How to enable Microsoft Defender for Container on one cluster instead of whole subscription

DiptiRanjan Swain 216 Reputation points
2024-02-06T10:46:35.9833333+00:00

Hi, I am trying to enable Microsoft Defender for Container on a specific AKS cluster instead of the whole subscription. I do not want to enable it on the whole subscription. I also tried to auto fix it under the recommendation "Azure Kubernetes Service clusters should have Defender profile enabled" but that is failing without showing the reason although I have contributor access on the AKS cluster. Can someone provide me the steps/document on how to enable and configure Microsoft Defender for Container on a specific AKS cluster

Azure Kubernetes Service
Azure Kubernetes Service
An Azure service that provides serverless Kubernetes, an integrated continuous integration and continuous delivery experience, and enterprise-grade security and governance.
2,458 questions
Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
{count} votes

Accepted answer
  1. Inbal Beitler 80 Reputation points Microsoft Employee
    2025-06-24T10:22:13.0866667+00:00

    This capability is now in preview, it is now possible to enable Defender for containers on a single cluster, enablement is available through the AKS security dashboard in the Azure portal, or through API.


1 additional answer

Sort by: Most helpful
  1. Michael Morten Sonne 605 Reputation points MVP
    2024-02-06T13:04:37.1166667+00:00

    Hi DiptiRanjan Swain,

    As of the current state of features, it is not possible to enable Microsoft Defender for Container on a single cluster; it applies to the entire Azure subscription.

    This is also stated in the documentation under https://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction - and FAQ here: https://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-general

    Defender for Servers has recently entered preview, but the activation is currently only available through the REST API, not the Portal (yet).

    Here is the documentaion: https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-servers-plan#enable-defender-for-servers-at-the-resource-level

    And a script to help: https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Powershell%20scripts/Defender%20for%20Servers%20on%20resource%20level

    The only option, if you do not want to enable it for your entire subscription, is to separate them into different Azure subscriptions from what I know about.

    Hope it helps a bit still. We can hope it comes here to in the feature.

    1 person found this answer helpful.

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.