Edit

Onboard agentless containers for CSPM

Enable agentless container posture in Defender CSPM to gain visibility into Kubernetes clusters and container images without deploying agents.

Agentless container posture is available for Azure, AWS, and GCP environments. This article walks you through enabling agentless container posture in each supported cloud so you can discover running containers, assess vulnerabilities in container registries, and analyze Kubernetes cluster configurations.

Prerequisites

How to onboard agentless container posture in Defender CSPM

Use the following steps to onboard agentless container posture in Defender CSPM for your cloud environment.

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

  3. Select the relevant subscription.

  4. Under Defender plans, locate Defender CSPM.

  5. Select Settings.

  6. Enable the following settings:

    • Kubernetes API access
    • Registry access
  7. Select Continue.

  8. Select Save.