You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: articles/security-center/built-in-vulnerability-assessment.md
+13-3Lines changed: 13 additions & 3 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -22,7 +22,7 @@ The vulnerability scanner included with Azure Security Center is powered by Qual
22
22
This feature is currently in preview.
23
23
24
24
> [!NOTE]
25
-
> Security Center supports the integration of tools from other vendors, but you'll need to handle the licensing costs, deployment, and configuration. For more information, see [Deploying a partner vulnerability scanning solution](partner-vulnerability-assessment.md).
25
+
> Security Center supports the integration of tools from other vendors, but you'll need to handle the licensing costs, deployment, and configuration. For more information, see [Deploying a partner vulnerability scanning solution](partner-vulnerability-assessment.md). You can also use those instructions to integrate your organization's own Qualys license, if you choose not to use the built-in vulnerability scanner included with Azure Security Center.
26
26
27
27
## Deploying the Qualys built-in vulnerability scanner (Standard tier only)
28
28
@@ -93,12 +93,22 @@ To see the findings and remediate the identified vulnerability:
93
93
1. To remediate a finding, follow the remediation steps from this details pane.
94
94
95
95
96
+
97
+
## Exporting results
98
+
99
+
To export vulnerability assessment results, you'll need to use [Azure Resource Graph](https://azure.microsoft.com/features/resource-graph/) (ARG). This tool provides instant access to resource information across your cloud environments with robust filtering, grouping, and sorting capabilities. It's a quick and efficient way to query information across Azure subscriptions programmatically or from within the Azure portal.
100
+
101
+
For full instructions and a sample ARG query, see this Tech Community post: [Exporting Vulnerability Assessment Results in Azure Security Center](https://techcommunity.microsoft.com/t5/azure-security-center/exporting-vulnerability-assessment-results-in-azure-security/ba-p/1212091).
102
+
103
+
96
104
## Built-in Qualys vulnerability scanner FAQ
97
105
98
106
### Are there any additional charges for the Qualys license?
99
-
No. The built-in scanner is free to all Standard tier users. The "Enable the built-in vulnerability assessment solution on virtual machines (powered by Qualys)" recommendation deploys a scanner that includes all the necessary licensing and configuration information. No additional licenses are required.
107
+
No. The built-in scanner is free to all standard tier users. The "Enable the built-in vulnerability assessment solution on virtual machines (powered by Qualys)" recommendation deploys a scanner that includes all the necessary licensing and configuration information. No additional licenses are required.
100
108
101
109
### What permissions are required to install the Qualys extension?
110
+
You'll need write permissions for any VM on which you want to deploy the extension.
111
+
102
112
The Azure Security Center Vulnerability Assessment extension (powered by Qualys), like other extensions, runs on top of the Azure Virtual Machine agent. So it runs as Local Host on Windows, and Root on Linux.
103
113
104
114
### Can I remove the Security Center Qualys extension?
@@ -151,7 +161,7 @@ When you open the recommendation, you'll see your VMs in one or more of the foll
151
161
The scanner is running on your virtual machine and looking for vulnerabilities of the VM itself. From the virtual machine, it can't scan your network.
152
162
153
163
### Does the scanner integrate with my existing Qualys console?
154
-
The Security Center extension is a separate tool from your existing Qualys scanner and, because of licensing restrictions, can only be used within Azure Security Center.
164
+
The Security Center extension is a separate tool from your existing Qualys scanner and, because of licensing restrictions, must be used within Azure Security Center.
155
165
156
166
### Microsoft Defender Advanced Threat Protection also includes Threat & Vulnerability Management (TVM). How is the Security Center Vulnerability Assessment extension different?
157
167
Microsoft is actively developing world-class vulnerability management with Microsoft Defender ATP's Threat & Vulnerability Management solution, built into Windows.
# Deploying a partner vulnerability scanning solution
19
19
20
-
Customers on the Free tier can choose to deploy vulnerability assessment solutions from [Qualys](https://www.qualys.com/lp/azure) and [Rapid7](https://www.rapid7.com/products/insightvm/). You can install the solution on multiple VMs. The VMs must belong to the same subscription.
20
+
If you're on the standard tier, you're able to use Azure Security Center's built-in vulnerability assessment tool as described in [Integrated vulnerability scanner for virtual machines](built-in-vulnerability-assessment.md). This tool doesn't require a Qualys license or even a Qualys account - everything's handled seamlessly inside Security Center.
21
+
22
+
Alternatively, you might want to deploy your own privately-licensed vulnerability assessment solution from [Qualys](https://www.qualys.com/lp/azure) or [Rapid7](https://www.rapid7.com/products/insightvm/). You can install one of these partner solutions on multiple VMs that belong to the same subscription.
21
23
22
24
## Configuring a partner solution
23
25
@@ -40,7 +42,7 @@ Customers on the Free tier can choose to deploy vulnerability assessment solutio
40
42
To deploy the agent from Security Center, you need a license code and public key from the vendor. To learn how to get the license code and public key, see the [Qualys documentation](https://community.qualys.com/docs/DOC-5823-deploying-qualys-cloud-agents-from-microsoft-azure-security-center) or [Rapid7 documentation](https://insightvm.help.rapid7.com/docs/azure-security-center).
41
43
42
44
43
-
1. To create a new assessment, click **Create new**. The partner’s **vulnerability management** page opens. The options shown on this page might change depending on the partner.
45
+
1. To create a new assessment, click **Create new**. The partner's **vulnerability management** page opens. The options shown on this page might change depending on the partner.
44
46
45
47

Copy file name to clipboardExpand all lines: articles/security-center/security-center-vulnerability-assessment-recommendations.md
+2-2Lines changed: 2 additions & 2 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -21,9 +21,9 @@ A core component of every cyber risk and security program is the identification
21
21
22
22
Security Center presents one of two recommendations if it doesn't find a vulnerability assessment solution installed on a VM:
23
23
24
-
***For standard tier users**, a recommendation offers to install an Azure Security Center Vulnerability Assessment extension (powered by Qualys) for you at no additional cost. This extension reports its findings directly back to Security Center. To learn more, see [Integrated vulnerability scanner for virtual machines](built-in-vulnerability-assessment.md).
24
+
-**Enable the built-in vulnerability assessment solution on virtual machines (powered by Qualys)** - This recommendation only appears standard tiers. It's an invitation to install an Azure Security Center Vulnerability Assessment extension (powered by Qualys) for you at no additional cost. This extension reports its findings directly back to Security Center. To learn more, see [Integrated vulnerability scanner for virtual machines](built-in-vulnerability-assessment.md).
25
25
26
-
***For users on the free tier**, Security Center recommends that you install a partner solution. You'll need to purchase a license for your chosen solution separately. Supported solutions report vulnerability data to the partner’s management platform. In turn, that platform provides vulnerability and health monitoring data back to Security Center. You can identify vulnerable VMs on the Security Center dashboard. Switch to the partner management console directly from Security Center for additional reports and information. To learn more, see [Deploying a partner vulnerability scanning solution](partner-vulnerability-assessment.md).
26
+
-**Vulnerability assessment solution should be installed on your virtual machines** - This recommendation appears for both standard and free tiers. Use this recommendation to install any of the supported partner solutions. You'll need to purchase a license for your chosen solution separately. Supported solutions report vulnerability data to the partner's management platform. In turn, that platform provides vulnerability and health monitoring data back to Security Center. You can identify vulnerable VMs on the Security Center dashboard. Switch to the partner management console directly from Security Center for additional reports and information. To learn more, see [Deploying a partner vulnerability scanning solution](partner-vulnerability-assessment.md).
27
27
28
28
Security Center also offers vulnerability analysis for your:
0 commit comments