Microsoft Defender for Cloud
Architecture and deployment

Onboard agentless containers for CSPM

In brief

The article now provides clearer onboarding direction for Azure, AWS, and GCP, including its coverage of running containers, registry vulnerabilities, and Kubernetes configuration analysis. It also clarifies AKS trusted access terminology.

What Defender admins need to know

Administrators can use the updated guidance to follow the enablement steps for their cloud environment more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Onboard agentless containers for CSPM

Enable agentless container posture in Defender CSPM to gain visibility into Kubernetes clusters and container images without deploying agents.

Agentless container posture is available for Azure, AWS, and GCP environments. This article walks you through enabling agentless container posture in each supported cloud so you can discover running containers, assess vulnerabilities in container registries, and analyze Kubernetes cluster configurations.

Prerequisites

How to onboard agentless container posture in Defender CSPM

Use the following steps to onboard agentless container posture in Defender CSPM for your cloud environment.

Azure

  1. Sign in to the Azure portal.
  2. Select Update.