> azure-defender-for-cloud

Expert knowledge for Azure Defender For Cloud development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure Defender For Cloud applications. Not for Azure Security (use azure-security), Azure Sentinel (use azure-sentinel), Azure DDos Protection (use azure-ddos-protection), Azure Firewall (use azure-firewall).

fetch
$curl "https://skillshub.wtf/MicrosoftDocs/Agent-Skills/azure-defender-for-cloud?format=md"
SKILL.mdazure-defender-for-cloud

Azure Defender For Cloud Skill

This skill provides expert guidance for Azure Defender For Cloud. Covers troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. It combines local quick-reference content with remote documentation fetching capabilities.

How to Use This Skill

IMPORTANT for Agent: Use the Category Index below to locate relevant sections. For categories with line ranges (e.g., L35-L120), use read_file with the specified lines. For categories with file links (e.g., [security.md](security.md)), use read_file on the linked reference file

IMPORTANT for Agent: If metadata.generated_at is more than 3 months old, suggest the user pull the latest version from the repository. If mcp_microsoftdocs tools are not available, suggest the user install it: Installation Guide

This skill requires network access to fetch documentation content:

  • Preferred: Use mcp_microsoftdocs:microsoft_docs_fetch with query string from=learn-agent-skill. Returns Markdown.
  • Fallback: Use fetch_webpage with query string from=learn-agent-skill&accept=text/markdown. Returns Markdown.

Category Index

CategoryLinesDescription
TroubleshootingL37-L62Diagnosing and fixing Defender for Cloud issues: alert validation, container/Kubernetes deployment checks, multi-cloud connector errors, SQL/Storage problems, and incident/alert ID references.
Best PracticesL63-L83Best practices for investigating and remediating vulnerabilities, misconfigurations, secrets, and API/endpoint/Kubernetes risks across Defender for Cloud, AKS, registries, and CI/CD.
Decision MakingL84-L101Guidance on choosing Defender for Cloud plans, portals, deployment and migration options, cost estimation/chargeback, DCU optimization, and planning agent/recommendation transitions.
Architecture & Design PatternsL102-L112Architectural guidance for Defender for Servers/Containers: agentless scanning, malware/vuln detection on VMs/Kubernetes, data collection, residency, workspaces, and large-scale deployment.
Limits & QuotasL113-L123Limits, quotas, and prerequisites for Defender for Cloud features: free trials, data ingestion, APIs, DevOps, portal preview, alert export limits, and data collection extension changes.
SecurityL124-L200Security alerts, permissions, and hardening for Defender for Cloud: alert references by resource, RBAC/CIEM setup, data handling, policies, and remediation for SQL, storage, containers, VMs, APIs, and more.
ConfigurationL201-L269How to configure and customize Defender for Cloud features: enable scans and alerts, set policies, exemptions, exports, DevOps/containers/SQL/storage settings, and cross-tenant/security posture options.
Integrations & Coding PatternsL270-L298Integrating Defender for Cloud with CI/CD, SIEM, EDR, ITSM, and third‑party security tools, exporting data via APIs/ARG, and automating alerts, tickets, and vulnerability workflows.
DeploymentL299-L327Deploying and managing Defender for Cloud plans and agents (Containers, SQL, Storage, Servers) across AKS/EKS/GKE and hybrid, including CI/CD, IaC, migration, and support matrices

Troubleshooting

TopicURL
Validate Defender for Cloud alert generation and coveragehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alert-validation
Trigger and validate Defender for APIs alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-apis-validation
Verify Defender for Containers deployment on EKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-aws-verify
Verify Defender for Containers deployment on AKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-azure-verify
Verify Defender for Containers deployment on GKEhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-gcp-verify
Respond to Microsoft Defender for DNS security alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-dns-alerts
Investigate and respond to Defender for Resource Manager alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-resource-manager-usage
Reference deprecated Defender for Cloud alert IDshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/deprecated-alerts
Remediate Defender for Cloud endpoint detection gapshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/endpoint-detection-response-solution-recommendations
Resolve common issues in Endor Labs integrationhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-endor-labs
Use Defender for Cloud incident reference cataloghttps://learn.microsoft.com/en-us/azure/defender-for-cloud/incidents-reference
Resolve agentless disk scan errors for GCP in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/resolve-disk-scanning-error
Fix GCP Domain Restricted Sharing issues for Defender connectorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/resolve-gcp-sharing-policy
Resolve GCP VPC Service Controls issues for Defender scanninghttps://learn.microsoft.com/en-us/azure/defender-for-cloud/resolve-vpc-service-controls-issues
Resolve Sentinel-connected AWS onboarding issues in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sentinel-connected-aws
Troubleshoot AWS and GCP connectors in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshoot-connectors
Troubleshoot Defender for SQL on Machines configurationhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshoot-sql-machines-guide
Troubleshoot Defender for SQL on Machines deployment (gov)https://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshoot-sql-machines-guide-gov
Troubleshoot express and classic SQL vulnerability configurationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshoot-vulnerability-findings
Troubleshoot common Microsoft Defender for Cloud issueshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshooting-guide
Troubleshoot gated deployment issues in Kuberneteshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/troubleshooting-runtime-gated
Interpret and act on Defender for Storage malware scan resultshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/understand-malware-scan-results

Best Practices

TopicURL
Apply agentless vulnerability assessment for containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-vulnerability-assessment-azure
Review OS misconfiguration recommendations against MCSB baselineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/apply-security-baseline
Review CI/CD scan results in Cloud Security Explorerhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-cli-reviewing-results
Investigate API security findings and posture in Defender for APIshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-apis-posture
Remediate system update and patch recommendations in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-periodic-system-updates
Investigate Defender for Endpoint misconfiguration recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/endpoint-detection-misconfiguration
Remediate endpoint detection and response gaps in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/endpoint-detection-response-solution-recommendations
Use Defender VA for AKS node OS and softwarehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/kubernetes-nodes-va
Apply Defender networking recommendations for Azurehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/protect-network-resources
Remediate cloud deployment secrets in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/remediate-cloud-deployment-secrets
Remediate machine secrets findings in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/remediate-server-secrets
Remediate machine vulnerability findings in Defender for Servershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/remediate-vulnerability-findings-vm
Review security annotations on pull requests in GitHub and Azure DevOpshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/review-pull-request-annotations
Prioritize and fix vulnerabilities in AKS containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/view-and-remediate-vulnerabilities-containers
Assess Kubernetes image vulnerabilities using Secure Scorehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/view-and-remediate-vulnerabilities-for-images-secure-score
Remediate registry image vulnerabilities using Secure Scorehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/view-and-remediate-vulnerability-assessment-findings-secure-score
Remediate registry image vulnerabilities in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/view-and-remediate-vulnerability-registry-images

Decision Making

TopicURL
Understand Defender for Servers vulnerability scanning optionshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/auto-deploy-vulnerability-assessment
Choose between Azure and Defender portals for Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/azure-portal-vs-defender-portal-comparison
Allocate Defender for Cloud costs via chargebackhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/chargeback
Select and configure Defender for Cloud plans for GCPhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-google-plans
Estimate Defender for Cloud costs with calculatorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/cost-calculator
Choose Defender for Containers deployment optionshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-deployment-overview
Decide between Defender for Storage classic and new planhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-classic
Migrate from Defender for Storage classic to new planhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-classic-migrate
Use BYOL vulnerability assessment with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-byol-vm
Choose the right Defender for Servers planhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-select-plan
Plan for Defender for Cloud Log Analytics agent retirementhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/prepare-deprecation-log-analytics-mma-agent
Plan for Defender for Cloud Log Analytics agent retirementhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/prepare-deprecation-log-analytics-mma-agent
Optimize Defender for Cloud spend with pre-purchase DCUshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/prepurchase-plan
Plan transition from grouped to individual Defender recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/transition-grouped-individual-recommendations

Architecture & Design Patterns

TopicURL
Use agentless malware scanning for virtual machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-malware-scanning
Understand Defender for Containers security architecturehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-architecture
Detect malware on Kubernetes nodes with Defender for Containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/kubernetes-nodes-malware
Design a Defender for Servers deployment architecturehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers
Understand Defender for Servers data collection designhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-agents
Plan Defender for Servers data residency and workspaceshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-data-workspace
Scale Microsoft Defender for Servers across environmentshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-scale

Limits & Quotas

TopicURL
Use Defender for Servers data ingestion benefit and free quotahttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-ingestion-benefit
Review Defender for APIs deployment prerequisiteshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-apis-prepare
Understand current limitations of Defender portal previewhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-portal/known-limitations
Review support scope and prerequisites for DevOps securityhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/devops-support
Export Defender for Cloud alerts to CSV with limitshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/export-alerts-to-csv
Check and understand Defender for Cloud free trial limitshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/free-trial
Understand Defender data collection extensions and retirementhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/monitoring-components

Security

TopicURL
Understand Defender for Cloud alerts for AI serviceshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-ai-workloads
Understand Defender for Cloud alerts for Azure App Servicehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-app-service
Understand Defender for Cloud alerts for Azure Cosmos DBhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-cosmos-db
Understand Defender for Cloud alerts for Azure DDoS Protectionhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-ddos-protection
Understand Defender for Cloud alerts for Azure Key Vaulthttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-key-vault
Understand Defender for Cloud alerts for Azure network layerhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-network-layer
Understand Defender for Cloud alerts for Azure Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-storage
Understand Defender for Cloud alerts for Azure VM extensionshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-azure-vm-extensions
Understand Defender for Containers and Kubernetes alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-containers
Understand Defender for Cloud alerts for Defender for APIshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-defender-for-apis
Understand Defender for Cloud alerts for DNShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-dns
Understand Defender for Cloud alerts for Linux VMshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-linux-machines
Understand Defender for Cloud alerts for open-source databaseshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-open-source-relational-databases
Navigate Defender for Cloud security alert referenceshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-reference
Understand Defender for Cloud alerts for Resource Managerhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-resource-manager
Understand Defender for Cloud alerts for SQL and Synapsehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-sql-database-and-azure-synapse-analytics
Understand Defender for Cloud alerts for Windows VMshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-windows-machines
Configure container runtime anti-malware policieshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/anti-malware
Assign granular access to AWS and GCP connectorshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/assign-access-to-workload
Understand GCP connector authentication architecture in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/authentication-architecture-google-cloud
Configure binary drift detection and blocking for containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/binary-drift-detection
Manage cloud scopes and unified RBAC in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/cloud-scopes-unified-rbac
Use the AKS security dashboard in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/cluster-security-dashboard
Understand AWS connector authentication architecture in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-authentication-architecture-aws
Use classic configuration to manage SQL vulnerability findingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-vulnerability-findings-classic
Use express configuration to manage SQL vulnerability findingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-vulnerability-findings-express
Permissions required for Defender for Containers on EKS and GKEhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/containers-permissions
Monitor APIs for sensitive data exposurehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-classification
Understand Defender for Cloud data handling and securityhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-security
Configure secure authentication for Defender for Cloud CLIhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-cli-authentication
Enable Microsoft Defender for Azure Cosmos DBhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-databases-enable-cosmos-protections
Explore and investigate Defender for SQL security alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-alerts
Use Defender VA scanner for SQL servers on machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-on-machines-vulnerability-assessment
Interpret Defender for Storage threats and alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-threats-alerts
Configure disable rules for container vulnerability findingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/disable-vulnerability-findings-containers-secure-score
Enable Defender for open-source databases on AWShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-defender-for-databases-aws
Enable Defender for open-source databases on Azurehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-defender-for-databases-azure
Enable CIEM in Microsoft Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-permissions-management
Enable and configure gated deployment for Kubernetes clustershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enablement-guide-runtime-gated
Understand Defender for Cloud permission requirementshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-permissions
Address Defender for Cloud regulatory compliance questionshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/faq-regulatory-compliance
Configure governance rules to enforce Defender remediationhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/governance-rules
Use Purview data sensitivity in Defender alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/information-protection
Apply Defender Kubernetes data plane hardening recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/kubernetes-workload-protections
Configure on-upload malware scanning for Azure Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/on-upload-malware-scanning
Assign Defender for Cloud roles and permissions with Azure RBAChttps://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions
Configure CIEM capabilities in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/permissions-management
Configure roles and permissions for Defender for Servershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/plan-defender-for-servers-roles
Manage Defender for Cloud user and personal datahttps://learn.microsoft.com/en-us/azure/defender-for-cloud/privacy
Use Defender for Cloud AI security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-ai
Apply Defender for Cloud API security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-api
Use Defender for Cloud App Service security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-app-services
Use Defender for Cloud compute security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-compute
Apply Defender for Cloud container security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-container
Use Defender for Cloud data security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-data
Review deprecated Defender for Cloud security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-deprecated
Apply Defender for Cloud DevOps security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-devops
Use Defender for Cloud identity and access recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-identity-access
Use Defender for Cloud IoT security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-iot
Use Defender for Cloud Key Vault security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-keyvault
Use Defender for Cloud networking security recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-networking
Use Defender for Cloud serverless protection recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/recommendations-reference-serverless-protection
Interpret and act on Defender for Cloud recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/review-security-recommendations
Secure Kubernetes deployments with gated container imageshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/runtime-gated-overview
Sign and verify container vulnerability findings artifactshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/secure-container-image
Configure security policies in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/security-policy-concept
Simulate Defender for SQL alerts on machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/simulate-alerts-sql-machines
Review and remediate SQL vulnerability assessment findingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-find
Configure and interpret Azure SQL vulnerability assessmentshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-overview
Reference for SQL vulnerability assessment ruleshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-rules
Changelog for SQL vulnerability assessment ruleshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-rules-changelog
Prerequisites and permissions for Defender for Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-storage
Manage tenant-wide permissions in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/tenant-wide-permissions-management

Configuration

TopicURL
Configure advanced malware scanning for Defender for Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/advanced-configurations-for-malware-scanning
Configure agentless code scanning in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-code-scanning
Configure Docker Hub vulnerability assessments with Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-vulnerability-assessment-docker-hub
Configure JFrog Artifactory vulnerability assessments with Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/agentless-vulnerability-assessment-jfrog-artifactory
Use Defender for Cloud alert schemas for integrationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/alerts-schemas
Configure Azure Monitor Agent for Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/auto-deploy-azure-monitoring-agent
Review prerequisites for data security posturehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-data-security-posture-prepare
Configure Microsoft Security Private Link for Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/concept-private-links
Configure Microsoft Security DevOps extension in Azure DevOpshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-azure-devops-extension
Configure Microsoft Security DevOps extension in Azure DevOpshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-azure-devops-extension
Configure Defender for Cloud alert email notificationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-email-notifications
Set up private endpoints for Defender for Cloud via Security Private Linkhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-private-endpoints
Modify Defender for Servers coverage and plan settingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/configure-servers-coverage
Configure continuous export of Defender for Cloud datahttps://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export
Configure continuous export with Azure Policy at scalehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export-azure-policy
Enable continuous export to event hubs behind firewallshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export-event-hub-firewall
Analyze Defender for Cloud export data in Azure Monitorhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export-view-data
Define custom security standards and recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/create-custom-recommendations
Configure cross-tenant management with Azure Lighthousehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/cross-tenant-management
Configure custom Data Collection Rules for Defender for Servershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-collection-rule
Enable data security posture for Azure datastoreshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-security-posture-enable
Customize Defender data sensitivity settingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/data-sensitivity-settings
Use Defender for Cloud CLI for security scanninghttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-cli-overview
Use Defender for Cloud CLI syntax for image and SBOM scanshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-cli-syntax
Manage onboarding and offboarding for Defender for APIshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-apis-manage
Programmatically enable Defender for Containers on Archttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-arc-enable-programmatically
Configure Defender for Containers settings on EKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-aws-configure
Configure Defender for Containers settings on AKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-azure-configure
Onboard Docker Hub registries to Defender for Containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-enable-external-registry-for-docker-hub
Configure Defender for Containers settings on GKEhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-gcp-configure
Enable and configure Defender for Storage classic via templateshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-classic-enable
Set up automated malware remediation in Defender for Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-configure-malware-scan
Enable vulnerability scanning with Defender Vulnerability Managementhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-vulnerability-assessment-defender-vulnerability-management
Disable specific VM vulnerability findings in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/disable-vulnerability-findings
Configure exemptions and disable container VA findingshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/disable-vulnerability-findings-containers
Configure agentless scanning for virtual machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms
Enable API security posture in Defender CSPMhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-api-security-posture
Enable and configure sensitive data threat detection for Storagehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-defender-for-storage-data-sensitivity
Enable just-in-time access for Azure virtual machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-just-in-time-access
Enable DevOps pull request security annotationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-pull-request-annotations
Configure Defender Vulnerability Management for containershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-vulnerability-assessment
Exclude machines from agentless scanning in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/exclude-machines-agentless-scanning
Configure resource exemptions for recommendationshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/exempt-resource
Create large-scale policy exemptions in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/exempt-resources-at-scale
SQL VA express configuration Azure CLI commands referencehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/express-configuration-azure-commands
SQL VA express configuration PowerShell commands referencehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/express-configuration-powershell-commands
SQL VA express configuration PowerShell wrapper module referencehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/express-configuration-sql-commands
Enable and configure File Integrity Monitoring in Defender for Servershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/file-integrity-monitoring-enable-defender-endpoint
Configure end-user and app context for AI security alertshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/gain-end-user-context-ai
Configure Microsoft Security DevOps GitHub Actionhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/github-action
Enable agentless container posture in Defender CSPMhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/how-to-enable-agentless-containers
Configure IaC misconfiguration scanning with Microsoft Security DevOpshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/iac-vulnerabilities
Configure and manage MCSB security standardhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/manage-mcsb
Enable Defender for Cloud on management groups via policyhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/onboard-management-group
Use built-in Azure Policy definitions for Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/policy-reference
Onboard Defender for Cloud using PowerShellhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/powershell-onboarding
PowerShell script to enable SQL VA express configurationhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/powershell-sample-vulnerability-assessment-azure-sql
PowerShell script to set SQL VA baselineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/powershell-sample-vulnerability-assessment-baselines
Query SBOM data in Defender for Cloud using Cloud Security Explorerhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/query-software-bill-of-materials
Set up Azure Policy guest configuration for Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/security-baseline-guest-configuration
Reference sensitive information types in Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sensitive-info-types
Enable SQL vulnerability assessment (Express) for Azure SQL and Synapsehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-enable
Enable SQL vulnerability assessment (Classic) with storage accounthttps://learn.microsoft.com/en-us/azure/defender-for-cloud/sql-azure-vulnerability-assessment-enable-classic
Test agentless malware scanning alerts for VMshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/test-agentless-malware-scanning
Update configuration for Defender for SQL Servers on Machineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/update-sql-machine-configuration

Integrations & Coding Patterns

TopicURL
Connect Defender for Cloud data to Power BIhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/add-data-power-bi
Query Defender attack path data via ARG APIhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/attack-path-api
Integrate Defender for Cloud CLI into CI/CD pipelineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/ci-cd-pipeline-scanning-with-defender-cli
Build Cloud Security Explorer queries for Kubernetes vulnerabilitieshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/cloud-security-explorer-kubernetes-clusters
Connect Endor Labs with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/connect-endor-labs
Connect Mend.io with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/connect-mend-io
Connect ServiceNow ITSM with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/connect-servicenow
Set up Defender for Cloud continuous export via REST APIhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/continuous-export-rest-api
Automate ServiceNow tickets with governance ruleshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/create-governance-rule-servicenow
Create and sync ServiceNow tickets from Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/create-ticket-servicenow
Programmatically deploy Defender for Containers on AKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-azure-enable-programmatically
Consume and export Defender for SQL scan results via ARGhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-scan-results
Use partner API security testing with Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-partner-applications
Enable Defender for Endpoint integration in Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-defender-for-endpoint
Stream Defender for Cloud alerts to SIEM toolshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-siem
Configure Azure resources to export alerts to QRadar and Splunkhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/export-to-splunk-or-qradar
Integrate AWS CloudTrail logs with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/integrate-cloud-trail
Integrate Defender for Endpoint with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/integration-defender-for-endpoint
Ingest GCP Cloud Logging into Defender for Cloud via Pub/Subhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/logging-ingestion
Onboard 42Crunch API security with Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/onboarding-guide-42crunch
Connect Bright Security DAST with Defenderhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/onboarding-guide-bright
Integrate StackHawk testing with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/onboarding-guide-stackhawk
Use legacy security solution integrations with Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/partner-integration
Run Azure Resource Graph queries for Defender for Cloudhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/resource-graph-samples
Use Defender VM subassessments for container vulnerabilitieshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/subassessment-rest-api

Deployment

TopicURL
Integrate Defender for Cloud CLI into CI/CD pipelineshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/ci-cd-pipeline-scanning-with-defender-cli
Enable Defender for Containers on EKS via portalhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-aws-enable-portal
Programmatically deploy Defender for Containers on EKShttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-aws-enable-programmatically
Remove Defender for Containers from EKS clustershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-aws-remove
Remove Defender for Containers from AKS clustershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-azure-remove
Enable Defender for Containers on GKE via portalhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-gcp-enable-portal
Programmatically deploy Defender for Containers on GKEhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-gcp-enable-programmatically
Remove Defender for Containers from GKE clustershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-containers-gcp-remove
Migrate Defender for SQL to AMA autoprovisioninghttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-autoprovisioning
Enable Defender for SQL Servers on Machines across environmentshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-sql-usage
Enable Defender for Storage via Azure portalhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-azure-portal-enablement
Enable Defender for Storage with IaC templateshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-infrastructure-as-code-enablement
Enable Defender for Storage using Azure Policyhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-policy-enablement
Enable Defender for Storage with Azure PowerShellhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-powershell-enablement
Enable Defender for Storage using REST APIhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/defender-for-storage-rest-api-enablement
Deploy Defender for Containers sensor via Helmhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/deploy-helm
Enable Defender for SQL on Machines at scalehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-defender-sql-at-scale
Deploy gated deployment agent via Infrastructure as Codehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/gated-deployment-infrastructure-as-code
Identify SQL Servers still protected by Microsoft Monitoring Agenthttps://learn.microsoft.com/en-us/azure/defender-for-cloud/identify-sql-servers-protected-by-monitor-agent
Migrate File Integrity Monitoring to Defender for Endpointhttps://learn.microsoft.com/en-us/azure/defender-for-cloud/migrate-file-integrity-monitoring
Review regional availability of Defender for Cloud planshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/regional-availability
Check Defender for Cloud interoperability and platform supporthttps://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-cloud
Support matrix for Defender for Containers featureshttps://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-containers
Review support matrix and requirements for Defender for Servershttps://learn.microsoft.com/en-us/azure/defender-for-cloud/support-matrix-defender-for-servers
Deploy Microsoft Defender for Storage on Azurehttps://learn.microsoft.com/en-us/azure/defender-for-cloud/tutorial-enable-storage-plan
Verify Defender for SQL Servers on Machines protection statushttps://learn.microsoft.com/en-us/azure/defender-for-cloud/verify-machine-protection

> related_skills --same-repo

> azure-well-architected

Expert guidance for designing, assessing, and optimizing Azure workloads using Azure Well Architected. Covers design review checklists, recommendations, design principles, tradeoffs, service guides, workload patterns, and assessment questions. Use when architecting new solutions, reviewing existing workloads, or applying Well-Architected principles.

> azure-web-pubsub

Expert knowledge for Azure Web PubSub development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure Web PubSub applications. Not for Azure SignalR Service (use azure-signalr-service), Azure Event Hubs (use azure-event-hubs), Azure Service Bus (use azure-service-bus), Azure Relay (use azure-relay).

> azure-web-application-firewall

Expert knowledge for Azure Web Application Firewall development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure Web Application Firewall applications. Not for Azure Application Gateway (use azure-application-gateway), Azure Front Door (use azure-front-door), Azure Firewall (use azure-firewall), Azure DDos Protectio

> azure-vpn-gateway

Expert knowledge for Azure VPN Gateway development including troubleshooting, best practices, decision making, architecture & design patterns, limits & quotas, security, configuration, integrations & coding patterns, and deployment. Use when building, debugging, or optimizing Azure VPN Gateway applications. Not for Azure Virtual Network (use azure-virtual-network), Azure Virtual WAN (use azure-virtual-wan), Azure ExpressRoute (use azure-expressroute), Azure Application Gateway (use azure-applica

┌ stats

installs/wk0
░░░░░░░░░░
github stars425
██████████
first seenMar 17, 2026
└────────────

┌ repo

MicrosoftDocs/Agent-Skills
by MicrosoftDocs
└────────────

┌ tags

└────────────