Azure_VM_4

Ensure that only approved extensions are installed

Description

Only install organization-approved extensions on VMs.

Remediation

Perform the following in the Azure Console:

  1. Go to Virtual machines
  2. For each virtual machine, go to Settings
  3. Click on Extensions
  4. If there are unapproved extensions, uninstall them.

Perform the following in Azure Command Line Interface 2.0:

From the audit command identify the unapproved extensions, and use the below CLI command to remove an unapproved extension attached to VM.

az vm extension delete –resource-group <resourceGroupName> –vm-name <vmName> –name <extensionName>

References:

  1. https://docs.microsoft.com/en-us/azure/virtual-machines/windows/extensions-features

Service

Virtual Machines

Severity

Medium

Compliance

Mapping

We are now live on AWS Marketplace.
The integrated view of your cloud infrastructure is now easier than ever!