lacework-global-611
Set Auto provisioning of 'Vulnerability assessment for machines' to 'On' (Manual)
This rule has been changed to manual, see Permanently Manual Policies (that were deemed automated) for CIS Azure 1.5.0 for details.
Profile Applicability
• Level 2
Description
Enable automatic provisioning of vulnerability assessment for machines on both Azure and hybrid (Arc enabled) machines.
Rationale
Vulnerability assessment for machines scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection, then produces alerts on threat and vulnerability findings.
Impact
Additional licensing is required and configuration of Azure Arc introduces complexity beyond this recommendation.
Audit
From Azure Portal
- From Azure Home select the Portal Menu
- Select
Microsoft Defender for Cloud
- Then
Environment Settings
- Select a subscription
- Click on
Auto Provisioning
in the left column. - Ensure that
Vulnerability assessment for machines
is set toOn
Repeat the above for any additional subscriptions.
Remediation
From Azure Portal
- From Azure Home select the Portal Menu.
- Select Microsoft Defender for Cloud.
- Then Environment Settings.
- Select a subscription.
- Click Settings & Monitoring.
- Set Vulnerability assessment for machines to On.
- Select the appropriate Extension deployment configuration for the subscription and click Apply.
- Click Continue.
Repeat the preceding steps for any additional subscriptions.
References
https://docs.microsoft.com/en-us/azure/defender-for-cloud/enable-data-collection?tabs=autoprovision-va
https://msdn.microsoft.com/en-us/library/mt704062.aspx
https://msdn.microsoft.com/en-us/library/mt704063.aspx
https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/list
https://docs.microsoft.com/en-us/rest/api/securitycenter/autoprovisioningsettings/create
https://docs.microsoft.com/en-us/security/benchmark/azure/security-controls-v3-posture-vulnerability-management#pv-5-perform-vulnerability-assessments
Additional Information
While this feature is generally available as of publication, it is not yet available for Azure Government tenants.