# Keep agentless inventory separate from software first-seen chronology

> Does a missing First seen at value mean Defender for Cloud has no software evidence?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:29:31+00:00
- Modified: 2026-09-10T00:52:39+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

Does a missing First seen at value mean Defender for Cloud has no software evidence?

## Potentially affected

Defender for Cloud installed-application inventory combining agent-based and agentless software observations.

## DSE recommendation

Record the collection method before using First seen at to compare software discovery timelines.

## Article

## Source facts

Defender for Cloud’s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory).

## Applicability

Use this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.

## DSE recommendation

Record the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.

## Verification

Compare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.

## Official references

[Microsoft Learn: Defender for Cloud asset inventory](https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory). Source reviewed September 9, 2026.

## Primary reference

- Name: Cloud asset inventory - Microsoft Defender for Cloud | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/defender-for-cloud/asset-inventory
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Keep agentless inventory separate from software first-seen chronology,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-145-keep-agentless-inventory-separate-from-software-first-seen-chronology/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
