Microsoft Defender for Cloud
Cloud and workloads

Verify Defender for Containers deployment

In brief

The documentation now specifies that Defender collectors for Arc-enabled clusters and Helm deployments run as a Kubernetes DaemonSet, with a pod scheduled on each node.

What Defender admins need to know

Administrators can use this clarification when verifying Defender deployment across cluster nodes.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Verify Defender for Containers deployment

Verify the Defender DaemonSet (Arc-enabled clusters and Helm)

For Arc-enabled clusters and Helm deployments, the Defender collectors run as a Kubernetes DaemonSet, which ensures a pod is scheduled on each node. You can also verify that the Defender DaemonSet is deployed correctly.correctly:

kubectl get ds -n mdc microsoft-defender-collectors-ds