Nota:
El acceso a esta página requiere autorización. Puede intentar iniciar sesión o cambiar directorios.
El acceso a esta página requiere autorización. Puede intentar cambiar los directorios.
Onboard a JFrog Artifactory tenant to Microsoft Defender for Cloud to enable agentless vulnerability assessment for container images.
JFrog Artifactory is supported as an external registry. After onboarding, images are scanned and vulnerability findings are surfaced as recommendations.
Each connector represents a single JFrog Artifactory tenant. To onboard multiple tenants, create a separate connector for each one.
Prerequisites
An Azure subscription with Microsoft Defender for Cloud enabled. If you don't have one, create an Azure account.
Security administrator permissions (or higher) in Microsoft Defender for Cloud.
One of the following plans enabled:
- Defender for Containers
- Defender CSPM
A JFrog Artifactory (Cloud) tenant with administrative access.
Onboard JFrog Artifactory to Defender for Cloud
Sign in to the Azure portal.
Go to Microsoft Defender for Cloud > Environment settings.
Select Add environment > JFrog.
Enter a Connector name.
Select a Location.
Select a Subscription and a Resource group.
Select a Scanning interval.
Enter the Server ID (JFrog Artifactory URL prefix).
Select Next : Select plans >.
Under the Status column, toggle on the relevant plans:
- Foundational CSPM: Inventory only
- Defender for Containers: Inventory and vulnerability assessment
- Defender CSPM: Adds contextual risk signals
Select Next : Configure access >.
Select your operating system.
Download the generated connection script and run it using the JFrog CLI.
Select Next : Review and generate >.
Select Create.
Validate onboarding
After onboarding completes:
Verify the Connectivity status for your JFrog environment shows as Connected in Environment settings.
Verify images from your JFrog Artifactory tenant appear in Inventory in Defender for Cloud.
Verify vulnerability recommendations for your JFrog images appear in Defender for Cloud.
Scanning typically begins within one hour after onboarding.