Description:
Auto-provisioning installs the Log Analytics agent automatically on Azure VMs to ensure they send security and monitoring data to Microsoft Defender for Cloud. This setting guarantees that all newly created or existing VMs begin forwarding logs without manual configuration.
Rationale:
Enabling auto-provisioning ensures consistent deployment of the Log Analytics agent across all Azure VMs. This improves monitoring coverage, supports automated threat detection, and prevents gaps where machines may operate without required security telemetry.
Impact:
Ensures uniform security monitoring across all Azure VMs
Automates onboarding of new VMs into Log Analytics / Defender
Supports SIEM, threat detection, and vulnerability scanning
Reduces operational overhead and human error
Required for many compliance standards
Default Value:
Auto provisioning is disabled by default.
Pre-Requisites:
A Log Analytics Workspace is available
Defender for Servers Plan recommended
Permissions:
Microsoft.Security/*
Microsoft.OperationalInsights/workspaces/*
Microsoft.Compute/virtualMachines/*
Test Plan:
Sign in to the Azure portal
Search for Microsoft Defender for Cloud
Under the management section, Select Environment Settings
Choose the Subscription
Under the settings, click Defender plans
In the Defender plans page, click Settings & Monitoring
Check if the Log Analytics agent is on or off
If it is off, follow the implementation steps.
Implementation Steps:
Sign in to the Azure portal
Search for Microsoft Defender for Cloud
Under the management section, click Environment Settings
Choose the Subscription
Under the settings, click Defender plans
In the Defender plans page, click Settings & Monitoring
Find the Log Analytics agent. Change toggle to On
Continue to Save changes
Backout Plan:
Sign in to the Azure portal.
Search for and open Microsoft Defender for Cloud.
Under the Management section, select Environment Settings.
Select the required subscription.
Under the settings, click Defender plans
In the Defender plans page, click Settings & Monitoring
Set Vulnerability assessment for machines to Off.
Save the changes.
Reference:



