last sync: 2022-May-23 16:32:10 UTC

Azure Policy definition

[Preview]: Configure Azure Kubernetes Service clusters to enable Defender profile

Name [Preview]: Configure Azure Kubernetes Service clusters to enable Defender profile
Azure Portal
Id 64def556-fbad-4622-930e-72d1d5589bf5
Version 3.0.3-preview
details on versioning
Category Kubernetes
Microsoft docs
Description Microsoft Defender for Containers provides cloud-native Kubernetes security capabilities including environment hardening, workload protection, and run-time protection. When you enable the SecurityProfile.AzureDefender on your Azure Kubernetes Service cluster, an agent is deployed to your cluster to collect security event data. Learn more about Microsoft Defender for Containers:
Mode Indexed
Type BuiltIn
Preview True
Deprecated FALSE
Effect Default: DeployIfNotExists
Allowed: (DeployIfNotExists, Disabled)
Used RBAC Role
Role Name Role Id
Contributor b24988ac-6180-42a0-ab88-20f7382dd24c
Log Analytics Contributor 92aaf0da-9dab-42b6-94a3-d43ce8d16293
Rule Aliases THEN-ExistenceCondition (1)
Alias Namespace ResourceType DefaultPath Modifiable
Microsoft.ContainerService/managedClusters/securityProfile.azureDefender.enabled Microsoft.ContainerService managedClusters properties.securityProfile.azureDefender.enabled false
Rule ResourceTypes IF (1)
THEN-Deployment (4)
Date/Time (UTC ymd) (i) Change type Change detail
2022-04-01 20:29:14 change Patch, suffix remains equal (3.0.2-preview > 3.0.3-preview)
2022-03-25 18:52:24 change Patch, suffix remains equal (3.0.1-preview > 3.0.2-preview)
2022-03-18 17:53:47 change Major, suffix remains equal (2.0.0-preview > 3.0.1-preview)
2022-03-11 18:16:48 change Major, suffix remains equal (1.1.0-preview > 2.0.0-preview)
2021-11-12 16:23:07 change Minor, suffix remains equal (1.0.0-preview > 1.1.0-preview)
2021-08-23 14:26:16 add 64def556-fbad-4622-930e-72d1d5589bf5
Used in Initiatives none
JSON Changes