Edit

Remediate system updates and patches recommendations

Defender for Cloud uses update assessment signals from Azure Update Manager to surface recommendations for missing system updates and patches across protected machines. Remediating these recommendations helps reduce exploitable vulnerabilities and keeps machine security hygiene aligned with Defender for Servers protections.

Microsoft Defender for Cloud provides security recommendations to improve your organizational security posture and reduce risk. An important element in risk reduction is to harden machines across your business environment.

As part of the hardening strategy, Defender for Cloud assesses machines to check that the latest system updates and patches are installed, and issues security recommendations if they're not. System updates and patches are crucial for keeping machines secure and healthy. Updates often contain security patches for vulnerabilities that, if left unfixed, are exploitable by attackers.

Defender for Servers Plan 2 automatically assesses updates and patches on machines and generates the following recommendations as needed:

These recommendations rely on Azure Update Manager, which uses a VM extension.

Note

The older method for update assessment used the Log Analytics agent (also known as the Microsoft Monitoring Agent (MMA)) to gather data. Use of the MMA is now deprecated.

Prerequisites

Enable periodic assessment on machines

To enable periodic assessment for system updates, complete the following steps:

  1. In Defender for Cloud, open the Recommendations page.

  2. Select the recommendation Machines should be configured to periodically check for missing system updates (powered by Azure Update Manager).

    • Under Remediation steps, review quick fix and manual fix details. If you follow the quick fix, the periodic assessment update setting is enabled on machines.
    • In the Unhealthy resources list, drill down to see resource details.
  3. Select Fix. For more information, see Use the fix option.

  4. Select the relevant machine, and then select Fix 1 resource.

Periodic assessment can also be enabled at scale with Azure Policy.

Remediate update recommendations

To remediate system update recommendations, complete the following steps:

  1. In Defender for Cloud, open the Recommendations page.

  2. Select the recommendation System updates should be installed on your machines (powered by Azure Update Manager).

  3. Review the recommendation.

  4. Select the Fix option to do a one-time installation of missing updates through the Update Manager portal.

    Screenshot that shows where the fix button is located.

Remediate recommendations at scale

You can remediate recommendations on many machines at the same time.

  1. In Defender for Cloud, open the Recommendations page.

  2. Select the recommendation System updates should be installed on your machines (powered by Azure Update Manager).

  3. Locate the relevant system update recommendation.

  4. Review the recommendation.

  5. In the recommendation details page, select View recommendation for all resources.

    Screenshot that shows where the view recommendation for all resources button is located.

  6. Select all machines you want to fix.

  7. Select Fix.

Next step