Skip to main content
compliance · azure

Non-Windows Azure VMs with no antimalware or Defender for Endpoint extension

resource types
1
rule IDs covered
1
severity
high

What does ZopNight detect here?

ZopNight flags an Azure VM that is not running Windows when neither the Microsoft Antimalware extension nor a Microsoft Defender for Endpoint extension is installed. Windows VMs are skipped because Windows Server 2016 and later include Microsoft Defender Antivirus. VMs with no reported operating system are still checked. No saving is claimed.

Signal and threshold

How ZopNight evaluates Non-Windows Azure VMs with no antimalware or Defender for Endpoint extension.
Field Value
Rule IDsRC-1304
Categorycompliance
Severityhigh
Metricnone — pure configuration read
Thresholdno endpoint protection extension
SourceZopNight
Permissions usedMicrosoft.Compute/virtualMachines/read · Microsoft.Compute/virtualMachines/extensions/read

Linux VMs get no antivirus by default

On Windows, Microsoft Defender Antivirus is built into Windows Server 2016 and later, so a Windows VM has endpoint protection even with no extension. Linux has no equivalent in the box. The classic Microsoft Antimalware for Azure extension does not help there: Microsoft lists it as not supported on Linux.

For Linux VMs, endpoint protection comes from Microsoft Defender for Endpoint, installed through Defender for Cloud as the MDE.Linux extension, or from a third-party agent. A Linux server without either has nothing watching for malware, crypto-miners or ransomware.

Checking what a VM has installed

Terminal window
az vm extension list --resource-group my-rg --vm-name my-vm --query "[].name" -o tsv
az vm show --resource-group my-rg --name my-vm --query storageProfile.osDisk.osType

Look for MDE.Linux (or IaaSAntimalware on Windows). The second command confirms the operating system type.

What ZopNight needs to see

The rule first looks at the operating system family Azure reports for the VM. Windows VMs are skipped outright. For the rest, ZopNight checks Azure’s inventory of antimalware and Defender for Endpoint extensions and fires only when that inventory was retrieved and the VM is absent from it. No metric or window is involved.

VMs that are not flagged

Windows VMs never fire, because the missing extension is not a real gap there. A VM whose operating system is not reported is not skipped: ZopNight evaluates it like a non-Windows VM rather than risk hiding an unprotected Linux machine, so a Windows VM with no OS data can occasionally be flagged. If the extension inventory was not available, the VM is treated as unknown. Tags claiming antimalware is installed are ignored.

Endpoint exposure; protection is a paid plan

This compliance finding claims no saving. Defender for Endpoint on servers is licensed through Defender for Servers, which Microsoft charges per hour of protected machine time.

Protecting a Linux VM

  1. Enable Microsoft Defender for Servers on the subscription in Defender for Cloud.
  2. Let Defender for Cloud provision the Defender for Endpoint sensor automatically; on Linux it appears as the MDE.Linux extension. See Defender for Endpoint integration.
  3. Or install a supported third-party Linux endpoint agent with real-time protection and scheduled scans.
  4. Confirm the VM shows as onboarded in the Defender portal, not just “Can be onboarded”.

See it fire on your bill.

Connect an account read-only. The first findings land in minutes.

472 rule families across 353 resource types on 22 platforms. Every threshold, metric, and IAM action is documented on these pages before you grant anything.

472 rule families documented
353 resource types covered
read-only default access level
Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console· Multi-cloud automation· Production-ready in 30 min· SOC 2 · ISO 27001· 20–60% off the bill, first month· 4 platforms · 1 console·