Microsoft Defender for Cloud: CSPM, CWPP and Rollout Guide

Learn what Microsoft Defender for Cloud does, how Foundational and Defender CSPM differ, and a practical rollout plan for Azure, AWS and GCP.
Microsoft Defender for Cloud is Azure's cloud-native application protection platform (CNAPP). It scans your Azure, AWS, and GCP environments for misconfigurations (posture management, or CSPM), then protects running workloads such as servers, containers, storage, and databases with optional paid plans (workload protection, or CWPP).
If you are building a career in cloud security, this is one of the most useful Microsoft tools to understand. It sits at the center of the Azure security stack, and it is also a practical example of how modern security teams manage risk across several clouds at once.
What Defender for Cloud actually does
According to Microsoft Learn, Defender for Cloud has three core components:
- Cloud Security Posture Management (CSPM): checks and improves the security posture of your cloud resources.
- DevSecOps: manages code-level security across multicloud and multi-pipeline environments, including GitHub, Azure DevOps, and GitLab.
- Cloud Workload Protection Platform (CWPP): defends workloads such as virtual machines, containers, storage, databases, and serverless functions from threats.
Think of it this way. CSPM answers the question "is my environment configured safely?" CWPP answers "is something attacking my workloads right now?" DevSecOps answers "are we shipping risk from code and pipelines?"
Defender for Cloud also covers generative AI workloads with AI security posture management and AI threat protection, which matters as more companies deploy AI apps on Azure, AWS, and GCP. If you want to go deeper on that side, read our guide to AI platform security on Bedrock, Azure AI, and Vertex AI.
Foundational CSPM vs Defender CSPM
This is the first decision most teams face, and the first question that comes up in interviews. Defender for Cloud includes a free tier called Foundational CSPM and a paid plan called Defender CSPM.
| Capability | Foundational CSPM (free) | Defender CSPM (paid) |
|---|---|---|
| Asset inventory | Yes | Yes |
| Security recommendations (Microsoft cloud security benchmark) | Yes | Yes |
| Secure score | Yes | Yes |
| Multicloud connectors (AWS, GCP) | Yes | Yes |
| Workflow automation and data export | Yes | Yes |
| Attack path analysis | No | Yes |
| Cloud security explorer | No | Yes |
| Governance rules (assign owners and deadlines) | No | Yes |
| Agentless VM vulnerability and secrets scanning | No | Yes |
| Data security posture management | No | Yes (also via Defender for Storage) |
| AI security posture management | No | Yes |
Feature availability changes often, so always confirm against the current Microsoft Learn documentation for Defender for Cloud before you design a deployment or quote a plan to a client. Pricing is published on the Azure pricing page and can be estimated with Microsoft's cost calculator, so we will not quote numbers here.
Secure score and recommendations
Defender for Cloud continually assesses your resources against the Microsoft cloud security benchmark, a built-in standard that also covers AWS and GCP. Each failed check becomes a recommendation, such as "storage accounts should restrict network access" or "MFA should be enabled for accounts with owner permissions."
The secure score summarizes those findings. As you remediate recommendations, the score improves. A higher score means a lower identified level of risk.
A word of caution for beginners: do not treat the score as the goal. A score is a measurement, not a security outcome. A resource with a critical exposure path matters more than ten low-severity items that move the number. This is where attack path analysis helps.
Attack paths and the cloud security explorer
Attack path analysis, part of the Defender CSPM plan, shows how an attacker could chain together weaknesses to reach a valuable resource. For example, an internet-exposed VM with a known vulnerability, holding a credential with access to a database containing sensitive data, is far more urgent than any one of those findings alone.
The cloud security explorer lets you query your environment like a graph. You can ask questions such as "which internet-exposed VMs have high-severity vulnerabilities and permission to a storage account?" Microsoft has also extended attack paths to cover compromised Microsoft Entra OAuth applications, which links posture work directly to identity risk. If you are still learning that layer, start with our Entra Conditional Access guide.
Workload protection plans (CWPP)
Beyond posture, you enable paid plans for the workloads you actually run. Microsoft lists plans for servers, containers, storage, App Service, databases, Key Vault, Resource Manager, APIs, and AI services. You do not need all of them. Enable what matches your architecture and risk.
| If you run... | Consider |
|---|---|
| Windows and Linux VMs (Azure, AWS, GCP, on-premises) | Defender for Servers |
| Kubernetes and container images | Defender for Containers |
| Blob storage with untrusted uploads | Defender for Storage (malware scanning, sensitive data threat detection) |
| Azure SQL, Cosmos DB, open-source databases | Defender for Databases |
| Secrets in vaults | Defender for Key Vault (see our Azure Key Vault best practices) |
| Public APIs | Defender for APIs |
Alerts from these plans can be exported to a SIEM. Many teams send them to Microsoft Sentinel, which we cover in Microsoft Sentinel: SIEM setup in the Defender portal.
A practical rollout plan
Here is a sensible order for a new environment, whether it is a lab or a client engagement:
- Inventory and scope. List subscriptions, AWS accounts, and GCP projects. Decide who owns each one.
- Enable Foundational CSPM everywhere. It is free and gives you asset inventory, recommendations, and secure score on day one.
- Connect AWS and GCP. Use the multicloud connectors so you have one view across providers.
- Triage by risk, not by count. Fix internet exposure, missing MFA, and over-privileged identities first.
- Pilot Defender CSPM on production subscriptions. Note that the Subscription Owner must enable the plan for agentless scanning to work, and that attack path analysis and the explorer will not show vulnerabilities if the agentless scanner is off.
- Add workload plans selectively. Match each plan to a real workload.
- Assign ownership and track. Use governance rules and workflow automation so findings reach the people who can fix them.
- Export and integrate. Send alerts and posture data to your SIEM and ticketing system.
Common mistakes
- Chasing the score. Fixing easy items to move the number while ignoring a real attack path.
- Enabling every plan. This adds cost without matching risk.
- No owner for recommendations. Findings that belong to nobody never get fixed.
- Ignoring multicloud. Teams monitor Azure carefully while AWS and GCP accounts sit unreviewed.
- Treating the tool as the program. Defender for Cloud finds problems. People, processes, and least-privilege design fix them.
That last point connects to fundamentals. Posture tools are most useful when you already understand least privilege in the cloud and common cloud misconfigurations.
How this fits a cloud security career
Hands-on experience with a CNAPP is a strong resume signal. In a lab you can enable Foundational CSPM, connect a second cloud, remediate a handful of recommendations, document before and after secure scores, and write up one attack path you resolved. That makes a good portfolio piece because it shows judgment, not just clicks.
In PrimeSec Academy's 20-week program, you practice this kind of work across Azure, AWS, and GCP in labs, then document it in projects you can show employers. You can review the full curriculum to see where posture management and workload protection fit.
Frequently asked questions
What is Microsoft Defender for Cloud used for? It is used to assess and improve the security posture of cloud resources, and to detect threats against workloads. It supports Azure, AWS, GCP, and hybrid environments, and it combines CSPM, DevSecOps, and workload protection in one platform.
Is Defender for Cloud free? Part of it is. Foundational CSPM is free and includes asset inventory, security recommendations, and secure score. Defender CSPM and the workload protection plans are paid. Check Microsoft's pricing page for current rates.
What is the difference between CSPM and CWPP? CSPM looks for misconfigurations and risky exposure before an attack happens. CWPP protects running workloads such as servers, containers, and databases by detecting active threats. Most mature teams use both.
Can Defender for Cloud protect AWS and GCP? Yes. You can connect AWS accounts and GCP projects to get posture management, and several workload protection plans extend to those clouds. Feature coverage varies, so check the multicloud support matrix on Microsoft Learn.
Is Defender for Cloud on the AZ-500 or SC-500 exam? Defender for Cloud is a core part of Azure security and appears in Microsoft's security learning paths. Exam objectives change, so verify the current skills outline on Microsoft Learn. Our AZ-500 to SC-500 transition guide covers the change.
Do I need Defender CSPM or is the free tier enough? The free tier is a good starting point for visibility. If you need attack path analysis, the cloud security explorer, agentless scanning, or governance workflows, you need the paid Defender CSPM plan. Start free, then pilot the paid plan on your most critical subscriptions.
Build the skills, not just the knowledge
Reading about Defender for Cloud helps. Operating it in a real lab environment is what gets you hired. If you want a structured path with labs, projects, and a defended capstone, see the PrimeSec Academy curriculum or enroll today.
