Deploy Defender Sensor
Implementation Effort: Medium – Requires enabling Defender for Containers and deploying the sensor across Kubernetes clusters using Azure portal, CLI, or templates.
User Impact: Low – Sensor deployment is handled by platform and security teams; end users are not directly affected.
Overview
Deploying the Defender sensor is a critical step in enabling runtime protection, telemetry collection, and threat detection in Microsoft Defender for Containers. The sensor runs as a DaemonSet on each node in your Kubernetes cluster and sends security data to Microsoft Defender for Cloud via a connected Log Analytics workspace.
Supported Environments
- Azure Kubernetes Service (AKS)
- Amazon EKS (via connected AWS account)
- Google GKE (via connected GCP project)
- On-premises or IaaS Kubernetes clusters (via Azure Arc) 1