Configure auto-provisioning extensions for Defender agents, vulnerability assessment, agentless scanning, and container sensors.
Configure auto-provisioning extensions for Defender agents, vulnerability assessment, agentless scanning, and container sensors.
Required Fields
subscriptionIdautoProvisioningSettingsautoProvisioningSettings[0].nameautoProvisioningSettings[0].autoProvisionOutput will appear here...Configure Defender for Cloud's auto-provisioning settings for security extensions (Defender for Endpoint, vulnerability assessment, Azure Monitor Agent, agentless scanning, container sensor, sensitive data discovery), each independently toggled with its own configuration block rather than one global on/off switch. MicrosoftDefenderForEndpoint's enforcementMode set to Audit (rather than Enforce or another blocking mode) means the extension reports what it would do without actually taking blocking action, a deliberate staged-rollout pattern, but a team that sets Audit intending it as a permanent conservative posture and never revisits it gets visibility without any actual enforcement indefinitely.
Treat enforcementMode: Audit as a temporary rollout stage with a planned revisit date, not a permanent security posture, a team that sets Audit and moves on gets visibility without actual protection indefinitely.
Exclusion tags scoped to one specific auto-provisioning setting are easy to mistake for a broader security exemption, verify what exactly a given exclusionTags configuration exempts a resource from before assuming it covers more than that one setting.
Scope SensitiveDataDiscovery's sensitiveInfoTypes list to what's actually relevant for your compliance requirements, an overly broad list generates more findings to triage without necessarily improving actual data-protection posture, dilating signal with types that aren't genuinely relevant to your data.
The builder validates that subscriptionId, autoProvisioningSettings, and the first setting's name/autoProvision resolve before accepting the JSON as a plausible combined auto-provisioning configuration payload; it can't verify a specific extension's configuration block (like AzureMonitorAgent's referenced workspace/DCR) is actually valid or that the referenced resource IDs exist, those checks happen only against the live Microsoft.Security resource provider.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.