Ensure that Microsoft Defender for Cloud is enabled for the virtual machine (VM) servers provisioned in your Azure cloud account. The threat detection and protection capabilities provided by Microsoft Defender for Cloud for VM servers include vulnerability assessment scanning, file integrity monitoring (also known as change monitoring), Just-in-time (JIT) virtual machine access monitoring, adaptive network hardening (ANH), fileless attack detection, and Docker host hardening.
This rule resolution is part of the Conformity Security & Compliance tool for Azure.
By default, Microsoft Defender for Cloud is not enabled for your virtual machine (VM) servers. Enabling the Defender security service for Azure virtual machines allows for better defense-in-depth with threat detection capabilities provided by the Microsoft Security Response Center (MSRC).
Audit
To determine if the Microsoft Defender for Cloud security service is enabled for your Azure virtual machines (VMs), perform the following actions:
Remediation / Resolution
To enable Microsoft Defender for Cloud for your Azure virtual machines (VMs), perform the following actions:
Note: Turning on Defender for Cloud for the specified resource type (i.e. VM servers) incurs an additional cost per resource.References
- Azure Official Documentation
- Microsoft Defender for Cloud documentation
- What is Microsoft Defender for Cloud?
- Microsoft Defender for Cloud pricing
- Microsoft Defender for Cloud's enhanced security features
- Introduction to Microsoft Defender for servers
- CIS Microsoft Azure Foundations
- Azure Command Line Interface (CLI) Documentation
- az
- az account get-access-token