Review & Remediate Security Baseline Recommendations
Implementation Effort: Medium
Security and IT teams must review OS-level misconfigurations, validate guest configuration deployment, and remediate findings based on Microsoft Cloud Security Benchmark (MCSB) baselines.
User Impact: Low
Security baseline remediation is handled by administrators and security teams; end users are not directly involved.
Overview
Microsoft Defender for Servers continuously assesses virtual machines against security baselines defined by the Microsoft Cloud Security Benchmark (MCSB). These baselines help ensure that operating system configurations align with best practices for security and compliance. When deviations are detected, Defender for Cloud generates recommendations to guide remediation.
Prerequisites
- Defender for Servers Plan 2 must be enabled.
- The Azure Policy machine configuration extension (formerly Guest Configuration) must be installed on the VM.
- Machines must not be using the deprecated Log Analytics agent (MMA) to avoid duplicate recommendations 1.