π Azure Subscription Vulnerability Assessment is not auto provisioned π’
- Contextual name: π Vulnerability Assessment is not auto provisioned π’
- ID:
/ce/ca/azure/subscription/vulnerability-assessment-auto-provisioning
- Located in: π Azure Subscription
Flagsβ
- π’ Impossible policy
- π’ Policy with categories
- π’ Policy with type
Our Metadataβ
- Policy Type:
COMPLIANCE_POLICY
- Policy Category:
SECURITY
Similar Policiesβ
Descriptionβ
Descriptionβ
Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.
Rationaleβ
Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.
Impactβ
Additional licensing is required and configuration of Azure Arc introduces complexity beyond this recommendation.
Auditβ
From Azure Portalβ
- From Azure Home select the Portal Menu.
- Select
Microsoft Defender for Cloud
.- Under
Management
, selectEnvironment Settings
.- Select a subscription.
- Click on
Settings & monitoring
.- Ensure that
Vulnerability assessment for machines
is set toOn
.Repeat the above for any additional subscriptions.
Default Valueβ
By default,
Automatic provisioning of monitoring agent
is set toOff
.Referencesβ
... see more
Remediationβ
Remediationβ
From Azure Portalβ
- From Azure Home select the Portal Menu.
- Select
Microsoft Defender for Cloud
.- Under
Management
, selectEnvironment Settings
.- Select a subscription.
- Click on
Settings & Monitoring
.- Set the
Status
ofVulnerability assessment for machines
toOn
.- Click
Continue
.Repeat the above for any additional subscriptions.
policy.yamlβ
Linked Framework Sectionsβ
Section | Sub Sections | Internal Rules | Policies | Flags |
---|---|---|---|---|
πΌ CIS Azure v2.1.0 β πΌ 2.1.15 Ensure that Auto provisioning of 'Vulnerability assessment for machines' is Set to 'On' - Level 2 (Manual) | 1 | |||
πΌ CIS Azure v3.0.0 β πΌ 3.1.3.2 Ensure that 'Vulnerability assessment for machines' component status is set to 'On' (Manual) | 1 | |||
πΌ Cloudaware Framework β πΌ Microsoft Defender Configuration | 26 |