You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何通过PowerShell操作Defender for Cloud安全配置及查询现有设置?

关于Defender for Cloud相关PowerShell操作的解答

1. 是否可以通过PowerShell启用Defender for Cloud中的agentless scanning和endpoint protection?

可以,具体操作如下:

  • 启用Agentless服务器漏洞扫描:
    使用Set-AzSecuritySetting修改对应安全设置:
    Set-AzSecuritySetting -Name "AgentlessVulnerabilityAssessment" -SettingKind "DataExportSettings" -Enabled $true
    
  • 启用Endpoint Protection自动部署:
    通过Set-AzSecurityAutoProvisioningSetting配置自动部署策略,为符合条件的服务器部署Microsoft Defender for Endpoint:
    Set-AzSecurityAutoProvisioningSetting -Name "default" -AutoProvision "On"
    

2. 是否可以通过PowerShell在Defender for SQL设置中配置AMA?

可以,通过PowerShell可配置Azure Monitor Agent(AMA)收集Defender for SQL所需数据,步骤如下:

  1. 先启用SQL服务器的Defender for SQL:
    Set-AzSqlServerSecurityAlertPolicy -ResourceGroupName "你的资源组名称" -ServerName "你的SQL服务器名称" -Enabled $true
    
  2. 创建数据收集规则(DCR)并关联到SQL服务器:
    # 创建数据收集规则示例
    $dcrParams = @{
        ResourceGroupName = "你的资源组名称"
        Location = "服务器所在区域"
        Name = "sql-ama-dcr"
        DataCollectionEndpointId = "/subscriptions/你的订阅ID/resourceGroups/你的资源组名称/providers/Microsoft.Insights/dataCollectionEndpoints/你的数据收集端点"
        DataSources = @{
            SqlServerAuditLogs = @(@{
                Name = "SqlAuditLogs"
                SubscriptionId = "你的订阅ID"
                ResourceGroupName = "你的资源组名称"
                ServerName = "你的SQL服务器名称"
                State = "Enabled"
            })
        }
        Destinations = @{
            LogAnalytics = @(@{
                WorkspaceResourceId = "/subscriptions/你的订阅ID/resourceGroups/你的资源组名称/providers/Microsoft.OperationalInsights/workspaces/你的日志分析工作区"
            })
        }
    }
    New-AzDataCollectionRule @dcrParams
    
    # 关联DCR到SQL服务器
    New-AzDataCollectionRuleAssociation -ResourceId "/subscriptions/你的订阅ID/resourceGroups/你的资源组名称/providers/Microsoft.Sql/servers/你的SQL服务器名称" -AssociationName "sql-ama-assoc" -DataCollectionRuleId "/subscriptions/你的订阅ID/resourceGroups/你的资源组名称/providers/Microsoft.Insights/dataCollectionRules/sql-ama-dcr"
    

3. 是否可以通过PowerShell获取Defender for Servers中现有的agentless scanning、endpoint protection以及Log Analytics agent配置?

可以,分别使用以下命令获取对应配置:

  • 获取Agentless扫描配置:
    Get-AzSecuritySetting -Name "AgentlessVulnerabilityAssessment"
    
  • 获取Endpoint Protection自动部署配置:
    Get-AzSecurityAutoProvisioningSetting -Name "default"
    
  • 获取Log Analytics Agent配置:
    # 获取Log Analytics Agent自动部署设置
    Get-AzSecurityAutoProvisioningSetting -Name "default" | Select-Object AutoProvision, LogAnalyticsWorkspaceId
    
    # 查看特定虚拟机的代理关联状态
    Get-AzResource -ResourceType "Microsoft.Compute/virtualMachines" -Name "你的虚拟机名称" -ResourceGroupName "你的资源组名称" | Get-AzLogAnalyticsWorkspaceAssociation
    

内容的提问来源于stack exchange,提问作者Narendra

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.07.02 11:11:24