How to Inventory and Patch Azure VM Extensions and Management Agents
Retrospective: this article looks back at events from September 2021, written in 2026 with the benefit of hindsight.
Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.
Step 1: Inventory extensions
List extensions on every VM with Azure Resource Graph:
Resources
| where type == "microsoft.compute/virtualmachines/extensions"
| extend vmName = tostring(split(id, "/")[8])
| project vmName, name, publisher = properties.publisher, type = properties.type,
version = properties.typeHandlerVersion, autoUpgrade = properties.enableAutomaticUpgrade
Do the same for Arc-enabled servers (microsoft.hybridcompute/machines/extensions).
Step 2: Remove what you don't need
Old monitoring agents (such as the legacy Log Analytics agent, retired by Microsoft in favor of the Azure Monitor Agent) and unused extensions should be removed.
Step 3: Enable automatic upgrades
Set automatic extension upgrade (enableAutomaticUpgrade) where supported, so Microsoft can roll out security fixes. Use Azure Policy to audit extensions without automatic upgrade enabled.
Step 4: Scan for vulnerabilities
Defender for Servers vulnerability assessment covers installed software, including agents such as OMI. Track findings by CVE.
Step 5: Restrict management ports
Ensure NSGs block inbound access to management ports used by agents (for OMI, ports 5985, 5986 and 1270) from the internet and from unnecessary networks.
Step 6: Control who can deploy extensions
Extensions such as Custom Script and VM Access run code with high privilege. Restrict the Microsoft.Compute/virtualMachines/extensions/write permission and alert on its use.
Verify
Monthly report of extensions by type and version, with outdated versions flagged.
- OMIGOD (Sept 2021): Hidden Azure Agents Running as Root Incident Teardowns
- Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL Detection & Response
- CIO Brief: The Software Your Cloud Provider Installs on Your Servers CIO Briefings