Skip to content

Commit 34cc68d

Browse files
committed
implementing feedback - updated screenshot
1 parent 54696e9 commit 34cc68d

File tree

4 files changed

+8
-9
lines changed

4 files changed

+8
-9
lines changed

articles/defender-for-cloud/concept-agentless-containers.md

Lines changed: 3 additions & 7 deletions
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ ms.custom: template-concept
1111

1212
Identify security risks in containers and Kubernetes realms with an agentless discovery and visibility capability across SDLC and runtime.
1313

14-
With container vulnerability assessment insights as part of [Cloud Security Explorer](how-to-manage-cloud-security-explorer.md) and Kubernetes [Attack Path](attack-path-reference.md#attack-paths) analysis, you can maximize coverage on container posture issues and extend beyond the reach of agent-based assessments, providing a holistic approach to your posture improvement.
14+
With container vulnerability assessment insights as part of [Cloud Security Explorer](how-to-manage-cloud-security-explorer.md) and Kubernetes [Attack Path](attack-path-reference.md#azure-containers) analysis, you can maximize coverage on container posture issues and extend beyond the reach of agent-based assessments, providing a holistic approach to your posture improvement.
1515

1616
Learn more about [Cloud Security Posture Management](concept-cloud-security-posture-management.md).
1717

@@ -76,13 +76,13 @@ Verify that the settings were saved successfully - a notification message pops u
7676

7777
Agentless information in Defender CSPM is updated once an hour via snapshotting mechanism. It can take up to **24 hours** to see results in Cloud Security Explorer and Attack Path.
7878

79-
Recommendations are available based on vulnerability assessment timeline. Learn more about [agentless scanning](concept-agentless-data-collection.md).
79+
Recommendations are available based on vulnerability assessment timeline. Learn more about [image scanning](defender-for-containers-vulnerability-assessment-azure.md).
8080

8181
## How agentless containers works
8282

8383
The system’s architecture is based on a snapshot mechanism at intervals.
8484

85-
<!--- :::image type="content" source="media/concept-agentless-containers/diagram-permissions-architecture.png" alt-text="Diagram of the permissions architecture." lightbox="media/concept-agentless-containers/diagram-permissions-architecture.png"::: --->
85+
:::image type="content" source="media/concept-agentless-containers/diagram-permissions-architecture.png" alt-text="Diagram of the permissions architecture." lightbox="media/concept-agentless-containers/diagram-permissions-architecture.png":::
8686

8787
By enabling the Agentless discovery for Kubernetes extension, the following process occurs:
8888

@@ -103,10 +103,6 @@ By enabling the Agentless discovery for Kubernetes extension, the following proc
103103

104104
1. **Bind**: Upon discovery of an AKS cluster, MDC performs an AKS bind operation between the created identity and the Kubernetes role “Microsoft.Security/pricings/microsoft-defender-operator”. The role is visible via API and gives MDC data plane read permission inside the cluster.
105105

106-
Agentless information in Defender CSPM is updated once an hour via snapshotting mechanism.
107-
108106
## Next steps
109107

110-
This article explains how agentless container posture works.
111-
112108
Learn more about [Cloud Security Posture Management](concept-cloud-security-posture-management.md).

articles/defender-for-cloud/how-to-manage-cloud-security-explorer.md

Lines changed: 5 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -19,9 +19,12 @@ Learn more about [the cloud security graph, attack path analysis, and the cloud
1919

2020
## Prerequisites
2121

22-
- You must [enable agentless scanning](enable-vulnerability-assessment-agentless.md).
22+
- You must [enable Defender CSPM](enable-enhanced-security.md).
23+
- For Agentless Container Posture, you must enable the following extensions:
24+
- Agentless discovery for Kubernetes (preview)
25+
- Container registries vulnerability assessments (preview)
2326

24-
- You must [enable Defender for CSPM](enable-enhanced-security.md).
27+
- You must [enable agentless scanning](enable-vulnerability-assessment-agentless.md).
2528

2629
- Required roles and permissions:
2730
- Security Reader
-20.2 KB
Loading
276 KB
Loading

0 commit comments

Comments
 (0)