Skip to main content

More Info:

Ensure that Microsoft Defender for Cloud is enabled for Azure containers.

Risk Level

High

Address

Operational Maturity, Security

Compliance Standards

  • CIS AZURE

Triage and Remediation

Remediation

Using Console

To enable Microsoft Defender for Cloud for Azure Containers, please follow the below steps:
  1. Go to the Azure portal and log in with your credentials.
  2. Navigate to the “Security Center” from the left-hand side menu.
  3. Click on “Security Center” and then select “Azure Defender” from the top menu.
  4. Click on “Container Security” and then select “On” to enable Microsoft Defender for Cloud for Azure Containers.
  5. Review the pricing tier options and select the one that suits your requirements.
  6. Click on “Save” to apply the changes.
  7. Once the changes are saved, you will see the status change to “Enabled” under the “Azure Defender” dashboard.
By following these steps, you will have successfully enabled Microsoft Defender for Cloud for Azure Containers.

To enable Microsoft Defender for Cloud for Azure Containers using AZURE CLI, follow these steps:
  1. Open the Azure CLI command prompt and log in to your Azure account.
  2. Run the following command to check if the Azure Defender for Container Registries is enabled:
    Replace <registry-id> with the ID of the registry you want to enable Azure Defender for.
  3. If the Azure Defender for Container Registries is not enabled, run the following command to enable it:
    Replace <registry-id> with the ID of the registry you want to enable Azure Defender for.
  4. Run the following command to check if the Azure Defender for Container Images is enabled:
    Replace <registry-id> with the ID of the registry you want to enable Azure Defender for.
  5. If the Azure Defender for Container Images is not enabled, run the following command to enable it:
    Replace <registry-id> with the ID of the registry you want to enable Azure Defender for.
  6. Finally, run the following command to check the status of the Azure Defender for Container Images:
    Replace <registry-id> with the ID of the registry you want to check the status for.
That’s it! You have successfully enabled Microsoft Defender for Cloud for Azure Containers using AZURE CLI.
To enable Microsoft Defender for Cloud for Azure Containers using Python, you can follow the below steps:Step 1: Install the Azure SDK for Python using the following command:
Step 2: Authenticate with Azure using the following code:
Step 3: Get the resource group and container registry where you want to enable Microsoft Defender for Cloud. You can use the following code to get the resource group and container registry:
Step 4: Enable Microsoft Defender for Cloud for Azure Containers using the following code:
After running the above code, Microsoft Defender for Cloud for Azure Containers will be enabled for the specified container registry.
These changes do not force resource replacement; they update the Defender pricing plan on the subscription.Verification: terraform plan should show azurerm_security_center_subscription_pricing.kubernetes_service_defender and .container_registry_defender being created or updated with tier = "Standard" and the corresponding resource_type values.