How to get information about resources connected with Microsoft Defender for Cloud.

Karan Bhatt 47 Reputation points
2023-09-26T01:17:57.62+00:00

Since last few days, I am receiving lots of requests from the users about to know when the Azure VM was connected or integrated with Microsoft Defender for Cloud.

Eg:- The VM was not connected with Defender for Cloud in Sept 2022 and now it's found connected. Tried to get information from Audit logs but didn't find a records past 30 days.

Is there any way to know the exact date when the Azure VM got connected with Defender for Cloud?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,392 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Akshay-MSFT 17,871 Reputation points Microsoft Employee
    2023-09-26T14:26:01.96+00:00

    @Karan Bhatt

    Thank you for posting your query on Microsoft Q&A. From above description I could understand that you want to know when did the VM first onboarded to Microsoft Defender for Cloud.

    Please do correct me if this is not the case by responding in the comments section.

    Microsoft Defender for cloud is enabled at subscription level and plans available under Cloud Workload Protection (CWP) are responsible for actions on your resources.

    For example if you are trying to target VM in your environment, then CSPM plan has to be enabled, and once enabled any VM deployed in the environment will be visible under defender for cloud inventory, this should be done on very same day when VM is deployed.

    User's image

    If you have enabled monitoring agent for the device you may get the details from Log-analytics

    User's image

    If you did push Endpoint protection say via Azure policy, then device would be visible then it would be visible on defender for endpoint portal along with onboarding date, which you could consider the time when device was on boarded to defender for endpoint.

    User's image

    Thanks,

    Akshay Kaushik

    Please "Accept the answer" (Yes), and share your feedback if the suggestion answers you’re your query. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.