{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
        "slug": "dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/"
        },
        "title": "Explain OS-only agentless findings before counting Azure data disks as covered",
        "summary": "Why can Defender for Cloud report an Azure VM's operating-system disk while leaving its data disks outside agentless coverage?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:28:07+00:00",
        "modified_at": "2026-09-10T01:20:46+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 259,
        "potentially_affected": "Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs.",
        "dse_recommendation": "Calculate combined provisioned disk capacity and record data-disk coverage separately from operating-system findings.",
        "primary_source": {
            "name": "Enable agentless machine scanning - Microsoft Defender for Cloud | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>For supported Azure VMs, Defender for Cloud agentless scanning considers the combined size of the operating-system and data disks. Above four terabytes, only the operating-system disk is scanned, and only if that disk is smaller than four terabytes. Data disks are then outside coverage. VMs with more than fourteen disks are unsupported. <a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>Scans follow a fixed daily schedule. A stopped or deallocated machine is skipped for that cycle. Microsoft explicitly cautions that an enabled setting does not establish coverage and advises against restructuring production disks solely to meet the scan limit. <a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs. Check the full disk-type, filesystem and encryption requirements as well as capacity. This size calculation is not a substitute for the remaining support checks.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends totaling provisioned disk sizes from the actual VM configuration, then marking operating-system and data-disk coverage separately. For data outside the agentless boundary, record the approved alternative assessment method and its owner. Do not classify an entire VM as assessed simply because some findings exist. Investigate scheduled power state before interpreting missing fresh results as a permission defect.</p>\n<h2>Verification</h2>\n<p>Compare expected coverage with the next eligible scan cycle&#8217;s findings. Check that the inventory records any OS-only result and the uncovered data disks explicitly. Retain the capacity calculation, disk count and power-state evidence with the assessment. Revisit the boundary when disks are added or resized rather than carrying the previous coverage label forward.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Enable agentless machine scanning</a>.</p>",
        "content_text": "Source facts\nFor supported Azure VMs, Defender for Cloud agentless scanning considers the combined size of the operating-system and data disks. Above four terabytes, only the operating-system disk is scanned, and only if that disk is smaller than four terabytes. Data disks are then outside coverage. VMs with more than fourteen disks are unsupported. Microsoft Learn.\nScans follow a fixed daily schedule. A stopped or deallocated machine is skipped for that cycle. Microsoft explicitly cautions that an enabled setting does not establish coverage and advises against restructuring production disks solely to meet the scan limit. Microsoft Learn.\nApplicability\nReview Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs. Check the full disk-type, filesystem and encryption requirements as well as capacity. This size calculation is not a substitute for the remaining support checks.\nDSE recommendation\nDSE recommends totaling provisioned disk sizes from the actual VM configuration, then marking operating-system and data-disk coverage separately. For data outside the agentless boundary, record the approved alternative assessment method and its owner. Do not classify an entire VM as assessed simply because some findings exist. Investigate scheduled power state before interpreting missing fresh results as a permission defect.\nVerification\nCompare expected coverage with the next eligible scan cycle’s findings. Check that the inventory records any OS-only result and the uncovered data disks explicitly. Retain the capacity calculation, disk count and power-state evidence with the assessment. Revisit the boundary when disks are added or resized rather than carrying the previous coverage label forward.\nOfficial references\nMicrosoft Learn: Enable agentless machine scanning.",
        "content_markdown": "## Source facts\n\nFor supported Azure VMs, Defender for Cloud agentless scanning considers the combined size of the operating-system and data disks. Above four terabytes, only the operating-system disk is scanned, and only if that disk is smaller than four terabytes. Data disks are then outside coverage. VMs with more than fourteen disks are unsupported. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms).\n\nScans follow a fixed daily schedule. A stopped or deallocated machine is skipped for that cycle. Microsoft explicitly cautions that an enabled setting does not establish coverage and advises against restructuring production disks solely to meet the scan limit. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms).\n\n## Applicability\n\nReview Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs. Check the full disk-type, filesystem and encryption requirements as well as capacity. This size calculation is not a substitute for the remaining support checks.\n\n## DSE recommendation\n\nDSE recommends totaling provisioned disk sizes from the actual VM configuration, then marking operating-system and data-disk coverage separately. For data outside the agentless boundary, record the approved alternative assessment method and its owner. Do not classify an entire VM as assessed simply because some findings exist. Investigate scheduled power state before interpreting missing fresh results as a permission defect.\n\n## Verification\n\nCompare expected coverage with the next eligible scan cycle’s findings. Check that the inventory records any OS-only result and the uncovered data disks explicitly. Retain the capacity calculation, disk count and power-state evidence with the assessment. Revisit the boundary when disks are added or resized rather than carrying the previous coverage label forward.\n\n## Official references\n\n[Microsoft Learn: Enable agentless machine scanning](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Explain OS-only agentless findings before counting Azure data disks as covered",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/",
                "headline": "Explain OS-only agentless findings before counting Azure data disks as covered",
                "description": "Why can Defender for Cloud report an Azure VM's operating-system disk while leaving its data disks outside agentless coverage?",
                "abstract": "Why can Defender for Cloud report an Azure VM's operating-system disk while leaving its data disks outside agentless coverage?",
                "articleBody": "Source facts\nFor supported Azure VMs, Defender for Cloud agentless scanning considers the combined size of the operating-system and data disks. Above four terabytes, only the operating-system disk is scanned, and only if that disk is smaller than four terabytes. Data disks are then outside coverage. VMs with more than fourteen disks are unsupported. Microsoft Learn.\nScans follow a fixed daily schedule. A stopped or deallocated machine is skipped for that cycle. Microsoft explicitly cautions that an enabled setting does not establish coverage and advises against restructuring production disks solely to meet the scan limit. Microsoft Learn.\nApplicability\nReview Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs. Check the full disk-type, filesystem and encryption requirements as well as capacity. This size calculation is not a substitute for the remaining support checks.\nDSE recommendation\nDSE recommends totaling provisioned disk sizes from the actual VM configuration, then marking operating-system and data-disk coverage separately. For data outside the agentless boundary, record the approved alternative assessment method and its owner. Do not classify an entire VM as assessed simply because some findings exist. Investigate scheduled power state before interpreting missing fresh results as a permission defect.\nVerification\nCompare expected coverage with the next eligible scan cycle’s findings. Check that the inventory records any OS-only result and the uncovered data disks explicitly. Retain the capacity calculation, disk count and power-state evidence with the assessment. Revisit the boundary when disks are added or resized rather than carrying the previous coverage label forward.\nOfficial references\nMicrosoft Learn: Enable agentless machine scanning.",
                "datePublished": "2026-09-10T00:28:07+00:00",
                "dateModified": "2026-09-10T01:20:46+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Explain OS-only agentless findings before counting Azure data disks as covered"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 259,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Enable agentless machine scanning - Microsoft Defender for Cloud | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms"
                }
            }
        ]
    }
}