Microsoft Defender for Cloud
Architecture and deployment

Vulnerability scanning in the Defender for Servers plan in Microsoft Defender for Cloud.

In brief

The article updates its date and authoring metadata, clarifies the Cloud overview and Vulnerabilities > Cloud navigation, improves software inventory and AWS/GCP onboarding links, and labels the BYOL scanning workflow more specifically.

What Defender admins need to know

Administrators get clearer navigation and links when reviewing vulnerability insights and BYOL scanning guidance; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

::: zone pivot="defender-portal"

Vulnerability scanning options in Defender for Servers

Microsoft Defender Vulnerability Management is now under Exposure Management and supports both cloud and device environments. Access vulnerability scanning in the Microsoft Defender portal at Exposure Management > Vulnerability Management > Overview > Cloud.

This centralized experienceThe Cloud overview page provides comprehensive vulnerability insights across your cloud infrastructure, including:

  • Cloud vulnerabilities overview: Key metrics and trends for cloud-specific vulnerabilities
  • Top cloud common vulnerabilities and exposures (CVEs): Most critical vulnerabilities affecting your cloud resources

The Defender for Servers plan in Microsoft Defender for Cloud provides vulnerability scanning for connected machines. You can access this data from the unified Vulnerability Management dashboard under Exposure Management.

For detailed analysis, go to Exposure Management > Vulnerability Management > Vulnerabilities > Cloud. This viewThe Vulnerabilities > Cloud page shows cloud vulnerabilities with enhanced filtering and risk-based prioritization alongside device vulnerabilities.

Key benefits of the integrated Exposure Management approach:

  • Scanning consistency: Use a consistent vulnerability scanner across a range of use cases, in multicloud environments, and different host runtimes.
  • Risk reduction: Discover vulnerabilities and misconfigurations in near real time.
  • Prioritization: Prioritize vulnerabilities based on the threat landscape and detections in your organization.
  • Software inventory: Get information about your Review your software inventory in Defender for Cloud.
  • Premium features: Use Defender Vulnerability Management premium features in Defender for Servers Plan 2, including certificate assessment, baseline assessment, vulnerable application blocking, and more.

Vulnerability scanning with Defender Vulnerability Management is supported for Azure virtual machines (VMs), onboarded AWS machines, and onboarded GCP machines that are connected to Defender for Cloud. It's also supported for on-premises VMs that are onboard on-premises machines as Azure Arc VMs.

For a quick overview of Defender Vulnerability Management, watch this video:

Instead of integrated Defender Vulnerability Management scanning, you can use your own bring your own license (BYOL) vulnerability scanner. Qualys and Rapid7 scanners are supported.

Here's how itBYOL vulnerability scanning works:

  • Supported solutions report vulnerability data to the partner's management platform.
  • Solution platforms provide vulnerability and health monitoring data back to Defender for Cloud. --- | --- No solution | If you don't have an agent-based vulnerability scanning solution enabled on VMs, Defender for Cloud automatically runs agentless scanning with Defender Vulnerability Management. Defender Vulnerability Management integration | If machines run the Defender for Endpoint agent, Defender for Cloud shows a unified vulnerability assessment view with optimized coverage and data freshness.

    - Machines using only one method, agent-based scanning or agentless scanning, show results from that method.
    - Machines using both methods show agent-based results only for better freshness. BYOL solution | If you're using a partner vulnerability assessment solution, Defender for Cloud shows partner results by default. Defender for Cloud shows agentless results for machines that don't have the partner agent installed, or for machines that aren't reporting findings correctly.

    You can change this behavior and always show results from Defender Vulnerability Management. To do this, manually enable vulnerability scanning on a subscription Vulnerability assessment for machines on the Environment settings page in Defender for Cloud.

Premium vulnerability management features