Disable Microsoft Defender for Cloud for select virtual machines in Azure

Paul Nerie 266 Reputation points
2024-05-02T01:43:52.0066667+00:00

I have several VMs running Windows 10/11 and Ubuntu in my Azure vnet and I really don't need them included in Microsoft Defender for Cloud.

I've done some searching and apparently there is no way to select which VMs are included in the service, it's an all-or-nothing affair.

However I a couple of articles that there might be a way to do this using API calls. Like the below:

https://www.seifbassem.com/blogs/posts/defender-for-servers-resource-level/

I've tried it out but it looks like it does not work. In the Inventory page the VMs are still tagged as 'On'.

I could be doing this wrong, maybe someone else has a better insight.

Thank in advance!

Azure Virtual Machines
Azure Virtual Machines
An Azure service that is used to provision Windows and Linux virtual machines.
7,256 questions
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,212 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Marcin Policht 13,175 Reputation points MVP
    2024-05-02T02:05:51.7266667+00:00

    This is available for Defender for Servers plans - it's documented and supported by Microsoft. Details at https://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-servers-plan#enable-defender-for-servers-at-the-resource-level


    If the above response helps answer your question, remember to "Accept Answer" so that others in the community facing similar issues can easily find the solution. Your contribution is highly appreciated.

    hth

    Marcin