Information
Enable vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.
Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Remediate from Azure Portal
- From Azure Home select the Portal Menu
- Select Microsoft Defender for Cloud
- Under Management select Environment Settings
- Select a subscription
- Click on Settings & Monitoring
- Set the Status of Vulnerability assessment for machines to On
- Click Continue
Repeat the above for any additional subscriptions.
Impact:
Microsoft Defender for Servers plan 2 licensing is required, and configuration of Azure Arc introduces complexity beyond this recommendation.