An organization uses Microsoft Defender for Cloud to protect Azure virtual machines. They notice that several VMs are not receiving vulnerability assessment findings, even though they are in a scope where the integrated Qualys VA solution is enabled. What should they verify first?
Trap 1: The VM is in a resource group that is excluded from the…
While resource group exclusions can prevent the vulnerability assessment from being applied, the scenario explicitly places the VM in scope, so an exclusion cannot be the reason. Exclusions are managed at the resource group level and would affect all VMs in that group. Because the VM is in scope, this option is not applicable.
Trap 2: The VM is behind a network security group that blocks outbound…
A network security group that blocks outbound traffic could indeed prevent the Qualys extension from communicating with the scanning service, leading to missing scan results. However, the most common and immediate cause for absent vulnerability data is the lack of the Log Analytics agent, which is a prerequisite for the extension. The agent should be checked before evaluating network connectivity.
Trap 3: The VM does not have a valid Qualys license.
Defender for Cloud includes the Qualys vulnerability scanner without requiring a separate Qualys license; the license is fully managed by Microsoft. Therefore, an invalid or missing Qualys license cannot be the reason for the absence of vulnerability findings. This option is incorrect because the licensing is transparent to the customer.
- A
The VM does not have the Log Analytics agent installed.
The vulnerability assessment solution in Microsoft Defender for Cloud uses the Qualys extension, which depends on the Log Analytics agent being installed and reporting to the configured workspace. Without that agent, the extension cannot be deployed or execute a scan, so no findings are returned. Verifying the agent's installation and health should be the first diagnostic step.
- B
The VM is in a resource group that is excluded from the vulnerability assessment solution.
Why it fails: While resource group exclusions can prevent the vulnerability assessment from being applied, the scenario explicitly places the VM in scope, so an exclusion cannot be the reason. Exclusions are managed at the resource group level and would affect all VMs in that group. Because the VM is in scope, this option is not applicable.
- C
The VM is behind a network security group that blocks outbound traffic.
Why it fails: A network security group that blocks outbound traffic could indeed prevent the Qualys extension from communicating with the scanning service, leading to missing scan results. However, the most common and immediate cause for absent vulnerability data is the lack of the Log Analytics agent, which is a prerequisite for the extension. The agent should be checked before evaluating network connectivity.
- D
The VM does not have a valid Qualys license.
Why it fails: Defender for Cloud includes the Qualys vulnerability scanner without requiring a separate Qualys license; the license is fully managed by Microsoft. Therefore, an invalid or missing Qualys license cannot be the reason for the absence of vulnerability findings. This option is incorrect because the licensing is transparent to the customer.