Non-Windows Azure VMs with no antimalware or Defender for Endpoint extension
What does ZopNight detect here?
ZopNight flags an Azure VM that is not running Windows when neither the Microsoft Antimalware extension nor a Microsoft Defender for Endpoint extension is installed. Windows VMs are skipped because Windows Server 2016 and later include Microsoft Defender Antivirus. VMs with no reported operating system are still checked. No saving is claimed.
Signal and threshold
| Field | Value |
|---|---|
| Rule IDs | RC-1304 |
| Category | compliance |
| Severity | high |
| Metric | none — pure configuration read |
| Threshold | no endpoint protection extension |
| Source | ZopNight |
| Permissions used | Microsoft.Compute/virtualMachines/read · Microsoft.Compute/virtualMachines/extensions/read |
Where it applies
Linux VMs get no antivirus by default
On Windows, Microsoft Defender Antivirus is built into Windows Server 2016 and later, so a Windows VM has endpoint protection even with no extension. Linux has no equivalent in the box. The classic Microsoft Antimalware for Azure extension does not help there: Microsoft lists it as not supported on Linux.
For Linux VMs, endpoint protection comes from Microsoft Defender for Endpoint, installed through
Defender for Cloud as the MDE.Linux extension, or from a third-party agent. A Linux server
without either has nothing watching for malware, crypto-miners or ransomware.
Checking what a VM has installed
az vm extension list --resource-group my-rg --vm-name my-vm --query "[].name" -o tsvaz vm show --resource-group my-rg --name my-vm --query storageProfile.osDisk.osTypeLook for MDE.Linux (or IaaSAntimalware on Windows). The second command confirms the
operating system type.
What ZopNight needs to see
The rule first looks at the operating system family Azure reports for the VM. Windows VMs are skipped outright. For the rest, ZopNight checks Azure’s inventory of antimalware and Defender for Endpoint extensions and fires only when that inventory was retrieved and the VM is absent from it. No metric or window is involved.
VMs that are not flagged
Windows VMs never fire, because the missing extension is not a real gap there. A VM whose operating system is not reported is not skipped: ZopNight evaluates it like a non-Windows VM rather than risk hiding an unprotected Linux machine, so a Windows VM with no OS data can occasionally be flagged. If the extension inventory was not available, the VM is treated as unknown. Tags claiming antimalware is installed are ignored.
Endpoint exposure; protection is a paid plan
This compliance finding claims no saving. Defender for Endpoint on servers is licensed through Defender for Servers, which Microsoft charges per hour of protected machine time.
Protecting a Linux VM
- Enable Microsoft Defender for Servers on the subscription in Defender for Cloud.
- Let Defender for Cloud provision the Defender for Endpoint sensor automatically; on Linux it
appears as the
MDE.Linuxextension. See Defender for Endpoint integration. - Or install a supported third-party Linux endpoint agent with real-time protection and scheduled scans.
- Confirm the VM shows as onboarded in the Defender portal, not just “Can be onboarded”.