Skip to main content

πŸ“ Azure Subscription Vulnerability Assessment is not auto provisioned 🟒

  • Contextual name: πŸ“ Vulnerability Assessment is not auto provisioned 🟒
  • ID: /ce/ca/azure/subscription/vulnerability-assessment-auto-provisioning
  • Located in: πŸ“ Azure Subscription

Flags​

Our Metadata​

  • Policy Type: COMPLIANCE_POLICY
  • Policy Category:
    • SECURITY

Similar Policies​

Description​

Open File

Description​

Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.

Rationale​

Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.

Impact​

Additional licensing is required and configuration of Azure Arc introduces complexity beyond this recommendation.

Audit​

From Azure Portal​
  1. From Azure Home select the Portal Menu.
  2. Select Microsoft Defender for Cloud.
  3. Under Management, select Environment Settings.
  4. Select a subscription.
  5. Click on Settings & monitoring.
  6. Ensure that Vulnerability assessment for machines is set to On.

Repeat the above for any additional subscriptions.

Default Value​

By default, Automatic provisioning of monitoring agent is set to Off.

References​

  1. https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-va

... see more

Remediation​

Open File

Remediation​

From Azure Portal​

  1. From Azure Home select the Portal Menu.
  2. Select Microsoft Defender for Cloud.
  3. Under Management, select Environment Settings.
  4. Select a subscription.
  5. Click on Settings & Monitoring.
  6. Set the Status of Vulnerability assessment for machines to On.
  7. Click Continue.

Repeat the above for any additional subscriptions.

policy.yaml​

Open File

Linked Framework Sections​

SectionSub SectionsInternal RulesPoliciesFlags
πŸ’Ό CIS Azure v2.1.0 β†’ πŸ’Ό 2.1.15 Ensure that Auto provisioning of 'Vulnerability assessment for machines' is Set to 'On' - Level 2 (Manual)1
πŸ’Ό CIS Azure v3.0.0 β†’ πŸ’Ό 3.1.3.2 Ensure that 'Vulnerability assessment for machines' component status is set to 'On' (Manual)1
πŸ’Ό Cloudaware Framework β†’ πŸ’Ό Microsoft Defender Configuration26