ExplainerInformationCybersecurityIT

Keep agentless inventory separate from software first-seen chronology

Does a missing First seen at value mean Defender for Cloud has no software evidence?

Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.
DSE visual intelligenceCyber defenseExplainer · 2 min read
Executive summary

What you need to know

Does a missing First seen at value mean Defender for Cloud has no software evidence?

Potentially affected

Defender for Cloud installed-application inventory combining agent-based and agentless software observations.

DSE recommendation

Record the collection method before using First seen at to compare software discovery timelines.

Source facts

Defender for Cloud’s installed-application inventory defines First seen at as when software was first observed on the asset. That field is populated only for agent-based scanning, not agentless scanning. The inventory separately exposes detected version and, when available, file or registry paths as evidence. Microsoft Learn.

Applicability

Use this interpretation when a report combines observations from both collection methods. The first-observation field should not be presented as an installation timestamp, and an empty value should not by itself settle whether software evidence exists.

DSE recommendation

Record the collection method before using First seen at to compare software discovery timelines. Keep the software identity, version and available evidence alongside the date field rather than ranking records solely by whether that date is present. For an investigation requiring installation chronology, identify the additional authorized evidence needed to establish it. Do not substitute the time of report generation for an unavailable first-observation value.

Verification

Compare representative agent-based and agentless records for the same reporting purpose. Confirm that an empty date remains explicitly unavailable and does not cause the software row to be discarded or described as newly installed. Inspect any downstream sorting, age calculations or exception logic that consumes the field. Preserve the collection-method distinction with the exported evidence so a later reviewer can understand why similar software records have different chronological detail. No installation or discovery event is inferred beyond the recorded observations.

Official references

Microsoft Learn: Defender for Cloud asset inventory. Source reviewed September 9, 2026.

Primary reference

Review the official source

Cloud asset inventory - Microsoft Defender for Cloud | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE