How to secure container in container apps using Defender for cloud

DiptiRanjan Swain 176 Reputation points
2024-04-12T17:10:20.8966667+00:00

Hi, I want to know how can I protect the containers during runtime and scan the images with Defender for containers. Listing down my questions

  1. How to configure Defender for Containers for runtime protection. And what action to take post configuration.
  2. How the runtime protection will work for containers in Container App
  3. How to scan the container images and notify findings to our development team
  4. What other Defender plans need to enable for complete protection of the containers
Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,250 questions
Azure Container Apps
Azure Container Apps
An Azure service that provides a general-purpose, serverless container platform.
324 questions
0 comments No comments
{count} votes

Accepted answer
  1. Patchfox 3,806 Reputation points
    2024-04-14T08:29:07.9866667+00:00

    Hi DiptiRanjan Swain, thanks fro your questions.

    I want to help you with this questions.

    As I understand, you want to know how you can start with Defender for Containers and how you configure them to protect container apps, as well as notify developers about finding and what are the cost of the DfC, right?

    First, you can enable Defender for Containers via the Defender for Cloud service in Azure.

    There you have to enable the payed plan, on default you have already security features in place but they are limited and not includes Defender for containers.

    After you set the Defender for Containers to On for the subscriptions, microsoft starts automatically with the deamon provision on the existing container in the scope.

    But if you dont want to have this process automatically you can disable the auto provisioning in the settings as well (in the plan activation blade on the left choose "Auto provisioning")

    After the privioning is done you should see the list of all containers in the Inventory blade of defender for cloud.

    To view the recommendations there are several ways for. As a developer the easiest way is to view it in the specific subscriptions. There are all recommendations listed, filtered for this specific subscription. Please consider the necessary permissions to see the recommendations blade in the subscription

    This is a quick overview about Defender for containers but you can read more here:

    https://video2.skills-academy.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction

    https://techcommunity.microsoft.com/t5/microsoft-defender-for-cloud/introducing-microsoft-defender-for-containers/ba-p/2952317

    Here you can read more about the architecture of Defender for Containers and how they work:

    https://video2.skills-academy.com/en-us/azure/defender-for-cloud/defender-for-containers-introduction

    About the Costs:

    When you activate Defender for Containers you pay for every virtual core per hour on the containers you activated with Defender for Containers.


    If the reply was helpful, please don’t forget to upvote or accept it as an answer, thank you!

    1 person found this answer helpful.

0 additional answers

Sort by: Most helpful