Azure Update Manager support for CIS-Hardened Images (Windows)

CelsoScarpim 25 Reputation points
2024-05-07T03:30:29.24+00:00

Hello there,

Any further update on support for CIS hardened images (Windows 2019/2022) in Azure Update Manager?

What's the recommended action if the deadline arrives and the support is not ready?

I saw somewhere else a possible option that would include using a non-cis image, enrolling it in the new Update Management Service, and then using the CIS scripts to harden the image. Is that possible/feasible/supported?

Thanks in advance.

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,255 questions
Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
303 questions
{count} votes

3 answers

Sort by: Most helpful
  1. AnTu31 6 Reputation points
    2024-08-01T07:33:07.0733333+00:00

    CIS images should have been supported by the end of July.

    https://techcommunity.microsoft.com/t5/azure-governance-and-management/azure-update-manager-to-support-cis-hardened-images-among-other/ba-p/4195864

    However mine are still showing as unsupported.

    User's image

    1 person found this answer helpful.

  2. Nikhil Mengaram 25 Reputation points Microsoft Employee
    2024-05-16T05:58:51.9733333+00:00

    Hi CelsoScarpim,

    Update manager team is working on supporting CIS hardened images in marketplace, as of now there is no ETA as validations are being made.

    It is possible to use Update manager on a marketplace vm and then harden it using scripts. Note that in this case Update manager can be used but this scenario is unsupported as currently Azure Update Manager doesn't support hardened images.

    0 comments No comments

  3. Riva Yadav 1 Reputation point Microsoft Employee
    2024-08-21T06:46:42.8466667+00:00

    Support for CIS hardened images in Azure Update Manager has been released. Refer to this blog post: https://aka.ms/aum-cis-images-blog

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.