Defender for Cloud technique that inspects snapshots of VM disks for secrets, vulnerabilities and installed software, with nothing installed on the VM.
Also called agentless machine scanning.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Agentless scanning in context, with comparison tables and the common traps.
Related terms
- Defender CSPM
Defender for Cloud's paid posture tier. On top of the free foundations it brings agentless scanning, attack path analysis, AI security posture management and the cloud security explorer.
- Defender for Servers Plan 1
The lower of the two Defender for Servers tiers: it includes Defender for Endpoint integration, giving EDR and anti-malware, plus vulnerability assessment through an agent. JIT access, FIM and agentless scanning come only with Plan 2.
- Defender for Servers Plan 2
Top Defender for Servers tier, which includes FIM, JIT VM access, agentless scanning and, from August 2023, Defender for DNS alerts. You turn it on per subscription or per Log Analytics workspace.
- Microsoft Defender for Cloud Servers Scanner Resource Provider
First-party app (ID 0c7668b5-3260-4ad0-9f53-34ed54fa19b2) behind agentless scanning. Where disks use a CMK, it requires the Key Vault Crypto Service Encryption User role or the Get, Wrap Key and Unwrap Key permissions.
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.