A vertical process flow showing the sequential steps to configure agentless vulnerability scanning in Microsoft Defender for Servers, from registering resource providers and activating the plan through policy assignment, automated scanning, and remediation of findings by severity.
Agentless vulnerability assessment in Microsoft Defender for Servers scans virtual machines (VMs) for security weaknesses without requiring any agent installed on the VM. This approach reduces management overhead while still providing continuous visibility into vulnerabilities. The assessment results appear in Defender for Cloud, where you can monitor and act on them.
Before you can use agentless scanning, you must register the Microsoft.Security and Microsoft.OperationalInsights resource providers in your subscription. These providers enable the underlying services that Defender for Cloud relies on. Next, activate the Defender for Servers plan, which unlocks the vulnerability assessment capability along with other protections for your VMs.
You need a Log Analytics workspace to collect and store security data from the scans. Provision a workspace and link it to Defender for Cloud. Ensure the workspace has proper network connectivity so that data can flow from your VMs to the workspace without interruption. The workspace becomes the central repository for vulnerability insights and helps with detailed analysis.
Assign the built-in Azure Policy definition designed for agentless vulnerability assessment. This policy automatically applies the scanning configuration to all VMs within the selected scope—no manual agent installation is needed. Once the policy is assigned, any new or existing VM in that scope is onboarded for scanning.
After configuration, scans run automatically on the VMs. Each scan evaluates the current security state, identifies vulnerabilities, and produces actionable findings. You can view the results directly in Defender for Cloud, where they are organized by severity and include remediation guidance.
Regularly review the assessment reports in Defender for Cloud to stay on top of vulnerabilities. The reports categorize findings by severity, helping you prioritize which issues to fix first. Use the provided remediation steps to address each vulnerability and continuously improve the security posture of your VMs.
Are you a guardian of your domain? Lean how to leverage your aptitude in security to protect Microsoft Azure technologies, with a goal of earning the Microsoft Certified: Azure Security Engineer Associate certification!
Prepare and test your skills

Prepare and test your skills

To enable agentless vulnerability assessment, you must register the Microsoft.Security and Microsoft.OperationalInsights resource providers in your subscription. You must also activate the Defender for Servers plan, which unlocks the vulnerability assessment capability for your virtual machines.
A Log Analytics workspace serves as the central repository to collect, store, and analyze security data and vulnerability insights generated from the scans. It must be linked to Defender for Cloud and configured with proper network connectivity to ensure data flows from your virtual machines without interruption.
Agentless scanning is applied by assigning the built-in Azure Policy definition designed for agentless vulnerability assessment. Once assigned, the policy automatically applies the scanning configuration to all existing and newly added virtual machines within that scope without requiring manual agent installation.