# Explain OS-only agentless findings before counting Azure data disks as covered

> Why can Defender for Cloud report an Azure VM's operating-system disk while leaving its data disks outside agentless coverage?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:28:07+00:00
- Modified: 2026-09-10T01:20:46+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, Networks & Infrastructure
- Reading time: 2 minutes

## What you need to know

Why can Defender for Cloud report an Azure VM's operating-system disk while leaving its data disks outside agentless coverage?

## Potentially affected

Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs.

## DSE recommendation

Calculate combined provisioned disk capacity and record data-disk coverage separately from operating-system findings.

## Article

## Source facts

For supported Azure VMs, Defender for Cloud agentless scanning considers the combined size of the operating-system and data disks. Above four terabytes, only the operating-system disk is scanned, and only if that disk is smaller than four terabytes. Data disks are then outside coverage. VMs with more than fourteen disks are unsupported. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms).

Scans follow a fixed daily schedule. A stopped or deallocated machine is skipped for that cycle. Microsoft explicitly cautions that an enabled setting does not establish coverage and advises against restructuring production disks solely to meet the scan limit. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms).

## Applicability

Review Defender for Cloud agentless scanning of Azure standard VMs and Flexible scale-set VMs. Check the full disk-type, filesystem and encryption requirements as well as capacity. This size calculation is not a substitute for the remaining support checks.

## DSE recommendation

DSE recommends totaling provisioned disk sizes from the actual VM configuration, then marking operating-system and data-disk coverage separately. For data outside the agentless boundary, record the approved alternative assessment method and its owner. Do not classify an entire VM as assessed simply because some findings exist. Investigate scheduled power state before interpreting missing fresh results as a permission defect.

## Verification

Compare expected coverage with the next eligible scan cycle’s findings. Check that the inventory records any OS-only result and the uncovered data disks explicitly. Retain the capacity calculation, disk count and power-state evidence with the assessment. Revisit the boundary when disks are added or resized rather than carrying the previous coverage label forward.

## Official references

[Microsoft Learn: Enable agentless machine scanning](https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms).

## Primary reference

- Name: Enable agentless machine scanning - Microsoft Defender for Cloud | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/azure/defender-for-cloud/enable-agentless-scanning-vms
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Explain OS-only agentless findings before counting Azure data disks as covered,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-229-explain-os-only-agentless-findings-before-counting-azure-data-disks-as-covered/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
