last sync: 2024-Jun-13 18:14:14 UTC

Configure machines to receive a vulnerability assessment provider

Azure BuiltIn Policy definition

Source Azure Portal
Display name Configure machines to receive a vulnerability assessment provider
Id 13ce0167-8ca6-4048-8e6b-f996402e3c1b
Version 4.0.0
Details on versioning
Category Security Center
Microsoft Learn
Description Azure Defender includes vulnerability scanning for your machines at no extra cost. You don't need a Qualys license or even a Qualys account - everything's handled seamlessly inside Security Center. When you enable this policy, Azure Defender automatically deploys the Qualys vulnerability assessment provider to all supported machines that don't already have it installed.
Mode Indexed
Type BuiltIn
Preview False
Deprecated False
Effect Default
DeployIfNotExists
Allowed
DeployIfNotExists, Disabled
RBAC role(s)
Role Name Role Id
Security Admin fb1c8493-542b-48eb-b624-b4c8fea62acd
Rule aliases THEN-ExistenceCondition (2)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.Security/assessments/status.cause Microsoft.Security assessments properties.status.cause false
Microsoft.Security/assessments/status.code Microsoft.Security assessments properties.status.code false
Rule resource types IF (2)
Microsoft.Compute/virtualMachines
Microsoft.HybridCompute/machines
THEN-Deployment (2)
Microsoft.compute/virtualmachines
Microsoft.hybridcompute/machines
Compliance
The following 6 compliance controls are associated with this Policy definition 'Configure machines to receive a vulnerability assessment provider' (13ce0167-8ca6-4048-8e6b-f996402e3c1b)
Control Domain Control Name MetadataId Category Title Owner Requirements Description Info Policy#
op.exp.2 Security configuration op.exp.2 Security configuration 404 not found n/a n/a 112
op.exp.3 Security configuration management op.exp.3 Security configuration management 404 not found n/a n/a 123
op.exp.4 Security maintenance and updates op.exp.4 Security maintenance and updates 404 not found n/a n/a 78
op.exp.5 Change management op.exp.5 Change management 404 not found n/a n/a 71
op.exp.6 Protection against harmful code op.exp.6 Protection against harmful code 404 not found n/a n/a 69
op.mon.3 Monitoring op.mon.3 Monitoring 404 not found n/a n/a 51
Initiatives usage
Initiative DisplayName Initiative Id Initiative Category State Type
[Deprecated]: Deploy Microsoft Defender for Cloud configuration Deploy-MDFC-Config Security Center Deprecated ALZ
Deploy Microsoft Defender for Cloud configuration Deploy-MDFC-Config_20240319 Security Center GA ALZ
Spain ENS 175daf90-21e1-4fec-b745-7b4c909aa94c Regulatory Compliance GA BuiltIn
History
Date/Time (UTC ymd) (i) Change type Change detail
2022-05-16 16:31:13 change Major, old suffix: preview (3.1.0-preview > 4.0.0)
2022-05-06 16:29:23 change Minor, suffix remains equal (3.0.0-preview > 3.1.0-preview)
2022-02-04 18:25:37 change Major, suffix remains equal (2.2.0-preview > 3.0.0-preview)
2021-09-13 16:35:32 change Minor, suffix remains equal (2.1.0-preview > 2.2.0-preview)
2021-05-04 14:34:06 change Minor, suffix remains equal (2.0.0-preview > 2.1.0-preview)
2021-03-10 14:52:46 change Major, suffix remains equal (1.0.0-preview > 2.0.0-preview)
2021-03-09 14:37:41 add 13ce0167-8ca6-4048-8e6b-f996402e3c1b
JSON compare
compare mode: version left: version right:
JSON
api-version=2021-06-01
EPAC