Secures container images and Kubernetes clusters wherever they run, whether AKS with ACR, EKS with ECR or GKE with Artifact Registry, and includes vulnerability scanning of registry images. Offered as a Defender for Cloud plan.
Also called Defender for Containers.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender for Containers in context, with comparison tables and the common traps.
Terms in this definition
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- AKS
Short for Azure Kubernetes Service, a managed Kubernetes offering that gives full control of clusters and node pools. Scaling uses the cluster autoscaler and Horizontal Pod Autoscaler; user sign-in is not built in.
- Azure Container Registry
Private Azure registry for container images. Images can be geo-replicated, cleaned up by retention policies and built by ACR Tasks, while webhooks let a push kick off continuous deployment.
- Amazon ECR
Amazon's registry service for container images, which Defender for Containers can scan once the AWS connector is in place.
- Artifact Registry
Google Cloud's service for storing container images. Once the GCP connector is set up, Defender for Containers can scan what it holds.
Related terms
- Agentless discovery for Kubernetes
Capability in Defender CSPM and Defender for Containers that inventories Kubernetes clusters and assesses their posture through APIs, using the Kubernetes Agentless Operator role. Pod admission and blocking are outside its scope.
- Container image vulnerability assessment
Agentless CVE scanning by Defender for Containers that covers images in registries and those running in clusters, kicked off when an image is pushed, imported or recently pulled.
- CWPP
Short for Cloud Workload Protection Platform: guarding live workloads, including servers, containers, storage and databases, against attack. Defender for Cloud delivers this with its individual Defender plans, Defender for Servers and Defender for Containers being two examples.
- Defender for container registries
Former Defender plan, now retired and folded into Microsoft Defender for Containers, which scanned ACR images when pushed, imported or recently pulled.
- Defender sensor
DaemonSet from Defender for Containers that runs on each node and gathers runtime telemetry with eBPF for threat detection. AKS gets it as a security profile; EKS and GKE get it as an Arc extension.
- Google Artifact Registry
Google Cloud's registry service for containers and packages. Defender CSPM and Defender for Containers both scan images held there for vulnerabilities.
- Microsoft Defender Vulnerability Management
Engine that Microsoft uses for vulnerability scanning in Defender for Containers and Defender for Servers, assessing container images and VMs, scale sets included.