You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/defender-for-cloud/support-matrix-defender-for-containers.md
+18-18Lines changed: 18 additions & 18 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -43,8 +43,8 @@ Following are the features for each of the domains in Defender for Containers:
43
43
44
44
| Feature | Description | Supported resources | Linux release state | Windows release state | Enablement method | Sensor | Plans | Azure clouds availability |
45
45
|--|--|--|--|--|--|--|--|--|
46
-
| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-azure---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| Vulnerability assessment for images in ACR | ACR, Private ACR | GA |Preview| Enable **Agentless container vulnerability assessment** toggle | Agentless | Defender for Containers or Defender CSPM | Commercial clouds<br/><br/> National clouds: Azure Government, Azure operated by 21Vianet |
47
-
| Agentless/agent-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-azure---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| Vulnerability assessment for running images in AKS | AKS | GA |Preview| Enable **Agentless container vulnerability assessment** toggle | Agentless (Requires Agentless discovery for Kubernetes) **OR/AND** Defender sensor | Defender for Containers or Defender CSPM | Commercial clouds<br/><br/> National clouds: Azure Government, Azure operated by 21Vianet |
46
+
| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-azure---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| Vulnerability assessment for images in ACR | ACR, Private ACR | GA |GA| Enable **Agentless container vulnerability assessment** toggle | Agentless | Defender for Containers or Defender CSPM | Commercial clouds<br/><br/> National clouds: Azure Government, Azure operated by 21Vianet |
47
+
| Agentless/agent-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-azure---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| Vulnerability assessment for running images in AKS | AKS | GA |GA| Enable **Agentless container vulnerability assessment** toggle | Agentless (Requires Agentless discovery for Kubernetes) **OR/AND** Defender sensor | Defender for Containers or Defender CSPM | Commercial clouds<br/><br/> National clouds: Azure Government, Azure operated by 21Vianet |
48
48
49
49
### Runtime threat protection
50
50
@@ -96,27 +96,27 @@ Learn how to [use Azure Private Link to connect networks to Azure Monitor](../az
96
96
97
97
| Domain | Feature | Supported Resources | Linux release state | Windows release state | Agentless/Sensor-based | Pricing tier |
98
98
|--|--| -- | -- | -- | -- | --|
99
-
| Security posture management |[Agentless discovery for Kubernetes](defender-for-containers-introduction.md#security-posture-management)| EKS |Preview|Preview| Agentless | Defender for Containers **OR** Defender CSPM |
| Security posture management | Kubernetes data plane hardening | EKS | GA| - | Azure Policy for Kubernetes | Defender for Containers |
106
-
|[Vulnerability assessment](agentless-vulnerability-assessment-aws.md)| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-aws---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| ECR |Preview|Preview| Agentless | Defender for Containers or Defender CSPM |
107
-
|[Vulnerability assessment](agentless-vulnerability-assessment-aws.md)| Agentless/sensor-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-aws---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| EKS |Preview|Preview| Agentless **OR/AND** Defender sensor | Defender for Containers or Defender CSPM |
106
+
|[Vulnerability assessment](agentless-vulnerability-assessment-aws.md)| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-aws---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| ECR |GA|GA| Agentless | Defender for Containers or Defender CSPM |
107
+
|[Vulnerability assessment](agentless-vulnerability-assessment-aws.md)| Agentless/sensor-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-aws---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| EKS |GA|GA| Agentless **OR/AND** Defender sensor | Defender for Containers or Defender CSPM |
108
108
| Runtime protection| Control plane | EKS | GA | Preview | Agentless | Defender for Containers |
109
109
| Runtime protection| Workload | EKS | GA | - | Defender sensor | Defender for Containers |
110
110
| Deployment & monitoring | Discovery of unprotected clusters | EKS | GA | - | Agentless | Defender for Containers |
111
-
| Deployment & monitoring | Auto provisioning of Defender sensor |-|-| - | - | - |
112
-
| Deployment & monitoring | Auto provisioning of Azure Policy for Kubernetes |-|-| - | - | - |
111
+
| Deployment & monitoring | Auto provisioning of Defender sensor |EKS|Preview| - | - | - |
112
+
| Deployment & monitoring | Auto provisioning of Azure Policy for Kubernetes |EKS|Preview| - | - | - |
113
113
114
114
### Registries and images support for AWS - Vulnerability assessment powered by Microsoft Defender Vulnerability Management
115
115
116
116
| Aspect | Details |
117
117
|--|--|
118
118
| Registries and images |**Supported**<br> • ECR registries <br> • Container images in Docker V2 format <br> • Images with [Open Container Initiative (OCI)](https://github.com/opencontainers/image-spec/blob/main/spec.md) image format specification <br> **Unsupported**<br> • Super-minimalist images such as [Docker scratch](https://hub.docker.com/_/scratch/) images is currently unsupported <br> • Public repositories <br> • Manifest lists <br>|
119
-
| Operating systems |**Supported** <br> • Alpine Linux 3.12-3.16 <br> • Red Hat Enterprise Linux 6-9 <br> • CentOS 6-9<br> • Oracle Linux 6-9 <br> • Amazon Linux 1, 2 <br> • openSUSE Leap, openSUSE Tumbleweed <br> • SUSE Enterprise Linux 11-15 <br> • Debian GNU/Linux 7-12 <br> • Google Distroless (based on Debian GNU/Linux 7-12)<br> • Ubuntu 12.04-22.04 <br> • Fedora 31-37<br> • Mariner 1-2<br> • Windows server 2016, 2019, 2022|
119
+
| Operating systems |**Supported** <br> • Alpine Linux 3.12-3.19 <br> • Red Hat Enterprise Linux 6-9 <br> • CentOS 6-9<br> • Oracle Linux 6-9 <br> • Amazon Linux 1, 2 <br> • openSUSE Leap, openSUSE Tumbleweed <br> • SUSE Enterprise Linux 11-15 <br> • Debian GNU/Linux 7-12 <br> • Google Distroless (based on Debian GNU/Linux 7-12)<br> • Ubuntu 12.04-22.04 <br> • Fedora 31-37<br> • Mariner 1-2<br> • Windows server 2016, 2019, 2022|
120
120
| Language specific packages <br><br> |**Supported** <br> • Python <br> • Node.js <br> • .NET <br> • JAVA <br> • Go |
121
121
122
122
### Kubernetes distributions/configurations support for AWS - Runtime threat protection
@@ -140,15 +140,15 @@ Outbound proxy without authentication and outbound proxy with basic authenticati
140
140
141
141
| Domain | Feature | Supported Resources | Linux release state | Windows release state | Agentless/Sensor-based | Pricing tier |
142
142
|--|--| -- | -- | -- | -- | --|
143
-
| Security posture management |[Agentless discovery for Kubernetes](defender-for-containers-introduction.md#security-posture-management)| GKE |Preview|Preview| Agentless | Defender for Containers **OR** Defender CSPM |
| Security posture management | Control plane hardening | GKE | GA | GA | Agentless | Free |
149
149
| Security posture management | Kubernetes data plane hardening | GKE | GA| - | Azure Policy for Kubernetes | Defender for Containers |
150
-
|[Vulnerability assessment](agentless-vulnerability-assessment-gcp.md)| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-gcp---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| GAR, GCR |Preview|Preview| Agentless | Defender for Containers or Defender CSPM |
151
-
|[Vulnerability assessment](agentless-vulnerability-assessment-gcp.md)| Agentless/sensor-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-gcp---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| GKE |Preview|Preview| Agentless **OR/AND** Defender sensor | Defender for Containers or Defender CSPM |
150
+
|[Vulnerability assessment](agentless-vulnerability-assessment-gcp.md)| Agentless registry scan (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-gcp---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| GAR, GCR |GA|GA| Agentless | Defender for Containers or Defender CSPM |
151
+
|[Vulnerability assessment](agentless-vulnerability-assessment-gcp.md)| Agentless/sensor-based runtime (powered by Microsoft Defender Vulnerability Management) [supported packages](#registries-and-images-support-for-gcp---vulnerability-assessment-powered-by-microsoft-defender-vulnerability-management)| GKE |GA|GA| Agentless **OR/AND** Defender sensor | Defender for Containers or Defender CSPM |
152
152
| Runtime protection| Control plane | GKE | GA | Preview | Agentless | Defender for Containers |
153
153
| Runtime protection| Workload | GKE | GA | - | Defender sensor | Defender for Containers |
154
154
| Deployment & monitoring | Discovery of unprotected clusters | GKE | GA | - | Agentless | Defender for Containers |
@@ -160,7 +160,7 @@ Outbound proxy without authentication and outbound proxy with basic authenticati
160
160
| Aspect | Details |
161
161
|--|--|
162
162
| Registries and images |**Supported**<br> • Google Registries (GAR, GCR) <br> • Container images in Docker V2 format <br> • Images with [Open Container Initiative (OCI)](https://github.com/opencontainers/image-spec/blob/main/spec.md) image format specification <br> **Unsupported**<br> • Super-minimalist images such as [Docker scratch](https://hub.docker.com/_/scratch/) images is currently unsupported <br> • Public repositories <br> • Manifest lists <br>|
163
-
| Operating systems |**Supported** <br> • Alpine Linux 3.12-3.16 <br> • Red Hat Enterprise Linux 6-9 <br> • CentOS 6-9<br> • Oracle Linux 6-9 <br> • Amazon Linux 1, 2 <br> • openSUSE Leap, openSUSE Tumbleweed <br> • SUSE Enterprise Linux 11-15 <br> • Debian GNU/Linux 7-12 <br> • Google Distroless (based on Debian GNU/Linux 7-12)<br> • Ubuntu 12.04-22.04 <br> • Fedora 31-37<br> • Mariner 1-2<br> • Windows server 2016, 2019, 2022|
163
+
| Operating systems |**Supported** <br> • Alpine Linux 3.12-3.19 <br> • Red Hat Enterprise Linux 6-9 <br> • CentOS 6-9<br> • Oracle Linux 6-9 <br> • Amazon Linux 1, 2 <br> • openSUSE Leap, openSUSE Tumbleweed <br> • SUSE Enterprise Linux 11-15 <br> • Debian GNU/Linux 7-12 <br> • Google Distroless (based on Debian GNU/Linux 7-12)<br> • Ubuntu 12.04-22.04 <br> • Fedora 31-37<br> • Mariner 1-2<br> • Windows server 2016, 2019, 2022|
164
164
| Language specific packages <br><br> |**Supported** <br> • Python <br> • Node.js <br> • .NET <br> • JAVA <br> • Go |
165
165
166
166
### Kubernetes distributions/configurations support for GCP - Runtime threat protection
0 commit comments