Azure Defender is a cloud workload protection service that utilizes and agent-based deployment to analyze signals from Azure network fabric and the service control plane, to detect threats across all Azure resources. It can also analyze non-Azure resources, utilizing Azure Arc, including those on-premises and in both AWS and GCP (once they’ve been onboarded). Azure Defender for container registries includes a vulnerability scanner to scan the images in Azure Resource Manager-based Azure Container Registry registries and provide deeper visibility image vulnerabilities.
Not enabling defender for container registries could lead to compromised account
Enable ContainerRegistry in Azure Defender
The following example will fail the azure-security-center-defender-on-container-registry check.
The following example will pass the azure-security-center-defender-on-container-registry check.