Defender for Cloud Inventory cannot show which lock-lab application owns each virtual machine during incident review. Which asset-management control should the security engineer apply first?
Select an answer to reveal the explanation.
Short Explanation
Inventory is only as smart as the labels on the crates. Force owner, data class, and environment tags with Policy at the management group so the lock-lab fleet stops showing up as mystery boxes.
Full Explanation
Required or inherited tags enforced by Azure Policy are a primary asset-management security control that feeds Defender for Cloud Inventory and incident ownership. Renaming resources or disabling Inventory does not create durable metadata. Suppressing tag-related recommendations hides the gap instead of fixing governance.