Enable agentless machine scanning
In brief
The article now details supported Azure, AWS, and GCP machines, Kubernetes coverage, capabilities by plan, scan limitations, unsupported configurations, permissions, and the 24-hour schedule. It also directs administrators to review coverage before enabling scanning.
What Defender admins need to know
Administrators can use the updated guidance to verify coverage and limitations before enabling agentless scanning; no required change is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
title: Enable agentless machine scanning
description: RunLearn what agentless scanning on Virtual Machines (VMs) for vulnerabilitiescovers, review supported Azure, AWS, and threatsGCP machines, and enable scanning in Microsoft Defender for Cloud.
ms.topic: how-to
ms.date: 06/02/08/24/2026
ms.custom: sfi-image-nochangenochange, msecd-doc-authoring-1013
#customer intent: As a security administrator, I want to enable agentless scanning for VMs so that I can identify vulnerabilities and threats without impacting performance. ai-usage: ai-assisted
Enable agentless machine scanning
Agentless machine scanning helps you discover vulnerabilities, secrets, malware signals, and software inventory across cloud machines without deploying endpoint agents. In Microsoft Defender for Cloud, this capability runs through your cloud connectors so security teams can scale coverage with low operational overhead and minimal performance impact.
This article explains the supported environments, important coverage limitations, and how to enable and manage scanning across Azure, AWS, and GCP environments so you can onboard protection quickly and start investigating findings. If your environment has plan or permission dependencies, review prerequisitesGCP.
Agentless machine scanning in Microsoft Defender for Cloud improves the security posture of machines connected to Defender for Cloud. Agentless machine scanning includes capabilities such as scanning for software inventory, vulnerabilities, secrets, and malware.
- Agentless scanning
doesn't require installed agents or network connectivity, and it doesn't affect machine performance. You can turn agentless machine scanning on or off, but you can't disable individual capabilities.Scans only run on VMs that are running. VMs that are off during a scan aren't scanned.The scanruns once every 24 hours on a nonconfigurableschedule once every 24 hours.
What agentless scanning covers
When you turn on The following table shows what each capability provides and which plans include it.
| Capability | What it provides | Defender CSPM | Defender for Servers Plan 2
|
|---|
When you enable agentless scanning | Yes | Yes | |
For malware scanning of Kubernetes node VMs, either Defender for Servers Plan 2 or | Yes | Yes | |
| Yes | Yes | ||
| Malware scanning | Detects malicious files and generates security alerts for detected threats. Review Malware scanning coverage and limitations. | No | Yes |
Agentless scanning has one setting for each connected environment, such as an Azure subscription, AWS account, or GCP project. The plans enabled for that environment determine which agentless capabilities are available. Individual agentless capabilities can't be turned on or off separately.
Agentless scanning supports Azure standard VMs and virtual machine scale sets that use flexible orchestration, subject to these limits:
Agentless scanning supports:
Amazon Machine Images (AMIs) that require third-party licensing, including applicable AWS Marketplace images, aren't supported.
Agentless scanning supports Compute Engine instances and instance groups, both managed and unmanaged, with Google-managed encryption keys or customer-managed encryption keys (CMEK).
GCP organization policies can prevent Defender for Cloud from creating or accessing the snapshots required for scanning. If no results appear within 24 hours, review Resolve an agentless scan error for GCP. Agentless malware scanning provides periodic, point-in-time visibility rather than continuous or real-time protection. The amount and type of content on a VM can affect scan coverage. A malware scan can complete with partial VM coverage when a compressed package meets any of these conditions: For a lower risk of partial coverage, use these planning targets for the total number of files eligible for malware scanning across the VM: Workloads that create or modify approximately 200,000 files or more between scans can also have an increased risk of partial coverage.
The following files might not be scanned:
Partial coverage doesn't discard the scan results. Detections from content that was successfully scanned are still reported.
To improve coverage:
Agentless scanning doesn't support the following configurations.
Verify the following requirements:
Use the rollout guidance in this section, and then follow the procedure for each cloud environment. A phased rollout helps you confirm permissions, identify unsupported machines, and establish a repeatable process before enabling agentless scanning across a large environment. Select a representative Azure subscription, AWS account, or GCP project. Review its machines against the supported coverage and limitation tables on this page. If malware scanning is required, review the file-count and compressed-package guidance. Confirm that the required plan, connector, and encryption permissions are in place. Define which results you expect to see for the test machines. Enable agentless scanning Verify that software inventory or vulnerability results appear. To validate malware scanning, follow Test agentless malware scanning. Resolve permission, connector, or support issues. Repeat the process for the next group of subscriptions, accounts, or projects. To enable agentless scanning In Defender for Cloud, open Environment settings.
Select the relevant subscription.
For In Settings and :::image type="content" source="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png" alt-text="Screenshot of Select Save.
Allow up to 24 hours for To assign these permissions To enable agentless scanning In Defender for Cloud, open Environment settings.
Select the relevant AWS account.
For Select Save and Next: Configure Access.
Download the CloudFormation template.
If you're onboarding Select Next: Review and generate To enable agentless scanning In Defender for Cloud, Select the relevant GCP project or organization.
For Set Agentless scanning to On.
Select Save and Next: Configure Access.
Copy Select Next: Review and generate Allow up to 24 hours for the next scheduled scan. If results don't appear, check whether a GCP organization policy is restricting disk, image, or snapshot access.Supported machines and scan coverage
Scan timing and machine state
Condition
Coverage
The machine is running during its scheduled scan
The machine is eligible to be scanned.
The machine is stopped or deallocated during its scheduled scan
The machine isn't scanned during that cycle. Results can remain missing or outdated until the machine is running during a later scheduled cycle.
Agentless scanning was just enabled or connector permissions were updated
Allow up to 24 hours for the next scheduled scan before troubleshooting missing results.
Azure VM requirements
Requirement
Supported coverage
Combined size of the operating system disk and all data disks is 4 TB or less
The operating system disk and supported data disks can be scanned.
Combined size of the operating system disk and all data disks exceeds 4 TB
Only the operating system disk is scanned, and only when that disk is less than 4 TB. Data disks aren't scanned.
The VM has 14 disks or fewer
The VM is within the supported disk-count limit. VMs with more than 14 disks aren't supported.
Disks use platform-managed keys
Supported.
Managed disks use customer-managed keys
Supported after you grant the additional Key Vault permissions described in Azure VMs with customer-managed keys. AWS requirements
GCP requirements
Malware scanning coverage and limitations
Compressed package limits
Condition Partial-coverage threshold Compressed package size Larger than 1 GB Files in a compressed package More than 10,000 files Nested archive depth More than five archive levels File-count planning targets
Operating system Planning target Windows Up to approximately 300,000 files Linux Up to approximately 500,000 files Files that might not be scanned
What partial coverage means
Limitations and unsupported configurations
Category
Unsupported configuration
Coverage consequence
Azure disk type
UltraSSD_LRS, PremiumV2_LRS, or Azure Kubernetes Service (AKS) ephemeral OS disksIf any disk attached to the VM uses one of these disk types, the VM isn't scanned.
Resource type
Databricks VMs
The VM isn't supported for agentless scanning.
File system
UFS (Unix File System), ReFS (Resilient File System), or ZFS (ZFS Member)
If any disk uses one of these file systems, the VM isn't scanned.
RAID or block-storage format
OracleASM (Oracle Automatic Storage Management), DRBD (Distributed Replicated Block Device), or
Linux_Raid_MemberIf any disk uses one of these formats, the VM isn't scanned.
Integrity mechanism or partition
DM_Verity_Hash or swapIf any disk contains one of these configurations, the VM isn't scanned.
Before you begin
virtualdisks encrypted with customer-managed keys, grant the additional Key Vault permissions described in Azure VMs with customer-managed keys. AWS and GCP connector setup includes the required permissions for their key-management services.Enable agentless scanning
Plan your rollout
Benefits of a phased rollout
(VMs), Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances,that exceed disk limits or use unsupported configurations before broad deployment.Google Cloud Platform (GCP) compute instances without installing an agent, if theycustomer-managed encryption keys can be accessed as expected.Guidelines for a successful rollout
Guideline Recommended approach Choose a representative test environment Include common machine types and any customer-managed encryption, large disks, multiple data disks, or scale sets used in your organization. Review support before enabling Check disk size, disk count, disk type, file system, encryption, and machine power-state requirements. Record machines that aren' re connected to Microsoft Defender for Cloudt supported.Assess malware content scale For malware scanning, compare file counts, file-change volume, and compressed packages with the coverage guidance.
Azure VMsDefine the expected resultsAgentless scanning is availableDecide which software inventory, vulnerability, secrets, or malware results you expect based on Azure standard VMs with:the
- Maximum total disk size of 4 TB (sum of all disks). If this limit is exceeded, only OS disk is scanned whenplan enabled for the OS disk is less than 4 TB.environment.
- Maximum number of disks allowed: 14
- Virtual machine scale set - Flex
Support for disks that are:
- Unencrypted
- Encrypted (managed disks using Azure Storage encryption with platform-managed keys (PMK))
- Encrypted with customer-managed keys.
AWSAllow for the scan scheduleAgentless scanning is available on EC2, Auto Scale instances, and disks that are unencrypted, encrypted (PMK), and encrypted (CMK). AMIs requiring third-party licensing, for example from AWS Marketplace, are not supported.Wait up to 24 hours after enablement or permission changes before assessing the results.
GCPVerify results, not only the settingAgentless scanning is available on compute instances, instance groups (managed and unmanaged), with Google-managed encryption keys, and customer-managed encryption key (CMEK)Confirm that results appear for the expected test machines. An enabled setting alone doesn't confirm successful coverage.
Kubernetes nodesResolve exceptions before expandingAgentless scanning for vulnerabilities and malware in Kubernetes node VMs is available.Correct missing permissions or connector configuration. Document machines that remain outside the
For vulnerability assessment, Defender for Servers Plan 2,Defender for Containers plan, or the Defender cloud security posture management (Defender CSPM) plan is required.supported configuration.
For malware scanning, Defender for Servers Plan 2 or Defender for Containers is required.
PermissionsRoll out in manageable groupsReview the permissions used by Defender for Cloud for agentless scanning.UnsupportedDisk type - If any of the VM's disks are on this list, the VM isn't scanned: - UltraSSD_LRS - PremiumV2_LRS -Enable additional Azure Kubernetes Service (AKS) Ephemeral OS Disks Resource type: - Databricks VM File systems: - UFS (Unix File System) - ReFS (Resilient File System) - ZFS (ZFS Member) RAIDsubscriptions, AWS accounts, or GCP projects in batches and Block storage formats: - OracleASM (Oracle Automatic Storage Management) - DRBD (Distributed Replicated Block Device) - Linux_Raid_Member Integrity mechanisms: - DM_Verity_Hash - Swapverify each batch before continuing.Recommended rollout sequence
on and allow up to 24 hours for the scheduled scan.Azure
on Azure:for an Azure subscription:
either the Defender CSPM plan, or Defender for Servers Plan 2,2, select Settings.
:::::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png" alt-text="Screenshot of the settings link for the settings of the Defender plans forin an Azure accounts.subscription." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png":::
monitoring,monitoring, turn on Agentless scanning for machines.
settings and monitoring screenthe setting used to turn on agentless scanning.scanning for Azure machines." lightbox="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png":::
EnableAzure VMs with CMK encrypted disksTo enable agentless scanning for the next scheduled scan. If results don't appear, use the troubleshooting checklist.Azure VMs with customer-managed
key (CMK) encrypted disks:keysFor agentless scanning of Azure VMs with CMKdisks encrypted disks, you need to grantby customer-managed keys require additional Key Vault permissions. These permissions allow Defender for Cloud extra permissions on Key Vaults used for CMK encryption for the VMs, to create and examine a secure copy of the disks.encrypted disk.
To manually assign theAssign permissions on a Key Vault:Key vaults with non-RBAC permissions: Assign "Microsoft Defender for Cloud Servers Scanner Resource Provider" ( with application ID 0c7668b5-3260-4ad0-9f53-34ed54fa19b2) these permissions:. Get,, and Unwrap Key Wrap, Key Unwrap. permissions.Key vaults using RBAC permissionsFor a key vault that uses Azure role-based access control (RBAC):: Assign "Microsoft Defender for Cloud Servers Scanner Resource Provider” (0c7668b5-3260-4ad0-9f53-34ed54fa19b2) the Key Vault Crypto Service Encryption User built-in role.at scale foracross multiple Key Vaults, use the agentless scanning CMK support script.
Enable agentless scanning on AWS
on AWS:for an AWS account:
either Defender cloud security posture management (Defender CSPM)CSPM or Defender for Servers Plan 2,2, select Settings.
:::::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png" alt-text="Screenshot of the settings link for the settings of the Defender plans forin an AWS accounts.account." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png":::
When you enable agentless scanning on either plan, the setting applies to both plans.In the settings pane, turnTurn on Agentless scanning for machines.
:::::image type="content" source="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png" alt-text="Screenshot of the agentless scanning statussetting for an AWS accounts.account." lightbox="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png":::
UsingCreate the downloaded CloudFormation template, create the stack in AWS as instructed on screen. by following the on-screen instructions.aan AWS management account, you need to rundeploy the CloudFormation template as both as Stacka stack and asa StackSet. Connectors will be created for the member accounts up to 24 hours after the onboarding.
.Select, and then select Update.
After you enable agentless scanning, softwareMember-account connectors can take up to 24 hours to be created. Software inventory and vulnerability information are updatedupdate automatically in Defender for Cloud.after scanning begins.
Enable agentless scanning on GCP
on Google Cloud Platform (GCP):for a GCP project or organization:
selectopen Environment settings.
either Defender cloud security posture management (Defender CSPM)CSPM or Defender for Servers Plan 2,2, select Settings.
:::::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-plan.png" alt-text="Screenshot that shows where to select theof selecting a Defender plan for a GCP projects.project." lightbox="media/enable-agentless-scanning-vms/gcp-select-plan.png":::
:::::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-agentless.png" alt-text="Screenshot that shows where to selectof the agentless scanning.scanning setting for a GCP project." lightbox="media/enable-agentless-scanning-vms/gcp-select-agentless.png":::
the onboarding script.Runand run the onboarding script inat the intended GCP organization/organization or project scope (GCP portal or gcloud CLI).scope.
.Select, and then select Update.
Next stepTroubleshoot missing or incomplete results[!div class="nextstepaction"]
Agentless scanning runs once every 24 hours. After enabling scanning or changing permissions, allow up to 24 hours before troubleshooting missing results.No machines are scanned
Done Action Guidance ☐ Check the plan Confirm that Defender CSPM or Defender for Servers Plan 2 is enabled. ☐ Check the setting In Environment settings, turn on Agentless scanning for machines. ☐ Check the connection Confirm that the Azure subscription, AWS account, or GCP project or organization is connected to Defender for Cloud. ☐ Check connector permissions Confirm that the cloud connector setup completed successfully and includes the required permissions. ☐ Wait for a scan cycle Keep the machines running and allow up to 24 hours for results. Some Azure VMs aren't scanned
Done Action Guidance ☐ Check the power state Confirm that each affected VM was running during a scheduled scan cycle. ☐ Count attached disks VMs with more than 14 disks aren't supported. ☐ Calculate total disk size Add the provisioned size of the operating system disk and all data disks. If the total exceeds 4 TB, only an operating system disk smaller than 4 TB can be scanned. ☐ Check disk types A VM isn't scanned if any disk uses UltraSSD_LRS, PremiumV2_LRS, or an AKS ephemeral OS disk.☐ Check the resource and storage format Databricks VMs and the listed unsupported file systems, RAID formats, and integrity mechanisms aren't scanned. ☐ Check encryption permissions For disks encrypted with customer-managed keys, verify the required Key Vault permissions. Only the Azure VM operating system disk is scanned
Done Action Guidance ☐ Calculate total disk size Add the provisioned size of the operating system disk and all data disks. ☐ Confirm the expected coverage If the total exceeds 4 TB, only the operating system disk is scanned, and only when that disk is less than 4 TB. ☐ Address the remaining coverage Document the data disks as outside agentless coverage and apply your organization's approved protection method. Don't reconfigure production disks solely to meet the scanning limit. Azure VMs with customer-managed-key encrypted disks aren't scanned
Done Action Guidance ☐ Find the encryption key Identify the Key Vault that contains the key used to encrypt the disks. ☐ Find the scanner identity Locate Microsoft Defender for Cloud Servers Scanner Resource Provider with application ID 0c7668b5-3260-4ad0-9f53-34ed54fa19b2.☐ Grant access-policy permissions For a key vault that uses access policies, grant Get, Wrap Key, and Unwrap Key. ☐ Grant Azure RBAC permissions For a key vault that uses Azure RBAC, assign the Key Vault Crypto Service Encryption User role. ☐ Wait for a scan cycle Allow up to 24 hours for the next scheduled scan. AWS machines aren't scanned
Done Action Guidance ☐ Check the connection Confirm that the AWS account appears as connected in Environment settings. ☐ Check the setting Confirm that agentless scanning is turned on under Defender CSPM or Defender for Servers Plan 2. ☐ Update connector permissions Deploy the latest CloudFormation template and confirm that the deployment succeeds. ☐ Check management-account deployment For an AWS management account, deploy the template as both a stack and a StackSet. ☐ Wait for member connectors Allow up to 24 hours for member-account connectors to be created. ☐ Check the AMI AMIs that require third-party licensing, including applicable AWS Marketplace images, aren't supported. GCP machines aren't scanned
Done Action Guidance ☐ Check the connection Confirm that the GCP project or organization appears as connected in Environment settings. ☐ Check the setting Confirm that agentless scanning is turned on under Defender CSPM or Defender for Servers Plan 2. ☐ Update connector permissions Run the current onboarding script at the intended GCP project or organization scope. ☐ Check the organization policy Confirm that the policy for Compute Engine disks, images, and snapshots doesn't block Defender for Cloud. ☐ Resolve a policy block Follow Resolve an agentless scan error for GCP to update the organization policy. ☐ Wait for a scan cycle Allow up to 24 hours for the next scheduled scan. Results are missing or outdated for stopped machines
Done Action Guidance ☐ Start the machine Agentless scanning scans only machines that are running during the scheduled scan. ☐ Wait for updated results Keep the machine running and allow up to 24 hours for results to update. Malware scan has partial coverage
Done Action Guidance ☐ Check compressed package size A package larger than 1 GB can result in partial VM coverage. ☐ Check the number of files in packages A compressed package containing more than 10,000 files can result in partial coverage. ☐ Check nested archives More than five nested archive levels can result in partial coverage. ☐ Estimate the total eligible file count Use approximately 300,000 files for Windows and 500,000 files for Linux as planning targets, not enforced limits. ☐ Review file-change volume Creating or modifying approximately 200,000 files or more between scans can increase the risk of partial coverage. ☐ Check file accessibility Empty, inaccessible, unavailable, system, offline, operating-system-level compressed, or reparse-point files might not be scanned. ☐ Improve package coverage Where operationally appropriate, reduce large file collections and extract or split packages that exceed the compressed-package thresholds. ☐ Review available detections Partial coverage doesn't discard detections from content that was scanned successfully. Malware alerts don't appear
Done Action Guidance ☐ Check the plan Defender for Servers Plan 2 is required. Defender CSPM alone doesn't include malware scanning. ☐ Check scanning eligibility Confirm that agentless scanning is on and that the machine meets the support requirements. ☐ Check other results Verify whether software inventory or vulnerability results appear for the machine. ☐ Run a validation test Malware alerts appear only when a threat is detected. Follow Test agentless malware scanning to validate the feature. Related content
@@ -1,9 +1,9 @@ --- title: Enable agentless machine scanning-description: Run agentless scanning on Virtual Machines (VMs) for vulnerabilities and threats in Microsoft Defender for Cloud.+description: Learn what agentless scanning covers, review supported Azure, AWS, and GCP machines, and enable scanning in Microsoft Defender for Cloud. ms.topic: how-to-ms.date: 06/02/2026-ms.custom: sfi-image-nochange+ms.date: 08/24/2026+ms.custom: sfi-image-nochange, msecd-doc-authoring-1013 #customer intent: As a security administrator, I want to enable agentless scanning for VMs so that I can identify vulnerabilities and threats without impacting performance. ai-usage: ai-assisted@@ -11,111 +11,374 @@ ai-usage: ai-assisted # Enable agentless machine scanning -Agentless machine scanning helps you discover vulnerabilities, secrets, malware signals, and software inventory across cloud machines without deploying endpoint agents. In Microsoft Defender for Cloud, this capability runs through your cloud connectors so security teams can scale coverage with low operational overhead and minimal performance impact. This article explains how to enable and manage scanning across Azure, AWS, and GCP environments so you can onboard protection quickly and start investigating findings. If your environment has plan or permission dependencies, review prerequisites before you begin.+Agentless machine scanning helps you discover vulnerabilities, secrets, malware signals, and software inventory across cloud machines without deploying endpoint agents. In Microsoft Defender for Cloud, this capability runs through your cloud connectors so security teams can scale coverage with low operational overhead and minimal performance impact. -## Overview+This article explains the supported environments, important coverage limitations, and how to enable and manage scanning across Azure, AWS, and GCP. -[Agentless machine scanning](concept-agentless-data-collection.md) in Microsoft Defender for Cloud improves the security posture of machines connected to Defender for Cloud. Agentless machine scanning includes capabilities such as scanning for software inventory, vulnerabilities, secrets, and malware.+> [!IMPORTANT]+> Review the [supported machines and scan coverage](#supported-machines-and-scan-coverage), followed by the [limitations and unsupported configurations](#limitations-and-unsupported-configurations), before enabling the feature. -- Agentless scanning doesn't require installed agents or network connectivity, and it doesn't affect machine performance.-- You can turn agentless machine scanning on or off, but you can't disable individual capabilities.-- Scans only run on VMs that are running. VMs that are off during a scan aren't scanned.-- The scan runs on a nonconfigurable schedule once every 24 hours.+Agentless scanning runs once every 24 hours on a nonconfigurable schedule. -When you turn on Defender for Servers Plan 2 or Defender cloud security posture management (Defender CSPM), agentless machine scanning is enabled by default. If needed, use the procedures in this article to enable agentless machine scanning manually.+## What agentless scanning covers -## Prerequisites+The following table shows what each capability provides and which plans include it. -|**Requirement** | **Details**|-|--- | ---|-|**Plan** | To use agentless scanning, the [Defender cloud security posture management (Defender CSPM)](concept-cloud-security-posture-management.md) plan or [Defender for Servers Plan 2](defender-for-servers-introduction.md) must be enabled.<br/><br/> When you enable agentless scanning on either plan, the setting is enabled for both plans.|-|**Malware scanning** | Malware scanning is only available when Defender for Servers Plan 2 is enabled.<br/><br/> For malware scanning of Kubernetes node VMs, either Defender for Servers Plan 2 or the Defender for Containers plan is required.|-| **Supported machines** | You can scan Azure virtual machines (VMs), Amazon Web Services (AWS) Elastic Compute Cloud (EC2) instances, and Google Cloud Platform (GCP) compute instances without installing an agent, if they're connected to [Microsoft Defender for Cloud](/azure/defender-for-cloud/). |-|**Azure VMs** | Agentless scanning is available on Azure standard VMs with:<br/><br/>- Maximum total disk size of 4 TB (sum of all disks). If this limit is exceeded, only the OS disk is scanned when the OS disk is less than 4 TB.<br/>- Maximum number of disks allowed: 14<br/>- Virtual machine scale set - Flex<br/><br/> Support for disks that are:<br/> - Unencrypted<br/> - Encrypted (managed disks using Azure Storage encryption with platform-managed keys (PMK))<br/>- Encrypted with customer-managed keys.|-|**AWS** | Agentless scanning is available on EC2, Auto Scale instances, and disks that are unencrypted, encrypted (PMK), and encrypted (CMK). AMIs requiring third-party licensing, for example from AWS Marketplace, are not supported.|-|**GCP** | Agentless scanning is available on compute instances, instance groups (managed and unmanaged), with Google-managed encryption keys, and customer-managed encryption key (CMEK)|-|**Kubernetes nodes** | Agentless scanning for vulnerabilities and malware in Kubernetes node VMs is available.<br/><br/> For [vulnerability assessment](kubernetes-nodes-va.md), Defender for Servers Plan 2, the Defender for Containers plan, or the Defender cloud security posture management (Defender CSPM) plan is required.<br/><br/> For [malware scanning](kubernetes-nodes-malware.md), Defender for Servers Plan 2 or Defender for Containers is required.|-|**Permissions** | [Review the permissions](concept-agentless-data-collection.md#permissions-used-by-agentless-scanning) used by Defender for Cloud for agentless scanning.|-|**Unsupported** | Disk type - If any of the VM's disks are on this list, the VM isn't scanned: <br> - UltraSSD_LRS <br> - PremiumV2_LRS <br> - Azure Kubernetes Service (AKS) Ephemeral OS Disks <br> <br> Resource type: <br> - Databricks VM <br> <br> File systems: <br> - UFS (Unix File System) <br> - ReFS (Resilient File System) <br> - ZFS (ZFS Member) <br> <br> RAID and Block storage formats: <br> - OracleASM (Oracle Automatic Storage Management) <br> - DRBD (Distributed Replicated Block Device) <br> - Linux_Raid_Member <br> <br> Integrity mechanisms: <br> - DM_Verity_Hash <br> - Swap|+| Capability | What it provides | Defender CSPM | Defender for Servers Plan 2 |+| --- | --- | :---: | :---: |+| Software inventory | Lists software found on supported machine disks. | Yes | Yes |+| Vulnerability assessment | Identifies known vulnerabilities associated with the discovered software. | Yes | Yes |+| Secrets scanning | Finds plaintext secrets stored on supported machine disks. | Yes | Yes |+| Malware scanning | Detects malicious files and generates security alerts for detected threats. Review [Malware scanning coverage and limitations](#malware-scanning-coverage-and-limitations). | No | Yes | -## Enable agentless scanning on Azure+Agentless scanning has one setting for each connected environment, such as an Azure subscription, AWS account, or GCP project. The plans enabled for that environment determine which agentless capabilities are available. Individual agentless capabilities can't be turned on or off separately. -To enable agentless scanning on Azure:+> [!NOTE]+> Malware scanning of Kubernetes node VMs requires Defender for Servers Plan 2 or Defender for Containers. This capability is available in commercial clouds only.++## Supported machines and scan coverage++### Scan timing and machine state++| Condition | Coverage |+| --- | --- |+| The machine is running during its scheduled scan | The machine is eligible to be scanned. |+| The machine is stopped or deallocated during its scheduled scan | The machine isn't scanned during that cycle. Results can remain missing or outdated until the machine is running during a later scheduled cycle. |+| Agentless scanning was just enabled or connector permissions were updated | Allow up to 24 hours for the next scheduled scan before troubleshooting missing results. |++### Azure VM requirements++Agentless scanning supports Azure standard VMs and virtual machine scale sets that use flexible orchestration, subject to these limits:++| Requirement | Supported coverage |+| --- | --- |+| Combined size of the operating system disk and all data disks is 4 TB or less | The operating system disk and supported data disks can be scanned. |+| Combined size of the operating system disk and all data disks exceeds 4 TB | Only the operating system disk is scanned, and only when that disk is less than 4 TB. Data disks aren't scanned. |+| The VM has 14 disks or fewer | The VM is within the supported disk-count limit. VMs with more than 14 disks aren't supported. |+| Disks use platform-managed keys | Supported. |+| Managed disks use customer-managed keys | Supported after you grant the additional Key Vault permissions described in [Azure VMs with customer-managed keys](#azure-vms-with-customer-managed-keys). |++> [!CAUTION]+> For an Azure VM whose combined disk size exceeds 4 TB, agentless findings cover only the operating system disk when that disk is less than 4 TB.++### AWS requirements++Agentless scanning supports:++- Amazon EC2 instances and instances in Auto Scaling groups.+- Unencrypted disks.+- Disks encrypted with platform-managed or customer-managed keys.++Amazon Machine Images (AMIs) that require third-party licensing, including applicable AWS Marketplace images, aren't supported.++### GCP requirements++Agentless scanning supports Compute Engine instances and instance groups, both managed and unmanaged, with Google-managed encryption keys or customer-managed encryption keys (CMEK).++GCP organization policies can prevent Defender for Cloud from creating or accessing the snapshots required for scanning. If no results appear within 24 hours, review [Resolve an agentless scan error for GCP](resolve-disk-scanning-error.md).++## Malware scanning coverage and limitations++Agentless malware scanning provides periodic, point-in-time visibility rather than continuous or real-time protection. The amount and type of content on a VM can affect scan coverage.++### Compressed package limits++A malware scan can complete with partial VM coverage when a compressed package meets any of these conditions:++| Condition | Partial-coverage threshold |+| --- | ---: |+| Compressed package size | Larger than 1 GB |+| Files in a compressed package | More than 10,000 files |+| Nested archive depth | More than five archive levels |++### File-count planning targets++For a lower risk of partial coverage, use these planning targets for the total number of files eligible for malware scanning across the VM:++| Operating system | Planning target |+| --- | ---: |+| Windows | Up to approximately 300,000 files |+| Linux | Up to approximately 500,000 files |++Workloads that create or modify approximately 200,000 files or more between scans can also have an increased risk of partial coverage.++> [!IMPORTANT]+> These file-count targets are planning guidance. They aren't service-enforced limits and don't guarantee complete coverage.++### Files that might not be scanned++The following files might not be scanned:++- Empty files.+- Files that are inaccessible or no longer available at scan time.+- Files with unsupported operating-system attributes, including system, offline, operating-system-level compressed, or reparse-point files.++### What partial coverage means++Partial coverage doesn't discard the scan results. Detections from content that was successfully scanned are still reported.++To improve coverage:++- Reduce large file collections where operationally appropriate.+- Extract or split compressed packages that exceed the package thresholds.+- Make sure important files are accessible at scan time.++## Limitations and unsupported configurations++Agentless scanning doesn't support the following configurations.++| Category | Unsupported configuration | Coverage consequence |+| --- | --- | --- |+| Azure disk type | `UltraSSD_LRS`, `PremiumV2_LRS`, or Azure Kubernetes Service (AKS) ephemeral OS disks | If any disk attached to the VM uses one of these disk types, the VM isn't scanned. |+| Resource type | Databricks VMs | The VM isn't supported for agentless scanning. |+| File system | UFS (Unix File System), ReFS (Resilient File System), or ZFS (ZFS Member) | If any disk uses one of these file systems, the VM isn't scanned. |+| RAID or block-storage format | OracleASM (Oracle Automatic Storage Management), DRBD (Distributed Replicated Block Device), or `Linux_Raid_Member` | If any disk uses one of these formats, the VM isn't scanned. |+| Integrity mechanism or partition | `DM_Verity_Hash` or swap | If any disk contains one of these configurations, the VM isn't scanned. |++> [!NOTE]+> After enabling agentless scanning, verify that results appear for the machines you expect. The setting status alone doesn't confirm that every machine meets the support requirements.++## Before you begin++Verify the following requirements:++- **Plan:** Agentless scanning requires Defender CSPM or Defender for Servers Plan 2. Agentless malware scanning is available only with Defender for Servers Plan 2.+- **Connected environment:** The Azure subscription, AWS account, or GCP project or organization must be connected to Microsoft Defender for Cloud.+- **Machine support:** Confirm that the machine and its disks meet the requirements in [Supported machines and scan coverage](#supported-machines-and-scan-coverage) and aren't listed under [Limitations and unsupported configurations](#limitations-and-unsupported-configurations).+- **Permissions:** Review the [permissions used by agentless scanning](concept-agentless-data-collection.md#permissions-used-by-agentless-scanning).+- **Customer-managed encryption:** For Azure disks encrypted with customer-managed keys, grant the additional Key Vault permissions described in [Azure VMs with customer-managed keys](#azure-vms-with-customer-managed-keys). AWS and GCP connector setup includes the required permissions for their key-management services.++## Enable agentless scanning++Use the rollout guidance in this section, and then follow the procedure for each cloud environment.++### Plan your rollout++A phased rollout helps you confirm permissions, identify unsupported machines, and establish a repeatable process before enabling agentless scanning across a large environment.++#### Benefits of a phased rollout++- **Find coverage gaps early:** Identify machines that exceed disk limits or use unsupported configurations before broad deployment.+- **Validate permissions:** Confirm that disk snapshots and customer-managed encryption keys can be accessed as expected.+- **Set clear expectations:** Verify which inventory, vulnerability, secrets, and malware results should appear for each enabled plan.+- **Reduce repeated work:** Use the validated connector and permission configuration as the pattern for additional environments.++#### Guidelines for a successful rollout++| Guideline | Recommended approach |+| --- | --- |+| Choose a representative test environment | Include common machine types and any customer-managed encryption, large disks, multiple data disks, or scale sets used in your organization. |+| Review support before enabling | Check disk size, disk count, disk type, file system, encryption, and machine power-state requirements. Record machines that aren't supported. |+| Assess malware content scale | For malware scanning, compare file counts, file-change volume, and compressed packages with the [coverage guidance](#malware-scanning-coverage-and-limitations). |+| Define the expected results | Decide which software inventory, vulnerability, secrets, or malware results you expect based on the plan enabled for the environment. |+| Allow for the scan schedule | Wait up to 24 hours after enablement or permission changes before assessing the results. |+| Verify results, not only the setting | Confirm that results appear for the expected test machines. An enabled setting alone doesn't confirm successful coverage. |+| Resolve exceptions before expanding | Correct missing permissions or connector configuration. Document machines that remain outside the supported configuration. |+| Roll out in manageable groups | Enable additional Azure subscriptions, AWS accounts, or GCP projects in batches and verify each batch before continuing. |++#### Recommended rollout sequence++1. Select a representative Azure subscription, AWS account, or GCP project.++1. Review its machines against the supported coverage and limitation tables on this page.++1. If malware scanning is required, review the file-count and compressed-package guidance.++1. Confirm that the required plan, connector, and encryption permissions are in place.++1. Define which results you expect to see for the test machines.++1. Enable agentless scanning and allow up to 24 hours for the scheduled scan.++1. Verify that software inventory or vulnerability results appear. To validate malware scanning, follow [Test agentless malware scanning](test-agentless-malware-scanning.md).++1. Resolve permission, connector, or support issues.++1. Repeat the process for the next group of subscriptions, accounts, or projects.++### Azure++To enable agentless scanning for an Azure subscription:++> [!IMPORTANT]+> If any Azure VM disks use customer-managed keys, also complete [Azure VMs with customer-managed keys](#azure-vms-with-customer-managed-keys). 1. In Defender for Cloud, open **Environment settings**.+ 1. Select the relevant subscription.-1. For either the Defender CSPM plan, or Defender for Servers Plan 2, select **Settings**. - :::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png" alt-text="Screenshot of link for the settings of the Defender plans for Azure accounts." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png":::+1. For **Defender CSPM** or **Defender for Servers Plan 2**, select **Settings**.++ :::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png" alt-text="Screenshot of the settings link for Defender plans in an Azure subscription." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-azure.png"::: -1. In Settings and monitoring, turn on **Agentless scanning for machines**.+1. In **Settings and monitoring**, turn on **Agentless scanning for machines**. - :::image type="content" source="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png" alt-text="Screenshot of settings and monitoring screen to turn on agentless scanning." lightbox="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png":::+ :::image type="content" source="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png" alt-text="Screenshot of the setting used to turn on agentless scanning for Azure machines." lightbox="media/enable-vulnerability-assessment-agentless/turn-on-agentless-scanning-azure.png"::: 1. Select **Save**. -## Enable for Azure VMs with CMK encrypted disks+Allow up to 24 hours for the next scheduled scan. If results don't appear, use the [troubleshooting checklist](#troubleshoot-missing-or-incomplete-results). -To enable agentless scanning for Azure VMs with customer-managed key (CMK) encrypted disks:+### Azure VMs with customer-managed keys -For agentless scanning of Azure VMs with CMK encrypted disks, you need to grant Defender for Cloud extra permissions on Key Vaults used for CMK encryption for the VMs, to create a secure copy of the disks.+Azure VMs with disks encrypted by customer-managed keys require additional Key Vault permissions. These permissions allow Defender for Cloud to create and examine a secure copy of the encrypted disk. -1. To manually assign the permissions on a Key Vault:+Assign permissions to **Microsoft Defender for Cloud Servers Scanner Resource Provider** with application ID `0c7668b5-3260-4ad0-9f53-34ed54fa19b2`. - - **Key vaults with non-RBAC permissions**: Assign "Microsoft Defender for Cloud Servers Scanner Resource Provider" (`0c7668b5-3260-4ad0-9f53-34ed54fa19b2`) these permissions: Key Get, Key Wrap, Key Unwrap.- - **Key vaults using RBAC permissions**: Assign "Microsoft Defender for Cloud Servers Scanner Resource Provider” (`0c7668b5-3260-4ad0-9f53-34ed54fa19b2`) the [Key Vault Crypto Service Encryption User](/azure/key-vault/general/rbac-guide?preserve-view=true&tabs=azure-cli#azure-built-in-roles-for-key-vault-data-plane-operations) built-in role.+- **For a key vault that uses access policies:** Grant **Get**, **Wrap Key**, and **Unwrap Key** permissions.+- **For a key vault that uses Azure role-based access control (RBAC):** Assign the [**Key Vault Crypto Service Encryption User**](/azure/key-vault/general/rbac-guide?preserve-view=true&tabs=azure-cli#azure-built-in-roles-for-key-vault-data-plane-operations) built-in role. -1. To assign these permissions at scale for multiple Key Vaults, use [this script](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Powershell%20scripts/Agentless%20Scanning%20CMK%20support).+To assign these permissions across multiple Key Vaults, use the [agentless scanning CMK support script](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Powershell%20scripts/Agentless%20Scanning%20CMK%20support). -## Enable agentless scanning on AWS+### AWS -To enable agentless scanning on AWS:+To enable agentless scanning for an AWS account: 1. In Defender for Cloud, open **Environment settings**.-1. Select the relevant account.-1. For either Defender cloud security posture management (Defender CSPM) or Defender for Servers Plan 2, select **Settings**. - :::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png" alt-text="Screenshot of link for the settings of the Defender plans for AWS accounts." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png":::+1. Select the relevant AWS account. - When you enable agentless scanning on either plan, the setting applies to both plans.+1. For **Defender CSPM** or **Defender for Servers Plan 2**, select **Settings**. -1. In the settings pane, turn on **Agentless scanning for machines**.+ :::image type="content" source="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png" alt-text="Screenshot of the settings link for Defender plans in an AWS account." lightbox="media/enable-vulnerability-assessment-agentless/defender-plan-settings-aws.png"::: - :::image type="content" source="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png" alt-text="Screenshot of the agentless scanning status for AWS accounts." lightbox="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png":::+1. Turn on **Agentless scanning for machines**.++ :::image type="content" source="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png" alt-text="Screenshot of the agentless scanning setting for an AWS account." lightbox="media/enable-vulnerability-assessment-agentless/agentless-scan-on-aws.png"::: 1. Select **Save and Next: Configure Access**. 1. Download the CloudFormation template. -1. Using the downloaded CloudFormation template, create the stack in AWS as instructed on screen. If you're onboarding a management account, you need to run the CloudFormation template both as Stack and as StackSet. Connectors will be created for the member accounts up to 24 hours after the onboarding.+1. Create the CloudFormation stack in AWS by following the on-screen instructions.++1. If you're onboarding an AWS management account, deploy the template as both a stack and a StackSet. -1. Select **Next: Review and generate**.+1. Select **Next: Review and generate**, and then select **Update**. -1. Select **Update**.+Member-account connectors can take up to 24 hours to be created. Software inventory and vulnerability information update automatically after scanning begins. -After you enable agentless scanning, software inventory and vulnerability information are updated automatically in Defender for Cloud.+### GCP -## Enable agentless scanning on GCP+To enable agentless scanning for a GCP project or organization:++1. In Defender for Cloud, open **Environment settings**. -To enable agentless scanning on Google Cloud Platform (GCP):+1. Select the relevant GCP project or organization. -1. In Defender for Cloud, select **Environment settings**.-1. Select the relevant project or organization.-1. For either Defender cloud security posture management (Defender CSPM) or Defender for Servers Plan 2, select **Settings**.+1. For **Defender CSPM** or **Defender for Servers Plan 2**, select **Settings**. - :::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-plan.png" alt-text="Screenshot that shows where to select the plan for GCP projects." lightbox="media/enable-agentless-scanning-vms/gcp-select-plan.png":::+ :::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-plan.png" alt-text="Screenshot of selecting a Defender plan for a GCP project." lightbox="media/enable-agentless-scanning-vms/gcp-select-plan.png"::: -1. Set Agentless scanning to **On**.+1. Set **Agentless scanning** to **On**. - :::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-agentless.png" alt-text="Screenshot that shows where to select agentless scanning." lightbox="media/enable-agentless-scanning-vms/gcp-select-agentless.png":::+ :::image type="content" source="media/enable-agentless-scanning-vms/gcp-select-agentless.png" alt-text="Screenshot of the agentless scanning setting for a GCP project." lightbox="media/enable-agentless-scanning-vms/gcp-select-agentless.png"::: 1. Select **Save and Next: Configure Access**.-1. Copy the onboarding script.-1. Run the onboarding script in the GCP organization/project scope (GCP portal or gcloud CLI).-1. Select **Next: Review and generate**.-1. Select **Update**. -## Next step+1. Copy and run the onboarding script at the intended GCP organization or project scope. -> [!div class="nextstepaction"]-> [Review agentless scanning support and permissions](concept-agentless-data-collection.md)+1. Select **Next: Review and generate**, and then select **Update**.++Allow up to 24 hours for the next scheduled scan. If results don't appear, check whether a GCP organization policy is restricting disk, image, or snapshot access.++## Troubleshoot missing or incomplete results++Agentless scanning runs once every 24 hours. After enabling scanning or changing permissions, allow up to 24 hours before troubleshooting missing results.++### No machines are scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check the plan | Confirm that Defender CSPM or Defender for Servers Plan 2 is enabled. |+| ☐ | Check the setting | In **Environment settings**, turn on **Agentless scanning for machines**. |+| ☐ | Check the connection | Confirm that the Azure subscription, AWS account, or GCP project or organization is connected to Defender for Cloud. |+| ☐ | Check connector permissions | Confirm that the cloud connector setup completed successfully and includes the required permissions. |+| ☐ | Wait for a scan cycle | Keep the machines running and allow up to 24 hours for results. |++### Some Azure VMs aren't scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check the power state | Confirm that each affected VM was running during a scheduled scan cycle. |+| ☐ | Count attached disks | VMs with more than 14 disks aren't supported. |+| ☐ | Calculate total disk size | Add the provisioned size of the operating system disk and all data disks. If the total exceeds 4 TB, only an operating system disk smaller than 4 TB can be scanned. |+| ☐ | Check disk types | A VM isn't scanned if any disk uses `UltraSSD_LRS`, `PremiumV2_LRS`, or an AKS ephemeral OS disk. |+| ☐ | Check the resource and storage format | Databricks VMs and the listed unsupported file systems, RAID formats, and integrity mechanisms aren't scanned. |+| ☐ | Check encryption permissions | For disks encrypted with customer-managed keys, verify the required Key Vault permissions. |++### Only the Azure VM operating system disk is scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Calculate total disk size | Add the provisioned size of the operating system disk and all data disks. |+| ☐ | Confirm the expected coverage | If the total exceeds 4 TB, only the operating system disk is scanned, and only when that disk is less than 4 TB. |+| ☐ | Address the remaining coverage | Document the data disks as outside agentless coverage and apply your organization's approved protection method. Don't reconfigure production disks solely to meet the scanning limit. |++### Azure VMs with customer-managed-key encrypted disks aren't scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Find the encryption key | Identify the Key Vault that contains the key used to encrypt the disks. |+| ☐ | Find the scanner identity | Locate **Microsoft Defender for Cloud Servers Scanner Resource Provider** with application ID `0c7668b5-3260-4ad0-9f53-34ed54fa19b2`. |+| ☐ | Grant access-policy permissions | For a key vault that uses access policies, grant **Get**, **Wrap Key**, and **Unwrap Key**. |+| ☐ | Grant Azure RBAC permissions | For a key vault that uses Azure RBAC, assign the **Key Vault Crypto Service Encryption User** role. |+| ☐ | Wait for a scan cycle | Allow up to 24 hours for the next scheduled scan. |++### AWS machines aren't scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check the connection | Confirm that the AWS account appears as connected in **Environment settings**. |+| ☐ | Check the setting | Confirm that agentless scanning is turned on under Defender CSPM or Defender for Servers Plan 2. |+| ☐ | Update connector permissions | Deploy the latest CloudFormation template and confirm that the deployment succeeds. |+| ☐ | Check management-account deployment | For an AWS management account, deploy the template as both a stack and a StackSet. |+| ☐ | Wait for member connectors | Allow up to 24 hours for member-account connectors to be created. |+| ☐ | Check the AMI | AMIs that require third-party licensing, including applicable AWS Marketplace images, aren't supported. |++### GCP machines aren't scanned++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check the connection | Confirm that the GCP project or organization appears as connected in **Environment settings**. |+| ☐ | Check the setting | Confirm that agentless scanning is turned on under Defender CSPM or Defender for Servers Plan 2. |+| ☐ | Update connector permissions | Run the current onboarding script at the intended GCP project or organization scope. |+| ☐ | Check the organization policy | Confirm that the policy for Compute Engine disks, images, and snapshots doesn't block Defender for Cloud. |+| ☐ | Resolve a policy block | Follow [Resolve an agentless scan error for GCP](resolve-disk-scanning-error.md) to update the organization policy. |+| ☐ | Wait for a scan cycle | Allow up to 24 hours for the next scheduled scan. |++### Results are missing or outdated for stopped machines++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Start the machine | Agentless scanning scans only machines that are running during the scheduled scan. |+| ☐ | Wait for updated results | Keep the machine running and allow up to 24 hours for results to update. |++### Malware scan has partial coverage++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check compressed package size | A package larger than 1 GB can result in partial VM coverage. |+| ☐ | Check the number of files in packages | A compressed package containing more than 10,000 files can result in partial coverage. |+| ☐ | Check nested archives | More than five nested archive levels can result in partial coverage. |+| ☐ | Estimate the total eligible file count | Use approximately 300,000 files for Windows and 500,000 files for Linux as planning targets, not enforced limits. |+| ☐ | Review file-change volume | Creating or modifying approximately 200,000 files or more between scans can increase the risk of partial coverage. |+| ☐ | Check file accessibility | Empty, inaccessible, unavailable, system, offline, operating-system-level compressed, or reparse-point files might not be scanned. |+| ☐ | Improve package coverage | Where operationally appropriate, reduce large file collections and extract or split packages that exceed the compressed-package thresholds. |+| ☐ | Review available detections | Partial coverage doesn't discard detections from content that was scanned successfully. |++### Malware alerts don't appear++| Done | Action | Guidance |+| :---: | --- | --- |+| ☐ | Check the plan | Defender for Servers Plan 2 is required. Defender CSPM alone doesn't include malware scanning. |+| ☐ | Check scanning eligibility | Confirm that agentless scanning is on and that the machine meets the support requirements. |+| ☐ | Check other results | Verify whether software inventory or vulnerability results appear for the machine. |+| ☐ | Run a validation test | Malware alerts appear only when a threat is detected. Follow [Test agentless malware scanning](test-agentless-malware-scanning.md) to validate the feature. |++## Related content++- [How agentless machine scanning works](concept-agentless-data-collection.md)+- [Agentless malware scanning](agentless-malware-scanning.md)+- [Test agentless malware scanning](test-agentless-malware-scanning.md)+- [Resolve an agentless scan error for GCP](resolve-disk-scanning-error.md)\ No newline at end of file
