Forum Discussion

nopenuttn's avatar
nopenuttn
Copper Contributor
Jun 30, 2025

File Integrity Monitoring - Agentless Issues in Detecting Changes to Files

Hello!

Looks like there have been some recent updates made to File Integrity Monitoring.  After reviewing the MS documentation https://learn.microsoft.com/en-us/azure/defender-for-cloud/file-integrity-monitoring-overview#recommended-items-to-monitor it looks like you can now create custom Rules for Files and for custom Registry keys.  From what I can gather from the documentation, agentless scans are used for custom rules that you create and an agentless scan occurs once every 24 hours.

I have created several custom rules to detect if a file has been Deleted, Added, Modified or Renamed and Defender for Cloud is still not detecting any changes.  I have made changes to these files 3 days ago, and no changes have been reported back.  Any ideas why this might not be working.  I have already confirmed that the appropriate RBAC Roles have been assigned to my Key Vaults where CMK Disks are being used.

I also wanted to know if the Agentless FIM can monitor Folders / Directories as well.  I haven't seen anything about this in the documentation.  Is this even supported?

No RepliesBe the first to reply

Resources