Understanding why full and quick scans are out of 7 days

Quattrocchi, Calogero 265 Reputation points
2024-06-06T12:05:36.9366667+00:00

Hi,

We have been receiving security recommendations for our virtual machines, and one of the findings states that "Both full and quick scans are out of 7 days":

EDR configuration issues should be resolved on virtual machines-> Findings-> Both full and quick scans are out of 7 days

The details indicate:

{
    
    
        
        
    }
}

The defender plan sor Servers is Plan2:

User's image User's image I would like to understand:

  1. Where does this security recommendations come from?
  2. Why a quick scan is not automatically performed when the option "agentless scanning for machines" is set to ON?
  3. How to solve it?

Thanks

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,395 questions
0 comments No comments
{count} vote

4 answers

Sort by: Most helpful
  1. Marilee Turscak-MSFT 36,856 Reputation points Microsoft Employee
    2024-06-07T23:04:35.7666667+00:00

    Hi @Quattrocchi, Calogero ,

    The details you shared are blank. Are the details truly empty or did they not copy/paste into your post? Aso, do you have all of the prerequisites met for agentless scanning for machines? If you see the finding "Both full and quick scans are out of 7 days", you need to investigate under the "Recommendations" section and follow the remediation steps documented here. If you've already resolved any EDR recommendations, it can take up to 24 hours for the changes to reflect.

    Note also that you need to meet the prerequisites highlighted in the article in order to view the recommendations:

    If you are not seeing information in the "Additional Information" section, feel free to reach out to me at AzCommunity@microsoft.com ("Attn: Marilee Turscak") and include your subscription ID and a link to this thread. That way we can further troubleshoot and I can open a one-time free support case to look into this issue.

    If the information helped you, please Accept the answer. This will help us and improve searchability for others in the community who may be researching similar questions.

    0 comments No comments

  2. Quattrocchi, Calogero 265 Reputation points
    2024-06-08T08:08:55.2333333+00:00

    Hi,

    Sorry the copy paste did not work (see below now the additional information).

    We meet all prerequistes as mentioned above.

    However, the reommendation is still present after more than 24 hours:

    "Both full and quick scans are out of 7 days"

    Why there is no automatic quick scan in place for the VMs?

    How to allow this automatic quick scan?

    Thanks

    Regards.

    {
        "assessedResourceType": "GeneralVulnerability",
        "data": {
            "LastQuickScanDate": "No quick scan date found",
            "LastFullScanDate": "No full scan date found"
        }
    }
    
    0 comments No comments

  3. Quattrocchi, Calogero 265 Reputation points
    2024-09-18T07:06:09.2466667+00:00

    Hello,

    After a few months, the recommendation from Microsoft Defender fo Cloud reappears

    "EDR configuration issues should be resolved on virtual machines".

    In the additionl information of the recommendation, we can read:

    {
        "assessedResourceType": "GeneralVulnerability",
        "data": {
            "LastQuickScanDate": "9/2/2024 1:50:07 PM",
            "LastFullScanDate": "No full scan date found"
        }
    }
    

    All prerequisites are still met:

    • Defender for Cloud enabled
    • Defender for Servers plan 2
    • Defender Cloud Security Posture Management (CSPM)
    • Agentless scanning for virtual machines enabled

    See screenshots below:

    User's image

    User's image

    User's image

    So, why do we get again this reommendation?

    Thanks

    Regards

    0 comments No comments

  4. Andrew Blumhardt 9,861 Reputation points Microsoft Employee
    2024-10-22T12:30:40.3833333+00:00

    This recommendation is based on the Azure Security Benchmark, which is a policy initiative or group of policies that is included with Azure. The initiative is updated periodically.

    This is one recommendation that I disagree with. I shared this with the MDE team and they seemed to agree. A more common recommendation is quick scans daily or weekly followed by full scans monthly (or only when manually requested).
    You might attempt to modify the polity to better reflect your scanning preferences. You also have the option o make exclusions or turn the associated policy off completely.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.