CNAPP / CSPM / Microsoft

Microsoft Defender for Cloud

Microsoft Defender for Cloud combines cloud posture, development-related security and workload protection. Its AWS and Google Cloud connectors extend selected capabilities beyond Azure. For a beginner, the key lesson is that connecting a cloud account for configuration visibility does not automatically install or enable every workload protection component.

Native Azure and multicloud CNAPPResearch reviewed

What you are evaluating

Foundational posture, paid Defender CSPM and workload-specific Defender plans have different coverage and billing. Some workload protections need Azure Arc or sensors; other service protections use cloud integrations. Map dependencies separately for each selected plan.

A useful evaluation context

A Microsoft-centered security team can evaluate cloud findings alongside its existing incident processes while checking each cloud’s feature matrix.

Documented capabilities

The vendor describes these capabilities in the linked sources. Availability depends on the product edition and supported environment.

  • Posture capabilities assess cloud configuration, with paid features adding graph, attack-path and data-aware context where supported.
  • Development security connects selected repository and pipeline findings to the cloud-security workflow.
  • Workload plans protect specified servers, containers, storage, databases and other supported services through their applicable collection methods.

Where it fits in the work

  1. Choose one Azure subscription and any required external-cloud lab connector, documenting its permissions and selected plans.
  2. Compare the inventory with known test resources, then distinguish configuration findings from signals that require an additional workload component.
  3. Route a synthetic finding to the responsible application owner and verify its correction without enabling unrelated paid plans.

APPLY THE IDEA / ILLUSTRATIVE EXERCISE

Make the outcome observable.

Connect a lab subscription for posture and separately onboard one supported workload using the documented protection plan.

Evidence to look for

The inventory distinguishes the two coverage states, and a benign documented test produces the expected signal only from the enabled control.

Use synthetic data and an authorized test environment. Agree the scope and recovery steps before enabling enforcement.

Questions for your evaluation

  1. Which requested functions belong to foundational posture, Defender CSPM or a workload plan?
  2. What agent, Arc connection or service integration does each workload actually require?
  3. How will the team see a disconnected connector or missing sensor before assuming a workload is covered?

Find your next idea.

Tip: press / to open search. Escape closes this window.