Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Defender for Cloud helps you find and fix vulnerabilities in images that your Kubernetes workloads use.
To create these findings, Defender for Cloud first builds a list of your Kubernetes workloads. It uses supported discovery and protection components to do this. Then it matches that list against known vulnerability data for the images those workloads run.
Findings for running containers appear as security recommendations. The following steps use the Flat list view, which shows results at the resource level. Learn more about reviewing recommendations by title or by resource.
Note
You might see both grouped and individual recommendation formats in the portal during this transition. Learn more about transitioning from grouped to individual recommendations.
Prerequisites
Before you begin, enable Defender for Containers or Defender CSPM on your subscription. Turn on one of these component sets:
- Registry access and either Kubernetes API access or Defender sensor. This option links scanned registry images to running workloads.
- Agentless scanning for machines and either Kubernetes API access or Defender sensor. This option checks for runtime vulnerabilities without a registry.
View vulnerabilities for running containers
To view vulnerabilities for a running container:
Sign in to the Azure portal.
Go to Microsoft Defender for Cloud > Recommendations.
Select the Vulnerabilities tab.
Select the Flat list view.
Select Add filter.
Select Resource type.
Select Container.
Select Apply.
Select a recommendation.
Review the details, including risk info, fix steps, and metadata.
Select the Associated CVEs tab to see the CVEs for that item.
Select a CVE to view its severity, affected components, and fix version.
Related content
To find all containers with a given vulnerability, see Group recommendations by title.
To fix vulnerabilities, see Remediate recommendations.