Does MS Defender provides security features (like vulnerability scanning and Intrusion prevention etc) can be configure for Azure Cloud service (extended support) CS-ES.

AzureGladiator 40 Reputation points
2024-12-13T13:37:57.6933333+00:00

Defender documentation shows The vulenerability scan is limited to VM as supported destinations only. Also the Defender inventory list does not shows any CS-ES instances protected by it.

Azure Cloud Services
Azure Cloud Services
An Azure platform as a service offer that is used to deploy web and cloud applications.
776 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

Accepted answer
  1. Prrudram-MSFT 28,366 Reputation points Microsoft Employee Moderator
    2024-12-13T13:44:53.1233333+00:00

    Hello @Gaurav Sharma

    I see you're referring to the limitations of Microsoft Defender's vulnerability scanning capabilities.
    You're correct that Microsoft Defender Vulnerability Management primarily supports vulnerability scanning for virtual machines (VMs) as the main destination. This includes Azure virtual machines and Azure Arc-enabled machines
    Regarding the inventory list, it seems that CS-ES (Cloud Services - Enterprise Scale) instances are not currently included in the supported inventory for Microsoft Defender. This document below might explain why you're not seeing any CS-ES instances protected by it.

    https://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-defender-vulnerability-management
    You can also look at the following support matrix link for defender for cloud https://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-cloud#security-benefits-for-azure-servicesUser's image

    Hope this helps! If you have any questions, please tag me in your comments.

    If I have answered your question, please accept this as answer as a token of appreciation and don't forget to thumbs up for "Was it helpful"!


1 additional answer

Sort by: Most helpful
  1. Ibrahima Mbodji 165 Reputation points MVP
    2024-12-13T13:48:33.1566667+00:00

    Hi Gaurav

    If you are referring to Defender for cloud CWP (Cloud Workload Protection) in general It's not limited to Azure VM /VMSS , you also have Azure storage (Malware scanning ) , Containers (K8S and Azure container registry) and Azure SQL . Azure Firewall is the right service that offers IPS/IDS.

    According to doc only CSPM is supported for Azure Cloud service

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.