How to Remove Duplicate Ephemeral Hosts in Defender for Cloud
Question details
The user needs to identify and remove duplicate ephemeral host entries in Microsoft Defender for Cloud to fix distorted coverage metrics.

- Product
- Microsoft Defender for Cloud
- Device & OS
- not provided
- Scenario
- Managing virtual machine instances and onboarding configurations in Microsoft Azure cloud environments.
- Observed behavior
- Duplicate ephemeral hosts are appearing in the portal, likely caused by inconsistent hardware UUIDs, VM agent identity issues, or stale onboarding records.
Ensure you have administrative access to the Azure portal and permissions to view virtual machine hardware UUIDs and VM agent logs.
Verify Virtual Machine Agent and Host Identity
Confirm whether the entries are actual duplicates rather than separate virtual machines by inspecting their configurations and agent identities.
Duplicate metrics often result from onboarding scripts that regenerate identities rather than reusing them. Validating the UUIDs ensures you do not accidentally target active machines.
Log in to the Microsoft Defender for Cloud portal and compare the hardware UUIDs of the suspected duplicate instances.
Review the installation files and running state of the Linux VM agent on the affected instances to ensure the host identity is properly configured and persistent.
Check your automated onboarding scripts to confirm they are not inadvertently generating multiple stale records when an ephemeral host is restarted or updated.

Submit a Support Request for Reconciliation
If you have corrected the agent configurations but stale duplicate records persist, you must contact Microsoft Support to safely remove them.
Manage Cloud Security Reports and Logs with WPS Office
While troubleshooting Microsoft Defender for Cloud duplicate issues, you may need to export diagnostic logs, analyze CSV metrics, and document your cloud infrastructure. WPS Office provides a free, lightweight, and highly compatible alternative to Microsoft Office for all your data analysis and documentation tasks.
- 1. Download and Install WPS: Get WPS Office for free from the official website and follow the installation wizard to set it up on your workstation.
- 2. Open Exported Azure Logs: Launch WPS Spreadsheet and open the CSV or XLSX logs you exported from the Microsoft Defender for Cloud portal.
- 3. Analyze and Filter Duplicate Data: Use built-in data filters, conditional formatting, and pivot tables to quickly identify and organize duplicate hardware UUIDs.

Frequently Asked Questions
Why do duplicate ephemeral hosts appear in Microsoft Defender for Cloud?
Duplicates usually occur due to inconsistent hardware UUIDs, virtual machine agent identity configuration errors, or stale onboarding records generated when ephemeral nodes are frequently spun up and down.
Is it safe to manually delete a duplicate host record in the portal?
No, you should not manually delete records unless the Defender for Cloud portal provides an officially supported removal option for that exact entry. Incorrect deletion can lead to tracking issues.
What information should I include when opening a support ticket for duplicate hosts?
To expedite resolution, provide the host names, hardware UUIDs, your subscription details, the exact timestamps when the duplicates were noticed, and the corresponding VM agent logs.




