Ensure that the "Agentless scanning for machines" component is turned on for your Azure subscriptions within Microsoft Defender for Cloud, so that connected virtual machines are automatically discovered and assessed without requiring the deployment of an in-guest agent. Agentless scanning becomes available once either the Microsoft Defender Cloud Security Posture Management (CSPM) plan or the Defender for Servers Plan 2 pricing plan is enabled for the subscription, and, once turned on, it periodically creates a secure, isolated snapshot of each supported machine's operating system and data disks to build a software inventory, identify known vulnerabilities, and detect plaintext secrets; when Defender for Servers Plan 2 is enabled, agentless scanning also scans the machine for malware. Agentless scanning runs on a fixed, non-configurable schedule of once every 24 hours, and it doesn't require network connectivity to the target machine or affect its performance.
The Microsoft Defender for Cloud agentless machine scanner provides threat detection, vulnerability detection, and discovery of sensitive information for virtual machines that don't have (or can't have) an in-guest Microsoft Defender for Endpoint agent installed, without adding operational overhead or performance impact to the scanned machines. Without agentless scanning enabled, unmanaged, unpatched, or misconfigured virtual machines can remain outside the coverage of Defender for Cloud's vulnerability assessment, software inventory, secrets scanning, and (when Defender for Servers Plan 2 is enabled) malware detection capabilities, increasing the risk that outdated software, exposed credentials, or malicious files on these machines go undetected until they're exploited or cause a security incident.
Note: Agentless scanning results are refreshed once every 24 hours on a fixed schedule, so allow up to 24 hours after enabling the setting before results appear. Malware detection is only available when Defender for Servers Plan 2 is enabled — enabling Defender CSPM alone provides software inventory, vulnerability assessment, and secrets scanning, but not malware scanning.
Audit
To determine if "Agentless scanning for machines" is enabled in Microsoft Defender for Cloud for your Azure subscriptions, perform the following operations:
Remediation / Resolution
To enable "Agentless scanning for machines" in Microsoft Defender for Cloud for your Azure subscriptions, perform the following operations:
Note: Enabling "Agentless scanning for machines" requires either the Microsoft Defender Cloud Security Posture Management (CSPM) plan or the Defender for Servers Plan 2 pricing plan to be enabled for the target Azure subscription. Agentless scanning itself is included at no additional cost within these plans, however Defender CSPM and Defender for Servers Plan 2 are billed pricing plans — review the Microsoft Defender for Cloud pricing page before enabling either plan.References
- Azure Official Documentation
- Enable agentless machine scanning - Microsoft Defender for Cloud
- Agentless machine scanning in Microsoft Defender for Cloud - Microsoft Defender for Cloud
- Agentless malware scanning for machines in Microsoft Defender for Cloud - Microsoft Defender for Cloud
- Pricing - Microsoft Defender for Cloud | Microsoft Azure
- Incident Response - Microsoft cloud security benchmark
- CIS Security Documentation
- CIS Microsoft Azure Benchmarks
- Azure Command Line Interface (CLI) Documentation
- az account list
- az account set
- az security pricing list
- az security pricing create