Defender for Cloud: Container Registry vulnerability assessment findings missing (shows "0 out of 0 scanned")

Bakhti Baymukhamedov 0 Reputation points
2026-08-10T12:16:38.38+00:00

Hi Team,

We are experiencing an issue where vulnerability findings for Azure Container Registry (ACR) images are no longer populated in Microsoft Defender for Cloud.

Up until last week, all container image vulnerabilities were properly scanned, visible, and mapped to tags under the recommendation "Azure registry container i

mages should have vulnerabilities resolved".

Currently, the recommendation shows:

  • Unhealthy registries: 0 / 0
  • Total vulnerable images: 0 (Out of 0 scanned)
  • Total vulnerabilities: 0

Configuration Status:

  1. Microsoft Defender for Containers plan is turned ON for the subscription.
  2. In Settings & Monitoring, "Registry access" (agentless vulnerability assessment for registry images) is set to ON.
  3. Images are present in our ACR but no scan results or tabs are showing up either in Defender for Cloud or directly on the image tag blades in ACR.

Could you please check if there is a known issue or sync delay related to the Defender Vulnerability Management engine transition?

Screenshot attached. Thanks!vulnerabilities_page

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Most helpful
  1. AI answer

    2026-08-10T12:16:57.5333333+00:00

    The supported checks for this symptom are:

    1. Verify that the subscription has Defender for Containers or Defender CSPM enabled, and that Registry access is turned on for the relevant scope. Registry vulnerability assessment requires Registry access to be enabled.
    2. In the Azure portal, go to Microsoft Defender for Cloud > Environment settings > select the subscription > Settings, and confirm the registry image vulnerability assessment capability is enabled.
    3. In Microsoft Defender for Cloud > Recommendations, use the Vulnerabilities category, switch to Flat list, add the Resource type filter, and select Container Image. This is the supported view for registry image findings.
    4. Allow for scan latency. Defender for Cloud notes that some assessment scans can take up to 24 hours to reflect in the dashboard.

    For the exact scenario where findings for ACR images are missing even though registry scanning is enabled, the documented guidance is to open a support case and provide:

    • registry name
    • image name
    • image digest
    • expected finding details

    The available documentation does not confirm a known issue or a specific sync problem related to the Defender Vulnerability Management engine transition.


    AI-generated content may be incorrect. Read our transparency notes for more information.

    Was this answer helpful?

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.