Ensure that Auto provisioning of 'Vulnerability assessment for machines' is Set to 'On'

MEDIUM

Description

Description:

Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.

Rationale:

Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.

Additional licensing is required and configuration of Azure Arc introduces complexity beyond this recommendation.

Remediation

From Azure Portal

  1. From Azure Home select the Portal Menu
  2. Select 'Microsoft Defender for Cloud'
  3. Then 'Environment Settings'
  4. Select a subscription
  5. Then 'Auto Provisioning' in the left column.
  6. Ensure that 'Vulnerability assessment for machines' is set to 'On'

Repeat the above for any additional subscriptions.

Policy Details

Rule Reference ID: AC_AZURE_0019
CSP: Azure
Remediation Available: Yes
Resource Category: Management
Resource Type: Security Center

Frameworks