Engine that Microsoft uses for vulnerability scanning in Defender for Containers and Defender for Servers, assessing container images and VMs, scale sets included.
Also called MDVM, TVM.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender Vulnerability Management in context, with comparison tables and the common traps.
Terms in this definition
- Microsoft Defender for Containers
Secures container images and Kubernetes clusters wherever they run, whether AKS with ACR, EKS with ECR or GKE with Artifact Registry, and includes vulnerability scanning of registry images. Offered as a Defender for Cloud plan.
- Microsoft Defender for Servers
Covers Arc-enabled servers and Azure VMs in Defender for Cloud. Plan 1 brings integration with Defender for Endpoint; Plan 2 goes further with agentless scanning, file integrity monitoring and alerts from Defender for DNS.
- Container
Something that groups data. Blob Storage containers sit inside a storage account and hold blobs much as folders hold files; Cosmos DB containers hold items and set the scope for partitioning and throughput.
- Virtual machines
Infrastructure-as-a-service compute giving complete control of the operating system, making it a fit for lift-and-shift moves and for software relying on OS-level pieces like COM.
Related terms
- Microsoft Defender Vulnerability Management add-on
Licence giving devices premium MDVM features, such as firmware and certificate assessment, security baselines and blocking of vulnerable apps. Servers covered by Defender for Servers Plan 2 have these already.
See Microsoft Defender Vulnerability Management in the full glossary