Azure Update Manager support for CIS-Hardened Images (Windows)

CelsoScarpim 15 Reputation points
2024-05-07T03:30:29.24+00:00

Hello there,

Any further update on support for CIS hardened images (Windows 2019/2022) in Azure Update Manager?

What's the recommended action if the deadline arrives and the support is not ready?

I saw somewhere else a possible option that would include using a non-cis image, enrolling it in the new Update Management Service, and then using the CIS scripts to harden the image. Is that possible/feasible/supported?

Thanks in advance.

Azure Automation
Azure Automation
An Azure service that is used to automate, configure, and install updates across hybrid environments.
1,157 questions
Azure Update Manager
Azure Update Manager
An Azure service to centrally manages updates and compliance at scale.
261 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Nikhil Mengaram 20 Reputation points Microsoft Employee
    2024-05-16T05:58:51.9733333+00:00

    Hi CelsoScarpim,

    Update manager team is working on supporting CIS hardened images in marketplace, as of now there is no ETA as validations are being made.

    It is possible to use Update manager on a marketplace vm and then harden it using scripts. Note that in this case Update manager can be used but this scenario is unsupported as currently Azure Update Manager doesn't support hardened images.

    0 comments No comments