A security team uses Microsoft Defender for Cloud to monitor Azure virtual machines. They want to automatically install a specific endpoint protection solution on all Windows VMs that are currently missing it, without manual intervention. The solution is not integrated natively with Defender for Cloud. Which feature should they use?
Create an Azure Policy definition using the DeployIfNotExists effect that targets VMs (or VM extensions) where the specific endpoint protection extension is absent. When the policy evaluates a VM and the condition is true, it deploys a linked ARM template, which installs the vendor's protection extension using the assignment's managed identity. This approach works for non-native, third-party solutions because you provide the extension template, and it can be used both for automatic evaluation of new VMs and for a remediation task to cover already-running VMs. The policy assignment must have a managed identity with Contributor (or equivalent) permissions on the target scope.
Why this answer
Azure Policy's 'DeployIfNotExists' effect can automatically deploy a custom endpoint protection extension to Windows VMs that are missing it, even if the solution is not natively integrated with Defender for Cloud. This allows the security team to enforce compliance by installing the specific third-party endpoint protection agent via a policy assignment, without manual intervention.
Exam trap
The trap here is that candidates often assume Defender for Cloud's 'Fix' option can deploy any endpoint protection solution, but it only supports solutions that are natively integrated and listed in the Defender for Cloud dashboard.
How to eliminate wrong answers
Option A is wrong because the 'Endpoint protection' recommendation in Defender for Cloud and its 'Fix' option only work with endpoint protection solutions that are natively integrated (e.g., Microsoft Defender Antivirus, Trend Micro, Symantec); it cannot deploy a non-integrated, custom solution. Option C is wrong because adaptive application controls are a whitelisting feature that controls which applications can run on a VM, not a mechanism to install or deploy software. Option D is wrong because just-in-time VM access manages network access to management ports (e.g., RDP, SSH) to reduce attack surface, not the installation of endpoint protection agents.