Skip to main content
Plerion scans the Azure workload types below when the matching option is enabled in the subscription’s workload scanning settings, except AKS and Azure Red Hat OpenShift, which are scanned by the Kubernetes integration. Each scan produces vulnerability, sensitive data and SBOM results on the workload’s asset, and a publicly exposed workload with high or critical vulnerabilities also produces an attack path finding (PLERION-AZURE-446).

Scanned workload types

Not scanned

Permissions

The permissions each workload type needs are granted by the CWPP install script. See Azure CWPP architecture for the full list.