Microsoft Defender for Cloud
Cloud and workloads

Operating system misconfigurations

In brief

The article now more clearly describes OS baseline misconfiguration assessment and remediation, updates terminology and links, and adds a “Supported systems and requirements” section heading.

What Defender admins need to know

No administrator action is stated; review the updated guidance when managing security baseline assessments.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Operating system misconfigurations

Microsoft Defender for Cloud provides security recommendations to improve organizational security posture and reduce risk. An important element in risk reduction is to harden machines across your business environment. This article explains how to assess and remediate operating system baseline misconfigurations using the Azure Machine Configuration extension and Defender Vulnerability Management.

Assessment (Azure Machine Configuration extension)

Defender for Cloud assessesuses built-in Azure policy initiatives to assess and enforces best-practiceapply security configurations using built-in Azure policy initiatives.configurations. The Microsoft Cloud Security Benchmark (MCSB)default initiative is Defender for Cloud's default initiative.the Microsoft Cloud Security Benchmark (MCSB).

MCSB includes compute security baselines for Windows and Linux operating systems.

Operating systemThese OS baseline recommendations based on these MCSB compute security baselines aren't included as part of the free security posture features in Defender for Cloud's free foundational security posture capabilities.Cloud.

  • The recommendations are available when Defender for Servers Plan 2 is enabled.
  • When Defender for Servers Plan 2 is enabled, relevant Azure policies are enabled on the subscription:

Assessment (Defender Vulnerability Management)

Microsoft Defender for Cloud integrates natively with Microsoft Defender for Endpoint and Microsoft Defender Vulnerability Management to provideManagement. This integration gives machines with vulnerability protection,protection and endpoint detection and response (EDR) capabilities.features.

As part of that integration,the integration with Defender Vulnerability Management, security baselines assessment is provided by Defender Vulnerability Management.provided.

  • Security baselines assessment uses customized securitycustom baseline profiles.
  • Profiles are basicallyEach profile is a template that consists of device configuration settings,settings and benchmarks against which to compare them.them against.

SupportSupported systems and requirements

The following requirements and limitations apply to security baselines assessment:

  • Assessing devices against the Defender Vulnerability Management security baselines assessment profiles is currently available in public preview.
  • Defender for Servers Plan 2 must be enabled, and the Defender for Endpoint agent must be running on machines you want to assess.