π Microsoft Defender File Integrity Monitoring Component is not enabled π’
- Contextual name: π File Integrity Monitoring Component is not enabled π’
- ID:
/ce/ca/azure/microsoft-defender/file-integrity-monitoring
- Located in: π Microsoft Defender for Cloud
Flagsβ
- π’ Impossible policy
- π’ Policy with categories
- π’ Policy with type
Our Metadataβ
- Policy Type:
COMPLIANCE_POLICY
- Policy Category:
SECURITY
Descriptionβ
Descriptionβ
File Integrity Monitoring (FIM) is a feature that monitors critical system files in Windows or Linux for potential signs of attack or compromise.
Rationaleβ
FIM provides a detection mechanism for compromised files. When FIM is enabled, critical system files are monitored for changes that might indicate a threat actor is attempting to modify system files for lateral compromise within a host operating system.
Impactβ
File Integrity Monitoring requires licensing and is included in these plans:
- Defender for Servers plan 2
Auditβ
From Azure Portalβ
- From the Azure Portal
Home
page, selectMicrosoft Defender for Cloud
.- Under
Management
selectEnvironment Settings
.- Select a subscription.
- Under
Settings
>Defender Plans
, clickSettings & monitoring
.- Under the Component column, locate the row for
File Integrity Monitoring
.- Ensure that
On
is selected.Repeat the above for any additional subscriptions.
Default Valueβ
By default, Agentless scanning for machines is
off
.Referencesβ
... see more
Remediationβ
Remediationβ
From Azure Portalβ
- From the Azure Portal
Home
page, selectMicrosoft Defender for Cloud
.- Under
Management
selectEnvironment Settings
.- Select a subscription.
- Under
Settings
>Defender Plans
, clickSettings & monitoring
.- Under the Component column, locate the row for
File Integrity Monitoring
.- Select
On
.- Click
Continue
in the top left.Repeat the above for any additional subscriptions.
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v3.0.0 β πΌ 3.1.3.4 Ensure that 'Agentless scanning for machines' component status is set to 'On' (Manual) | 1 | |||
πΌ Cloudaware Framework β πΌ Microsoft Defender Configuration | 26 |