Intelligent Assessment: Natural language Guardrails powered by AI →
Mods
Azure

Policy: Azure > CIS v3.0 > 03 - Security > 03.01 - Microsoft Defender for Cloud > 03.01.04 - Defender Plan Containers > 03.01.04.03 - Ensure that 'Agentless container vulnerability assessment' component status is 'On'

Configures auditing against a CIS Benchmark item.

Level: 2

Enable automatic vulnerability management for images stored in ACR or running in AKS clusters.

Agentless vulnerability scanning will examine container images - whether running or in storage - for vulnerable configurations.

Targets

This policy targets the following resource types:

Primary Policy

This policy is used with the following primary policy:

Policy Specification

Schema Type
string
Default
Per Azure > CIS v3.0 > 03 - Microsoft Defender
Valid Values [YAML]
  • Per Azure > CIS v3.0 > 03 - Microsoft Defender
    
  • Skip
    
  • Check: Benchmark using attestation
    

Category

In Your Workspace

Developers