Review & Remediate Guest Configuration Recommendations
Implementation Effort: Medium
Security and IT teams must ensure the guest configuration extension is deployed, review OS-level misconfigurations, and apply remediations based on Microsoft Cloud Security Benchmark (MCSB) baselines.
User Impact: Low
Guest configuration remediation is handled by administrators and security teams; end users are not directly involved.
Overview
Microsoft Defender for Servers uses the Azure Policy machine configuration extension (formerly known as Guest Configuration) to assess operating system settings against security baselines. These baselines are defined by the Microsoft Cloud Security Benchmark (MCSB) and help organizations harden their server environments.
When misconfigurations are detected, Defender for Cloud generates recommendations that guide remediation efforts for both Windows and Linux machines.
Prerequisites
- Defender for Servers Plan 2 must be enabled.
- The Azure Policy machine configuration extension must be installed on each machine.
- Avoid using the deprecated Log Analytics agent (MMA) to prevent duplicate recommendations 1.