MEDIUM
Source
CloudSploit
ID
auto-provisioning-enabled

Auto Provisioning Enabled

Ensures that automatic provisioning of the monitoring agent is enabled.

The Microsoft Monitoring Agent scans for various security-related configurations and events such as system updates, OS vulnerabilities, and endpoint protection and provides alerts.

Follow the appropriate remediation steps below to resolve the issue.

  1. Log in to the Microsoft Azure Management Console.

  2. Select the “Search resources, services, and docs” option at the top and search for “Microsoft Defender for Cloud”. Step

  3. On the “Microsoft Defender for Cloud” page scroll down the left navigation panel and choose “Environment Settings”. Step

  4. On the “Environment Settings” page, select the “Subscription” by clicking on its “Name”. Step

  5. Under the “Settings” page, click on “Defender Plans”. Step

  6. On the “Settings | Defender” page, select the “Settings and Monitoring Tab”. Step

  7. On the settings and Monitoring Page. If the “Log Analytics agent” shows status as turned off, then the “Automatic provisioning” of the monitoring agent is not enabled. Step

  8. On the “Settings | Auto provisioning” page, turn the status “ON” for “Log Analytics agent for Azure VMs” by toggling it. Step

  9. This will open the “Auto Provisioning configuration”. Under Workplace Selection, select the “Default Workspace(s)” and select “Apply” to save changes. Step

  10. Repeat step number 3 - 9 to ensure that the data collection settings of the subscription have Auto Provisioning set to enabled.