Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2024)

Edit

Share via

One of Microsoft Defender for Cloud's main pillars is cloud security posture management (CSPM). CSPM provides detailed visibility into the security state of your assets and workloads, and provides hardening guidance to help you efficiently and effectively improve your security posture.

Defender for Cloud continually assesses your resources against security standards that are defined for your Azure subscriptions, AWS accounts, and GCP projects. Defender for Cloud issues security recommendations based on these assessments.

By default, when you enable Defender for Cloud on an Azure subscription, the Microsoft Cloud Security Benchmark (MCSB) compliance standard is turned on. It provides recommendations. Defender for Cloud provides an aggregated secure score based on some of the MCSB recommendations. The higher the score, the lower the identified risk level.

CSPM features

Defender for Cloud provides the following CSPM offerings:

  • Foundational CSPM - Defender for Cloud offers foundational multicloud CSPM capabilities for free. These capabilities are automatically enabled by default for subscriptions and accounts that onboard to Defender for Cloud.

  • Defender Cloud Security Posture Management (CSPM) plan - The optional, paid Defender for Cloud Secure Posture Management plan provides more, advanced security posture features.

Plan availability

Learn more about Defender CSPM pricing.

The following table summarizes each plan and their cloud availability.

FeatureFoundational CSPMDefender CSPMCloud availability
Security recommendationsCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (1)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2)Azure, AWS, GCP, on-premises
Asset inventoryCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (3)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (4)Azure, AWS, GCP, on-premises
Secure scoreCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (5)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (6)Azure, AWS, GCP, on-premises
Data visualization and reporting with Azure WorkbooksCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (7)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (8)Azure, AWS, GCP, on-premises
Data exportingCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (9)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (10)Azure, AWS, GCP, on-premises
Workflow automationCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (11)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (12)Azure, AWS, GCP, on-premises
Tools for remediationCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (13)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (14)Azure, AWS, GCP, on-premises
Microsoft Cloud Security BenchmarkCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (15)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (16)Azure, AWS, GCP
AI security posture management-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (17)Azure, AWS
Agentless VM vulnerability scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (18)Azure, AWS, GCP
Agentless VM secrets scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (19)Azure, AWS, GCP
Attack path analysis-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (20)Azure, AWS, GCP
Risk prioritization-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (21)Azure, AWS, GCP
Risk hunting with security explorer-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (22)Azure, AWS, GCP
Code-to-cloud mapping for containers-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (23)GitHub, Azure DevOps
Code-to-cloud mapping for IaC-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (24)Azure DevOps
PR annotations-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (25)GitHub, Azure DevOps
Internet exposure analysis-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (26)Azure, AWS, GCP
External attack surface management-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (27)Azure, AWS, GCP
Permissions Management (CIEM)-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (28)Azure, AWS, GCP
Regulatory compliance assessments-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (29)Azure, AWS, GCP
ServiceNow Integration-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (30)Azure, AWS, GCP
Critical assets protection-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (31)Azure, AWS, GCP
Governance to drive remediation at-scale-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (32)Azure, AWS, GCP
Data security posture management (DSPM), Sensitive data scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (33)Azure, AWS, GCP1
Agentless discovery for Kubernetes-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (34)Azure, AWS, GCP
Custom Recommendations-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (35)Azure, AWS, GCP
Agentless code-to-cloud containers vulnerability assessment-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (36)Azure, AWS, GCP

1: GCP sensitive data discovery only supports Cloud Storage.

Note

Starting March 7, 2024, Defender CSPM must be enabled to have premium DevOps security capabilities that include code-to-cloud contextualization powering security explorer and attack paths and pull request annotations for Infrastructure-as-Code security findings. See DevOps security support and prerequisites to learn more.

Integrations

Microsoft Defender for Cloud now has built-in integrations to help you use third-party systems to seamlessly manage and track tickets, events, and customer interactions. You can push recommendations to a third-party ticketing tool, and assign responsibility to a team for remediation.

Integration streamlines your incident response process, and improves your ability to manage security incidents. You can track, prioritize, and resolve security incidents more effectively.

You can choose which ticketing system to integrate. For preview, only ServiceNow integration is supported. For more information about how to configure ServiceNow integration, see Integrate ServiceNow with Microsoft Defender for Cloud (preview).

Plan pricing

  • Review the Defender for Cloud pricing page to learn about Defender CSPM pricing.

  • From March 7, 2024, advanced DevOps security posture capabilities will only be available through the paid Defender CSPM plan. Free foundational security posture management in Defender for Cloud will continue providing a number of Azure DevOps recommendations. Learn more about DevOps security features.

  • For subscriptions that use both Defender CSPM and Defender for Containers plans, free vulnerability assessment is calculated based on free image scans provided via the Defender for Containers plan, as summarized in the Microsoft Defender for Cloud pricing page.

  • Defender CSPM protects all multicloud workloads, but billing is applied only on specific resources. The following tables list the billable resources when Defender CSPM is enabled on Azure subscriptions, AWS accounts, or GCP projects.

    Azure ServiceResource typesExclusions
    ComputeMicrosoft.Compute/virtualMachines
    Microsoft.Compute/virtualMachineScaleSets/virtualMachines
    Microsoft.ClassicCompute/virtualMachines
    - Deallocated VMs
    - Databricks VMs
    StorageMicrosoft.Storage/storageAccountsStorage accounts without blob containers or file shares
    DBsMicrosoft.Sql/servers
    Microsoft.DBforPostgreSQL/servers
    Microsoft.DBforMySQL/servers
    Microsoft.Sql/managedInstances
    Microsoft.DBforMariaDB/servers
    Microsoft.Synapse/workspaces
    ---
    AWS ServiceResource typesExclusions
    ComputeEC2 instancesDeallocated VMs
    StorageS3 Buckets---
    DBsRDS instances---
    GCP ServiceResource typesExclusions
    Compute1. Google Compute instances
    2. Google Instance Group
    Instances with non-running states
    StorageStorage buckets- Buckets from classes: ‘nearline’, ‘coldline’, ‘archive’
    - Buckets from regions other than: europe-west1, us-east1, us-west1, us-central1, us-east4, asia-south1, northamerica-northeast1
    DBsCloud SQL Instances---

Azure cloud support

For commercial and national cloud coverage, review the features supported in Azure cloud environments.

Support for Resource type in AWS and GCP

For multicloud support of resource types (or services) in our foundational multicloud CSPM tier, see the table of multicloud resource and service types for AWS and GCP.

Next steps

Feedback

Was this page helpful?

Ask the community

Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2024)
Top Articles
What Are Financial Ratios? 6 To Track & How To Calculate
How to Prepare for a Global Food Shortage (2023) | Eden Green
English Bulldog Puppies For Sale Under 1000 In Florida
Katie Pavlich Bikini Photos
Gamevault Agent
Pieology Nutrition Calculator Mobile
Hocus Pocus Showtimes Near Harkins Theatres Yuma Palms 14
Hendersonville (Tennessee) – Travel guide at Wikivoyage
Compare the Samsung Galaxy S24 - 256GB - Cobalt Violet vs Apple iPhone 16 Pro - 128GB - Desert Titanium | AT&T
Vardis Olive Garden (Georgioupolis, Kreta) ✈️ inkl. Flug buchen
Craigslist Dog Kennels For Sale
Things To Do In Atlanta Tomorrow Night
Non Sequitur
Crossword Nexus Solver
How To Cut Eelgrass Grounded
Pac Man Deviantart
Alexander Funeral Home Gallatin Obituaries
Energy Healing Conference Utah
Geometry Review Quiz 5 Answer Key
Hobby Stores Near Me Now
Icivics The Electoral Process Answer Key
Allybearloves
Bible Gateway passage: Revelation 3 - New Living Translation
Yisd Home Access Center
Pearson Correlation Coefficient
Home
Shadbase Get Out Of Jail
Gina Wilson Angle Addition Postulate
Celina Powell Lil Meech Video: A Controversial Encounter Shakes Social Media - Video Reddit Trend
Walmart Pharmacy Near Me Open
Marquette Gas Prices
A Christmas Horse - Alison Senxation
Ou Football Brainiacs
Access a Shared Resource | Computing for Arts + Sciences
Vera Bradley Factory Outlet Sunbury Products
Pixel Combat Unblocked
Movies - EPIC Theatres
Cvs Sport Physicals
Mercedes W204 Belt Diagram
Mia Malkova Bio, Net Worth, Age & More - Magzica
'Conan Exiles' 3.0 Guide: How To Unlock Spells And Sorcery
Teenbeautyfitness
Where Can I Cash A Huntington National Bank Check
Topos De Bolos Engraçados
Sand Castle Parents Guide
Gregory (Five Nights at Freddy's)
Grand Valley State University Library Hours
Hello – Cornerstone Chapel
Stoughton Commuter Rail Schedule
Nfsd Web Portal
Selly Medaline
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6132

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.