9.1.3.4 Ensure that 'Agentless scanning for machines' component status is set to 'On'

Information

Using disk snapshots, the agentless scanner scans for installed software, vulnerabilities, and plain text secrets.

The Microsoft Defender for Cloud agentless machine scanner provides threat detection, vulnerability detection, and discovery of sensitive information.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Audit from Azure Portal

- From the Azure Portal Home page, select Microsoft Defender for Cloud
- Under Management select Environment Settings
- Select a subscription
- Under Settings > Defender Plans click Settings & monitoring
- Under the Component column, locate the row for Agentless scanning for machines
- Select On
- Click Continue in the top left

Repeat the above for any additional subscriptions.

Impact:

Agentless scanning for machines requires licensing and is included in these plans:

- Defender CSPM
- Defender for Servers plan 2

See Also

https://workbench.cisecurity.org/benchmarks/19304

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|3.1

Plugin: microsoft_azure

Control ID: f103ebdabd1f0ec054f09144b9f11843c337a2e9b6f874c48fbf2a5ece06ac01