Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium

A security engineer is configuring Microsoft Defender for Cloud for a new Azure subscription. The organization requires that all virtual machines (VMs) deployed in this subscription must have a specific set of security extensions installed, such as the Log Analytics agent and Azure Disk Encryption. The engineer wants to ensure that these extensions are automatically deployed to any new or existing VM that does not have them. Which Defender for Cloud capability, leveraging Azure Policy, should be used?

  1. AJust-in-Time (JIT) VM access
  2. BAuto-provisioning of agents and extensions
  3. CFile integrity monitoring
  4. DAdaptive application controls
Show answer & explanation

Correct answer: B. Auto-provisioning of agents and extensions

Auto-provisioning in Microsoft Defender for Cloud, often backed by Azure Policy's 'DeployIfNotExists' effect, is designed to automatically deploy necessary agents and extensions (like Log Analytics agent, Azure Disk Encryption, or Endpoint Protection) to new and existing VMs to ensure consistent security coverage.

Why the other options are wrong

  • A. JIT VM access is for reducing the attack surface of VMs by locking down inbound ports, not for deploying extensions.
  • C. File integrity monitoring (FIM) tracks changes to critical files and registries, which is a feature enabled by agents, but not the mechanism for deploying the agents themselves.
  • D. Adaptive application controls help harden VMs against malware by controlling which applications can run, not for deploying agents.

Defender for Cloud Auto-provisioning

Microsoft Defender for Cloud's auto-provisioning capability automatically deploys security-related agents and extensions to Azure, hybrid, and multi-cloud machines, ensuring consistent security monitoring and posture management.

  • Leverages Azure Policy's 'DeployIfNotExists' effect.
  • Ensures agents like Log Analytics agent are installed.
  • Can deploy Azure Disk Encryption and Endpoint Protection.
  • Simplifies initial setup and ongoing compliance for VMs.

Memory trick: Auto-deploy's aim: Agents always on, always active.

More Mitigate threats using Microsoft Defender for Cloud questions