Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudHard

A security engineer is configuring Microsoft Defender for Cloud for a sensitive Azure subscription. They need to ensure that any virtual machine deployed in this subscription is automatically configured with the Azure Monitor Agent (AMA) for data collection to support Defender for Cloud's recommendations and threat detection. Which Azure Policy effect should be used to achieve this automatic deployment for new VMs?

  1. ADeployIfNotExists
  2. BModify
  3. CDeny
  4. DAudit
Show answer & explanation

Correct answer: A. DeployIfNotExists

The 'DeployIfNotExists' Azure Policy effect is designed to automatically deploy a resource or configuration (like the Azure Monitor Agent) if it is not present on a newly deployed or existing resource, ensuring compliance and data collection.

Why the other options are wrong

  • B. Modify can add or update properties of resources, but 'DeployIfNotExists' is more suitable for ensuring a resource (like an agent) is *present* if it isn't already.
  • C. Deny would prevent VM deployment if AMA is not installed, which is too restrictive and not the goal of *automatic deployment*.
  • D. Audit only creates a warning; it does not deploy the agent.

Azure Policy 'DeployIfNotExists' Effect

An Azure Policy effect that ensures a specific resource or configuration is deployed if it's not detected on a target resource, commonly used for automated remediation and baseline enforcement.

  • Used to automatically deploy missing resources or configurations.
  • Evaluated after resource creation or update.
  • Ideal for deploying agents, extensions, or enabling settings.
  • Supports compliance by ensuring required components are present.

Memory trick: If the agent is not there, 'DeployIfNotExists' will show care.

More Mitigate threats using Microsoft Defender for Cloud questions