CIO Brief: The Software Your Cloud Provider Installs on Your Servers
Retrospective: this article looks back at events from September 2021, written in 2026 with the benefit of hindsight.
The short version: In 2021, researchers found serious flaws in a management program Microsoft quietly installed on many Linux servers in Azure. Many customers didn't know it was there, so they didn't know they needed to update it.
Why hidden software matters
Cloud providers install agents on your servers to provide monitoring, backup and management features. Those agents often run with full administrator rights. If they have flaws, your servers are exposed — even if you diligently patch everything you know about.
The business impact
- Exposure you didn't know existed.
- Unclear responsibility between you and the provider for updates.
- Potential full server compromise from a single agent flaw.
Questions to ask your team
- Do we have a complete list of software running on our cloud servers, including provider-installed agents?
- Are those agents set to update automatically?
- Which management ports are open on our servers, and to whom?
What good looks like
A full software inventory per server, automatic updates for provider agents where available, vulnerability scanning that includes agents, and management ports closed to the internet.
The decision
Ask your team to confirm that vulnerability scanning covers all installed software — not just the operating system — on your cloud servers.
- OMIGOD (Sept 2021): Hidden Azure Agents Running as Root Incident Teardowns
- How to Inventory and Patch Azure VM Extensions and Management Agents How-To & Hardening
- Detecting VM Agent Exploitation: Defender for Cloud and Sentinel KQL Detection & Response