Skip to content

Commit e18b7de

Browse files
author
David Curwin
committed
updates after shani review
1 parent b42ece5 commit e18b7de

File tree

3 files changed

+9
-2
lines changed

3 files changed

+9
-2
lines changed

articles/defender-for-cloud/defender-for-containers-introduction.md

Lines changed: 3 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -114,7 +114,9 @@ The discovery process is based on snapshots taken at intervals:
114114

115115
When you enable the agentless discovery for Kubernetes extension, the following process occurs:
116116

117-
- **Create**: Defender for Cloud creates an identity in customer environments called CloudPosture/securityOperator/DefenderCSPMSecurityOperator.
117+
- **Create**:
118+
- If the extension is enabled from Defender CSPM, Defender for Cloud creates an identity in customer environments called `CloudPosture/securityOperator/DefenderCSPMSecurityOperator`.
119+
- If the extension is enabled from Defender for Containers, Defender for Cloud creates an identity in customer environments called `CloudPosture/securityOperator/DefenderForContainersSecurityOperator`.
118120
- **Assign**: Defender for Cloud assigns a built-in role called **Kubernetes Agentless Operator** to that identity on subscription scope. The role contains the following permissions:
119121

120122
- AKS read (Microsoft.ContainerService/managedClusters/read)
251 KB
Loading

articles/defender-for-cloud/release-notes.md

Lines changed: 6 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -44,7 +44,12 @@ We're excited to introduce to Defender For Containers: Agentless discovery for K
4444
- Kubernetes-specific security insights
4545
- Enhanced risk hunting with Cloud Security Explorer
4646

47-
Agentless discovery for Kubernetes is now available to all Defender For Containers customers. You can start using these advanced capabilities today. For more information, see [Agentless discovery for Kubernetes](defender-for-containers-introduction.md#agentless-discovery-for-kubernetes).
47+
Agentless discovery for Kubernetes is now available to all Defender For Containers customers. You can start using these advanced capabilities today. We encourage you to update your subscriptions to have the full set of extensions enabled, and benefit from the latest additions and features. Visit the **Environment and settings** pane of your Defender for Containers subscription to enable the extension.
48+
49+
> [!NOTE]
50+
> Enabling the latest additions won't incur new costs to active Defender for Containers customers.
51+
52+
For more information, see [Agentless discovery for Kubernetes](defender-for-containers-introduction.md#agentless-discovery-for-kubernetes).
4853

4954
### Recommendation release: Microsoft Defender for Storage should be enabled with malware scanning and sensitive data threat detection
5055

0 commit comments

Comments
 (0)