Microsoft Defender for Cloud
Cloud and workloads

Review Docker host hardening recommendations

In brief

The article now includes prerequisites and steps for finding and remediating Docker host misconfigurations, along with updated wording and metadata.

What Defender admins need to know

Administrators can use the added prerequisites and remediation steps when reviewing Docker host hardening recommendations.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review Docker host hardening recommendations

The Defender for Servers plan in Microsoft Defender for Cloud identifies unmanaged containers hosted on IaaS Linux VMs, or other Linux machines running Docker containers. Defender for Servers continuously assesses the configuration of these Docker hosts, and compares them with the Center for Internet Security (CIS) Docker Benchmark.

This article explains how to review Docker host hardening recommendations, identify configuration issues, and remediate findings in Defender for Cloud.

  • Defender for Cloud includes the entire ruleset of the CIS Docker Benchmark and alerts you if your containers don't satisfy any of the controls.
  • When itDefender for Servers finds misconfigurations, Defender for Serversit generates security recommendations to address the findings.
  • When vulnerabilities are found, they're grouped inside a single recommendation.

Prerequisites

Before you review Docker host hardening recommendations, make sure the following prerequisites are met:

  • You need Defender for Servers Plan 2 to use this feature.
  • These CIS benchmark checks will not run on AKS-managed instances or Databricks-managed VMs.
  • You need Reader permissions on the workspace to which the host connects.

Identify Docker configuration issues

Use the following steps to find and remediate Docker host misconfigurations in Defender for Cloud.

  1. From Defender for Cloud's menu, open the Recommendations page.

  2. Filter to the recommendation Vulnerabilities in container security configurations should be remediated and select the recommendation.