Microsoft Defender for Cloud
Cloud and workloads

Enable File Integrity Monitoring

In brief

The page now clearly describes configuring File Integrity Monitoring in the Azure portal after enabling Defender for Servers Plan 2, using the Defender for Endpoint agent and agentless machine scanning. It also improves links, headings, and disablement instructions.

What Defender admins need to know

Administrators can use the clarified prerequisites and steps when configuring or disabling monitoring; no required configuration change is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

In Defender for Servers Plan 2 in Microsoft Defender for Cloud, the File Integrity Monitoring feature helps to keep enterprise assets and resources secure. It scans and analyzes operating system files, Windows registries, application software, and Linux system files for changes that might indicate an attack.

After you enable Defender for Servers Plan 2, follow the instructions in this articlesteps below to configure File Integrity Monitoring using the Microsoft Defender for Endpoint agent and agentless machine scanning to collect data.

  • You must enable Defender for Servers Plan 2 on your subscription.

  • You must install the Defender for Endpoint agent through the Defender for Servers Defender for Servers extensions on machines you want to monitor.

  • You must connect Non-Azure machines with Azure Arc.

  • Linux machines - The Defender for Endpoint agent is automatically updated if autoprovisioning is turned on for the machines in Defender for Cloud. After the MDE.Linux extension is installed on a Linux machine, the machine attempts to update the agent version each time the Virtual Machine (VM) reboots. You can also update the agent version manually.

Enable File Integrity Monitoring in the Azure portal

File Integrity Monitoring isn't enabled by default. You can enable it in the Microsoft Defender for Cloud portal.

Review enablement status for File Integrity Monitoring

Review the File Integrity Monitoring enablement to ensure it'sthe configuration is correct and all prerequisites are met.

  1. Go to Workload protection > File Integrity Monitoring.

If you disable File Integrity Monitoring, no new events are collected. However, the data collected before the disablement, remains in the Log Analytics workspace, in accordance with the workspace retention policy.

Disable as follows:To disable File Integrity Monitoring, follow these steps:

  1. Sign in to the Azure portal.

Related content