2.1.16 Ensure that Auto provisioning of 'Microsoft Defender for Containers components' is Set to 'On'

Information

Enable automatic provisioning of the Microsoft Defender for Containers components.

Rationale:

As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.

Impact:

Microsoft Defender for Containers will require additional licensing.

Solution

From Azure Portal

From the Azure Portal Home page, select Microsoft Defender for Cloud

Under Management, select Environment Settings

Select a subscription

Set Containers to On

Default Value:

By default, Microsoft Defender for Containers is disabled. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.

See Also

https://workbench.cisecurity.org/benchmarks/12346

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|3.1

Plugin: microsoft_azure

Control ID: 698c2e94e4e8d8e58b6c817bc16738205016b0442733852fb9b19461fa9dd501