Skip to content

Commit d725d57

Browse files
committed
Learn Editor: Update enable-agentless-scanning-vms.md
1 parent 4d9669b commit d725d57

File tree

1 file changed

+3
-1
lines changed

1 file changed

+3
-1
lines changed

articles/defender-for-cloud/enable-agentless-scanning-vms.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -71,7 +71,9 @@ To manually assign the permissions, follow the below instructions according to y
7171
- For Key Vaults using non-RBAC permissions, assign "Microsoft Defender for Cloud Servers Scanner Resource Provider" (`0c7668b5-3260-4ad0-9f53-34ed54fa19b2`) these permissions: Key Get, Key Wrap, Key Unwrap.
7272
- For Key Vaults using RBAC permissions, assign "Microsoft Defender for Cloud Servers Scanner Resource Provider” (`0c7668b5-3260-4ad0-9f53-34ed54fa19b2`) the [Key Vault Crypto Service Encryption User](https://learn.microsoft.com/en-us/azure/key-vault/general/rbac-guide?preserve-view=true&tabs=azure-cli#azure-built-in-roles-for-key-vault-data-plane-operations) built-in role.
7373

74-
Learn more on [agentless scanning permissions](faq-permissions#which-permissions-are-used-by-agentless-scanning-)
74+
To assign these permissions at scale, you can also use [this script](https://github.com/Azure/Microsoft-Defender-for-Cloud/tree/main/Powershell%20scripts/Agentless%20Scanning%20CMK%20support).
75+
76+
Learn more on [agentless scanning permissions](faq-permissions#which-permissions-are-used-by-agentless-scanning-).
7577

7678
### Agentless vulnerability assessment on AWS
7779

0 commit comments

Comments
 (0)