Azure Arc connected servers: 1 or 2 expired self signed certificates in machine My store

Andre++ 21 Reputation points
2023-12-11T19:00:16.32+00:00

We find that after a year any onboarded Arc connected server has 1 or 2 expired self signed certificates in its machine My store. (Microsoft.Azure.AzureDefenderForServers.MDE.Windows, Microsoft.EnterpriseCloud.Monitoring.MicrosoftMonitoringAgent, resp.)

Everything seems working normally. Agent is connected and all looks fine. However, in Defender for Servers, TVM, Certificate inventory we see thousands of these expired certificates.
Should these be renewed? Or could these safely be removed? If so, what is/was the purpose of these certificates (only used during enrollment? Why are these not removed then?)
User's image

User's image

Azure Arc
Azure Arc
A Microsoft cloud service that enables deployment of Azure services across hybrid and multicloud environments.
513 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,542 questions
{count} votes

Accepted answer
  1. Akshay-MSFT 17,941 Reputation points Microsoft Employee Moderator
    2023-12-12T08:46:49.5066667+00:00

    @Andre++

    Thank you for your time and patience, from above description I could understand that you are looking for advisory on the following:

    • What is the purpose of certificate issued from Microsoft Defender for endpoint or Microsoft Monitoring agent?
    • Is it safe to remove the expired certificates?

    Please do correct me if you find any discrepancies in above ask by responding in the comments:

    Purpose of the certificate is that each extension creates a certificate to establish secure connection with the backend (Azure service, in your case MDE and Azure Monitor). Also, certificate is used for authentication. A new certificate should automatically renew when the certificate expired.

    You may delete the expired certificates as new one should automatically be renewed after the predefined threshold by Azure services. As the services don't have any mechanism to delete the certificate from any VMs/Azure ARC.

    Thanks,

    Akshay Kaushik

    Please "Accept the answer(Yes)" and "share your feedback ". This will help us and others in the community as well.


0 additional answers

Sort by: Most helpful

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.