logo
search
Others

How to Remove Duplicate Ephemeral Hosts in Defender for Cloud

WPS Content ManagerWPS Content Manager Sep 28, 2026 869 views

Question details

The user needs to identify and remove duplicate ephemeral host entries in Microsoft Defender for Cloud to fix distorted coverage metrics.

How to Remove Duplicate Ephemeral Hosts in Defender for Cloud
Product
Microsoft Defender for Cloud
Device & OS
not provided
Scenario
Managing virtual machine instances and onboarding configurations in Microsoft Azure cloud environments.
Observed behavior
Duplicate ephemeral hosts are appearing in the portal, likely caused by inconsistent hardware UUIDs, VM agent identity issues, or stale onboarding records.
Before you start

Ensure you have administrative access to the Azure portal and permissions to view virtual machine hardware UUIDs and VM agent logs.

Solution 1Recommended

Verify Virtual Machine Agent and Host Identity

Confirm whether the entries are actual duplicates rather than separate virtual machines by inspecting their configurations and agent identities.

Duplicate metrics often result from onboarding scripts that regenerate identities rather than reusing them. Validating the UUIDs ensures you do not accidentally target active machines.

1
Check Hardware UUIDs

Log in to the Microsoft Defender for Cloud portal and compare the hardware UUIDs of the suspected duplicate instances.

2
Inspect Linux VM Agent Installation

Review the installation files and running state of the Linux VM agent on the affected instances to ensure the host identity is properly configured and persistent.

3
Review Onboarding Configuration

Check your automated onboarding scripts to confirm they are not inadvertently generating multiple stale records when an ephemeral host is restarted or updated.

Verify Virtual Machine Agent and Host Identity
Manual Deletion Warning: Do not attempt to manually delete records in the portal unless a supported removal or deletion option is explicitly provided for that specific entry.
Free Microsoft Office alternative

Manage Cloud Security Reports and Logs with WPS Office

While troubleshooting Microsoft Defender for Cloud duplicate issues, you may need to export diagnostic logs, analyze CSV metrics, and document your cloud infrastructure. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for all your data analysis and documentation tasks.

  1. 1. Download and Install WPS: Get WPS Office for free from the official website and follow the installation wizard to set it up on your workstation.
  2. 2. Open Exported Azure Logs: Launch WPS Spreadsheet and open the CSV or XLSX logs you exported from the Microsoft Defender for Cloud portal.
  3. 3. Analyze and Filter Duplicate Data: Use built-in data filters, conditional formatting, and pivot tables to quickly identify and organize duplicate hardware UUIDs.
Fully compatible with Microsoft Excel (.xlsx) and CSV formats, perfect for analyzing exported Azure security logs.Lightweight architecture ensures fast loading and smooth performance even with massive cloud metric datasets.Familiar user interface allows for a seamless transition from Microsoft Office without a learning curve.Built-in PDF toolkit makes it easy to document and share support request details with your engineering team.
microsoft office alternative - wps office

Frequently Asked Questions

Why do duplicate ephemeral hosts appear in Microsoft Defender for Cloud?

Duplicates usually occur due to inconsistent hardware UUIDs, virtual machine agent identity configuration errors, or stale onboarding records generated when ephemeral nodes are frequently spun up and down.

Is it safe to manually delete a duplicate host record in the portal?

No, you should not manually delete records unless the Defender for Cloud portal provides an officially supported removal option for that exact entry. Incorrect deletion can lead to tracking issues.

What information should I include when opening a support ticket for duplicate hosts?

To expedite resolution, provide the host names, hardware UUIDs, your subscription details, the exact timestamps when the duplicates were noticed, and the corresponding VM agent logs.