3.1.3.4 Ensure that 'Agentless scanning for machines' component status is set to 'On'

Information

Using disk snapshots, the agentless scanner scans for installed software, vulnerabilities, and plain text secrets.

Rationale:

The Microsoft Defender for Cloud agentless machine scanner provides threat detection, vulnerability detection, and discovery of sensitive information.

Impact:

Agentless scanning for machines requires licensing and is included in these plans:

Defender CSPM

Defender for Servers plan 2

NOTE: Nessus has not performed this check. Please review the benchmark to ensure target compliance.

Solution

Audit from Azure Portal

From the Azure Portal Home page, select Microsoft Defender for Cloud

Under Management select Environment Settings

Select a subscription

Under Settings > Defender Plans, click Settings & monitoring

Under the Component column, locate the row for Agentless scanning for machines

Select On

Click Continue in the top left

Repeat the above for any additional subscriptions.

Default Value:

By default, Agentless scanning for machines is off.

See Also

https://workbench.cisecurity.org/benchmarks/16820

Item Details

Category: RISK ASSESSMENT

References: 800-53|RA-5, CSCv7|3.1

Plugin: microsoft_azure

Control ID: 4b91a8457626c2f8aa4e45a6df27f11e0cd4bd2ca492e5e9fe39c80a1411d008