3.1.4.2 Ensure that 'Agentless discovery for Kubernetes' component status 'On'

Information

Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.

Rationale:

As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.

Impact:

Agentless discovery for Kubernetes requires licensing and is included in:

Defender CSPM

Defender for Containers plans.

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Audit from Azure Portal

From the Azure Portal Home page, select Microsoft Defender for Cloud

Under Management select Environment Settings

Select a subscription

Under Settings > Defender Plans, click Settings & monitoring

Locate the row for Agentless discovery for Kubernetes

Select On

Click Continue in the top left

Repeat the above for any additional subscriptions.

Default Value:

By default, Microsoft Defender for Containers is Off. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.

See Also

https://workbench.cisecurity.org/benchmarks/16820

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|3.1

Plugin: microsoft_azure

Control ID: 2b8a208e0b979b2da7a95e42065aec2a2ef7784b40a9c74167aab8629a8614f0