Microsoft Defender for Cloud is a security platform that helps organizations check their security, find risks, and protect cloud workloads on Azure, Amazon Web Services (AWS), Google Cloud, and other connected environments.
-
Cloud Security Posture Management (CSPM): Finds security misconfigurations, gives recommendations, and helps organizations fix the most important issues first.
- Cloud Workload Protection Platform (CWPP): Offers threat protection for specific workloads like servers, containers, databases, and storage, based on the protection plans you choose.
Key Features
- Secure Score: It checks your cloud setup and finds any weaknesses or misconfigurations.
- Security Recommendations: You get clear, step-by-step actions to fix issues, like turning on MFA or closing open ports.
- Threat Protection Plans: Defender offers dedicated plans for App Service, Containers, Servers, Storage, Databases, Key Vault, and APIs.
- Regulatory Compliance: You get a dashboard that compares your setup to standards like ISO 27001, PCI DSS, and the Microsoft cloud security benchmark.
- Attack Path Analysis: This feature shows how an attacker might move from a weak spot to your most important resources.
- DevOps Security: It scans code in GitHub, Azure DevOps, and GitLab before the code goes live.
Examples
- Secure Storage Accounts: Your storage account allows unnecessary public access. Defender for Cloud recommends reviewing your access settings to protect sensitive data.
- Identify Attacks: A virtual machine has excessive permissions that could let an attacker access an exposed database. Microsoft Defender for Cloud can identify the attack path and help the security team prioritize fixes.
- Protect Virtual Machine: A virtual machine is exposed to the internet with an unnecessary port open. Defender for Cloud identifies this risk and recommends limiting access to reduce the chance of an attack.
How to activate
To enable Cloud Security in Defender portal (http://security.microsoft.com) the tenant must have an active paid plan.
To do so, in the Azure Portal, go to Microsoft Defender for Cloud -> Manangement -> Environment settings -> choose an active Azure subscription, i.e. “Microsoft Azure MVP Subscription”

Then, turn on the Defender CSPM plan (the free Foundational CSPM alone does’t count)

Wait a few minutes. Then navigate to https://security.microsoft.com, go to Cloud security -> Overview
![]()
Tap on the “Prepare tenant” button to enable Defender for Cloud in the Defender portal.

After completing tenant preparation, you must wait one or more days for the system to gather logs, depending on the amount of tenant data. For demonstration purposes, I created a demo tenant with two subscriptions.
The following image illustrates the overview page for Cloud security.

