Microsoft Defender for Cloud
Cloud and workloads

Enable Defender for Containers in Microsoft Defender for Cloud

In brief

The article now provides platform-specific enablement guidance for AKS, EKS, GKE, and Azure Arc-enabled Kubernetes, uses clearer link names, and explains how to verify the plan using a subscription or connector.

What Defender admins need to know

Administrators can use the updated instructions and verification steps when enabling Defender for Containers; no required action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Enable Defender for Containers in Microsoft Defender for Cloud

Enable the Microsoft Defender for Containers plan in Microsoft Defender for Cloud to protect your Kubernetes clusters and container workloads. This article walks you through enabling the plan in the Azure portal for Azure Kubernetes Service (AKS), Amazon Elastic Kubernetes Service (EKS), Google Kubernetes Engine (GKE), and Azure Arc-enabled Kubernetes clusters. When you enable the plan, you can configure protection components such as runtime threat detection, vulnerability scanning, and security posture assessments.

Azure Kubernetes Service (AKS)

Before you begin, make sure that:

Enable the Defender for Containers plan

To enable the Defender for Containers plan for your AKS clusters in the Azure portal:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

Enable the Defender for Containers plan

To enable the Defender for Containers plan for your EKS clusters:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

Enable the Defender for Containers plan

To enable the Defender for Containers plan for your GKE clusters:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

Enable the Defender for Containers plan

To enable the Defender for Containers plan for your Azure Arc-enabled Kubernetes clusters:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

Verify the plan is enabled

To confirm that the Defender for Containers plan is enabled and the required components are active:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

  3. Select the subscription.subscription or connector where you enabled Defender for Containers.

  4. Verify that Containers is set to On.