Skip to main content

πŸ›‘οΈ Microsoft Defender Recommendations for Apply System Updates are not completed🟒βšͺ

  • Contextual name: πŸ›‘οΈ Recommendations for Apply System Updates are not completed🟒βšͺ
  • ID: /ce/ca/azure/microsoft-defender/recommendations-for-apply-system-updates
  • Tags:
  • Policy Type: COMPLIANCE_POLICY
  • Policy Categories: SECURITY

Description​

Open File

Description​

Ensure that the latest OS patches for all virtual machines are applied.

Rationale​

Windows and Linux virtual machines should be kept updated to:

  • Address a specific bug or flaw.
  • Improve an OS or application's general stability.
  • Fix a security vulnerability.

Microsoft Defender for Cloud retrieves a list of available security and critical updates from Windows Update or Windows Server Update Services (WSUS), depending on which service is configured on a Windows VM. The security center also checks for the latest updates in Linux systems. If a VM is missing a system update, the security center will recommend system updates be applied.

Impact​

Running Microsoft Defender for Cloud incurs additional charges for each resource monitored. Please see attached reference for exact charges per hour.

Audit​

From Azure Portal​
  1. In the Azure portal, open the portal menu.
  2. Select Microsoft Defender for Cloud.
  3. Then the Recommendations blade.
  4. Ensure that there are no recommendations for Apply system updates.

... see more

Remediation​

Open File

Remediation​

Follow Microsoft documentation to apply security patches from Defender for Cloud. Alternatively, you can employ your own patch assessment and management tool to periodically assess, report, and install the required security patches for your OS.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlagsCompliance
πŸ’Ό CIS Azure v5.0.0 β†’ πŸ’Ό 8.1.10 Ensure that Microsoft Defender for Cloud is configured to check VM operating systems for updates (Automated)1no data
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Microsoft Defender Configuration29no data