Microsoft Defender for Cloud
Cloud and workloads

Resolve VPC service controls issues

In brief

The article now explains that GCP Logs Explorer can identify when VPC Service Controls block Defender for Cloud API calls. It also clarifies that the ingress and egress policy configuration is validated by the next scheduled agentless disk scan, which may take up to 24 hours.

What Defender admins need to know

Administrators can more clearly diagnose blocked API calls and understand when to verify policy configuration; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

To allow Microsoft Defender for Cloud to scan resources within these protected environments, you need to configure ingress and egress policies that allow Defender for Cloud service accounts to operate within the perimeter. This configuration ensures that security scans can be performed without compromising the integrity of the perimeter’s restrictions.

If you're unsure whether your Defender for Cloud account is experiencing issues with VPC Service Controls, you can check your GCP Logs Explorer to find out.determine whether VPC Service Controls are blocking Defender for Cloud API calls.

Prerequisites

  1. Select Save.

Defender for Cloud triggers agentless disk scanning with API calls. You'll know thisthe ingress and egress policy configuration works after the next scheduled scan API call, which can take up to 24 hours.

Next stepsteps

[!div class="nextstepaction"] Microsoft Defender for Cloud troubleshooting guide \ No newline at end of file