Information
Using disk snapshots, the agentless scanner scans for installed software, vulnerabilities, and plain text secrets.
The Microsoft Defender for Cloud agentless machine scanner provides threat detection, vulnerability detection, and discovery of sensitive information.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Audit from Azure Portal
- From the Azure Portal Home page, select Microsoft Defender for Cloud
- Under Management select Environment Settings
- Select a subscription
- Under Settings > Defender Plans click Settings & monitoring
- Under the Component column, locate the row for Agentless scanning for machines
- Select On
- Click Continue in the top left
Repeat the above for any additional subscriptions.
Impact:
Agentless scanning for machines requires licensing and is included in these plans:
- Defender CSPM
- Defender for Servers plan 2