In MS Defender for Cloud how to exclude a single VM from the monitoring

Jamal Balametov 0 Reputation points
2025-01-30T02:46:36.71+00:00

I have a virtual appliance from MDR provider AlerLogic. MS Defender generates alerts for the VM because it does vulnerability scanning and uses some tools that make Defender unhappy. This is the normal behavior of the Virtual Appliance. Is there any way to exclude it from Defender's monitoring completely?

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,480 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Stanislav Zhelyazkov 25,686 Reputation points MVP
    2025-01-30T09:59:19.7766667+00:00

    Hi,

    Specifically for the agentless scanning capabilities of Defender for Cloud you can exclude specific VMs by tags: Exclude machines from agentless scanning. So you assign specific tag and value to that machine and after that configure the same tag and value to exclude it on the agentless scanning configuration.

    Please "Accept the answer" if the information helped you. This will help us and others in the community as well.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.