Information
Enable automatic discovery and configuration scanning of the Microsoft Kubernetes clusters.
Rationale:
As with any compute resource, Container environments require hardening and run-time protection to ensure safe operations and detection of threats and vulnerabilities.
Impact:
Agentless discovery for Kubernetes requires licensing and is included in:
Defender CSPM
Defender for Containers plans.
NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.
Solution
Audit from Azure Portal
From the Azure Portal Home page, select Microsoft Defender for Cloud
Under Management select Environment Settings
Select a subscription
Under Settings > Defender Plans, click Settings & monitoring
Locate the row for Agentless discovery for Kubernetes
Select On
Click Continue in the top left
Repeat the above for any additional subscriptions.
Default Value:
By default, Microsoft Defender for Containers is Off. If Defender for Containers is enabled from the Microsoft Defender for Cloud portal, auto provisioning will be enabled.