
Default Valueβ
By default, Agentless scanning for machines is
off.Referencesβ
- https://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-agentless-data-collection
- https://learn.microsoft.com/en-us/security/benchmark/azure/mcsb-incident-response#ir-2-preparation---setup-incident-notification
... see more
Remediationβ
Remediationβ
From Azure Portalβ
- From the Azure Portal
Homepage, selectMicrosoft Defender for Cloud.- Under
ManagementselectEnvironment Settings.- Select a subscription.
- Under
Settings>Defender Plans, clickSettings & monitoring.- Under the Component column, locate the row for
Agentless scanning for machines.- Select
On.- Click
Continuein the top left.Repeat the above for any additional subscriptions.
policy.yamlβ
Linked Framework Sectionsβ
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| πΌ CIS Azure v3.0.0 β πΌ 3.1.3.5 Ensure that 'File Integrity Monitoring' component status is set to 'On' (Manual) | 1 | no data | |||
| πΌ CIS Azure v4.0.0 β πΌ 9.1.3.4 Ensure that 'Agentless scanning for machines' component status is set to 'On' (Manual) | 1 | no data | |||
| πΌ Cloudaware Framework β πΌ Microsoft Defender Configuration | 26 | no data |