Microsoft Security Operations AnalystMitigate threats using Microsoft Defender for CloudMedium
A security engineer is configuring a new Azure subscription for a development team. They need to ensure that all virtual machines provisioned in this subscription are automatically onboarded to Microsoft Defender for Servers Plan 2, including the installation of necessary agents. The solution should be scalable and require minimal manual intervention. Which Defender for Cloud setting should the engineer configure?
- APolicy management
- BSecurity alerts configuration
- CResource hygiene
- DAuto-provisioning
Show answer & explanationAnswer & explanation
Correct answer: D. Auto-provisioning
Auto-provisioning in Microsoft Defender for Cloud automatically deploys necessary agents (like the Log Analytics agent or Defender for Endpoint agent) to newly created or existing VMs, ensuring they are onboarded to Defender for Servers Plan 2 without manual intervention.
Why the other options are wrong
- A. Policy management uses Azure Policy to enforce standards but doesn't directly handle agent installation for Defender for Cloud onboarding.
- B. Security alerts configuration manages how alerts are generated and handled, not the provisioning of protection.
- C. Resource hygiene refers to the overall security posture and health of resources, not an onboarding mechanism.
Auto-provisioning (Defender for Cloud)
Auto-provisioning in Microsoft Defender for Cloud enables the automatic deployment of relevant agents and extensions (e.g., Log Analytics agent, Azure Monitor Agent, Defender for Endpoint extension) to supported Azure resources, ensuring they are protected by Defender for Cloud plans.
- Automates agent deployment for Defender for Cloud plans.
- Ensures consistent security coverage for new and existing resources.
- Reduces manual effort for onboarding resources.
Memory trick: Auto-provisioning means 'set it and forget it' for Defender's agents.