AzureHow-To & HardeningRetrospectives

How to Inventory and Patch Azure VM Extensions and Management Agents

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from September 2021, written in 2026 with the benefit of hindsight.

Azure VM extensions and management agents add capabilities — and attack surface. Here is how to inventory and patch them.

Step 1: Inventory extensions

List extensions on every VM with Azure Resource Graph:

Resources
| where type == "microsoft.compute/virtualmachines/extensions"
| extend vmName = tostring(split(id, "/")[8])
| project vmName, name, publisher = properties.publisher, type = properties.type,
    version = properties.typeHandlerVersion, autoUpgrade = properties.enableAutomaticUpgrade

Do the same for Arc-enabled servers (microsoft.hybridcompute/machines/extensions).

Step 2: Remove what you don't need

Old monitoring agents (such as the legacy Log Analytics agent, retired by Microsoft in favor of the Azure Monitor Agent) and unused extensions should be removed.

Step 3: Enable automatic upgrades

Set automatic extension upgrade (enableAutomaticUpgrade) where supported, so Microsoft can roll out security fixes. Use Azure Policy to audit extensions without automatic upgrade enabled.

Step 4: Scan for vulnerabilities

Defender for Servers vulnerability assessment covers installed software, including agents such as OMI. Track findings by CVE.

Step 5: Restrict management ports

Ensure NSGs block inbound access to management ports used by agents (for OMI, ports 5985, 5986 and 1270) from the internet and from unnecessary networks.

Step 6: Control who can deploy extensions

Extensions such as Custom Script and VM Access run code with high privilege. Restrict the Microsoft.Compute/virtualMachines/extensions/write permission and alert on its use.

Verify

Monthly report of extensions by type and version, with outdated versions flagged.

azure vm extension securityOMIGOD2021

More on this story