Explore risks to pre-deployment generative AI artifacts
In brief
The article now more clearly explains how Defender for Cloud CSPM scans AI artifacts for known library vulnerabilities and how to use Cloud Security Explorer to find affected containers and Azure OpenAI code repositories. It also adds prerequisite guidance and corrects remediation links.
What Defender admins need to know
Administrators get clearer steps and a corrected link for reviewing findings and remediation recommendations.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Explore risks to pre-deployment generative AI artifacts
The Defender Cloud Security Posture Management (CSPM) plan in Microsoft Defender for Cloud helps you to improve the security posture ofsecure your generative AI apps, by identifying vulnerabilities in generativeapps. It scans AI libraries that exist in your AI artifactsartifacts, such as container images and code repositories. This article explains howrepositories, to explore,find known vulnerabilities in AI libraries.
In this article, you use the cloud security explorer in Defender for Cloud to find containers running vulnerable generative AI images and to identify security risks for those applications.vulnerable code repositories that provision Azure OpenAI. After you complete these steps, you can review findings and remediate recommendations.
Prerequisites
Before you begin, make sure you meet the following prerequisites:
Read about AI security posture management.
Learn more about investigating risks with the cloud security explorer and attack paths.
Identify containers running on vulnerable generative AI container images
TheUse the cloud security explorer can be used to identifyfind containers that are runningrun generative AI container images with known vulnerabilities.
Sign in to the Azure portal.
Select Open the vulnerability page.
Identify vulnerable generative AI code repositories
TheUse the cloud security explorer can be used to identifyfind vulnerable generative AI code repositories,repositories that provision Azure OpenAI.
Sign in to the Azure portal.
Select Open the vulnerability page.
Related content
@@ -2,17 +2,22 @@ title: Explore risks to pre-deployment generative AI artifacts description: Learn how to discover potential security risks for your generative AI applications in Microsoft Defender for Cloud. ms.topic: how-to-ms.date: 07/15/2025+ms.date: 07/03/2026+ms.custom: msecd-doc-authoring-1013 # customer intent: As a user, I want to learn how to identify potential security risks for my generative AI applications in Microsoft Defender for Cloud so that I can enhance their security. ai-usage: ai-assisted --- # Explore risks to pre-deployment generative AI artifacts -Defender Cloud Security Posture Management (CSPM) plan in Microsoft Defender for Cloud helps you to improve the security posture of generative AI apps, by identifying vulnerabilities in generative AI libraries that exist in your AI artifacts such as container images and code repositories. This article explains how to explore, identify security risks for those applications.+The Defender Cloud Security Posture Management (CSPM) plan in Microsoft Defender for Cloud helps you secure your generative AI apps. It scans AI artifacts, such as container images and code repositories, to find known vulnerabilities in AI libraries.++In this article, you use the cloud security explorer in Defender for Cloud to find containers running vulnerable generative AI images and to identify vulnerable code repositories that provision Azure OpenAI. After you complete these steps, you can review findings and remediate recommendations. ## Prerequisites +Before you begin, make sure you meet the following prerequisites:+ - Read about [AI security posture management](ai-security-posture.md). - Learn more about [investigating risks with the cloud security explorer and attack paths](concept-attack-path.md).@@ -27,7 +32,7 @@ Defender Cloud Security Posture Management (CSPM) plan in Microsoft Defender for ## Identify containers running on vulnerable generative AI container images -The cloud security explorer can be used to identify containers that are running generative AI container images with known vulnerabilities.+Use the cloud security explorer to find containers that run generative AI images with known vulnerabilities. 1. Sign in to the [Azure portal](https://portal.azure.com/). @@ -51,11 +56,11 @@ The cloud security explorer can be used to identify containers that are running 1. Select **Open the vulnerability page**. -1. [Remediate the recommendation](implement-security-recommendations.md#remediate-recommendations).+1. [Remediate the recommendation](implement-security-recommendations.md#remediate-a-recommendation). ## Identify vulnerable generative AI code repositories -The cloud security explorer can be used to identify vulnerable generative AI code repositories, that provision Azure OpenAI. +Use the cloud security explorer to find vulnerable generative AI code repositories that provision Azure OpenAI. 1. Sign in to the [Azure portal](https://portal.azure.com/). @@ -79,7 +84,7 @@ The cloud security explorer can be used to identify vulnerable generative AI cod 1. Select **Open the vulnerability page**. -1. [Remediate the recommendation](implement-security-recommendations.md#remediate-recommendations).+1. [Remediate the recommendation](implement-security-recommendations.md#remediate-a-recommendation). ## Related content 