🛡️ Azure Subscription Vulnerability Assessment is not auto provisioned🟢⚪
- Contextual name: 🛡️ Vulnerability Assessment is not auto provisioned🟢⚪
- ID:
/ce/ca/azure/subscription/vulnerability-assessment-auto-provisioning - Tags:
- Policy Type:
COMPLIANCE_POLICY - Policy Categories:
SECURITY
Similar Policies
Description
Description
Enable vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.
Rationale
Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.
Impact
Microsoft Defender for Servers plan 2 licensing is required, and configuration of Azure Arc introduces complexity beyond this recommendation.
Audit
From Azure Portal
- From Azure Home select the Portal Menu.
- Select
Microsoft Defender for Cloud.- Under
Management, selectEnvironment Settings.- Select a subscription.
- Click on
Settings & monitoring.- Ensure that
Vulnerability assessment for machinesis set toOn.Repeat the above for any additional subscriptions.
From Azure Policy
If referencing a digital copy of this Benchmark, clicking a Policy ID will open a link to the associated Policy definition in Azure.
- Policy ID: 501541f7-f7e7-4cd6-868c-4190fdad3ac9 - Name:
A vulnerability assessment solution should be enabled on your virtual machines... see more
Remediation
Remediation
From Azure Portal
- From Azure Home select the Portal Menu.
- Select
Microsoft Defender for Cloud.- Under
Management, selectEnvironment Settings.- Select a subscription.
- Click on
Settings & Monitoring.- Set the
StatusofVulnerability assessment for machinestoOn.- Click
Continue.Repeat the above for any additional subscriptions.
policy.yaml
Linked Framework Sections
| Section | Sub Sections | Internal Rules | Policies | Flags | Compliance |
|---|---|---|---|---|---|
| 💼 CIS Azure v5.0.0 → 💼 8.1.3.2 Ensure that 'Vulnerability assessment for machines' component status is set to 'On' (Manual) | 1 | no data | |||
| 💼 Cloudaware Framework → 💼 Microsoft Defender Configuration | 29 | no data |