Skip to main content

Microsoft Defender for Cloud

Microsoft Defender for Cloud is Azure's posture management and threat protection service: it scores configuration against security recommendations and raises alerts from per-resource-type protection plans. The Azure Enterprise Baseline sets every plan explicitly in every subscription and sends all of its data to one security workspace in acme-core-security.

What it does​

The free foundational posture management evaluates resources against the Microsoft cloud security benchmark and produces recommendations and a secure score. Paid Defender plans add threat protection per resource type: containers, storage, Key Vault, Resource Manager, servers, databases, APIs, and Defender CSPM (cloud security posture management) for attack paths and permissions analysis. Plans are enabled per subscription, in the Standard tier, or left Free. A plan raises security alerts with a severity from Informational to High (and Critical for some detections). Continuous export streams alerts, recommendations, regulatory compliance and secure score to a Log Analytics workspace.

How BuiltForProd uses it​

The plans come from one place, environments/core/security/security.hcl, which every subscription's baseline reads:

Azure/acme-azure-platform-baseline/environments/core/security/security.hcl (lines 14-25)
# Microsoft Defender for Cloud plans applied to EVERY subscription (prices per month, eastus2).
defender_plans = { # @optional: one switch per plan
containers = true # ~$7 per vCore of AKS nodes; runtime threat detection + ACR image scanning
storage = true # $10 per storage account; activity and sensitive-data threat detection
key_vaults = true # $0.02 per 10k operations
arm = true # ~$4 per million management operations
servers = false # $15 per server (P2); no VMs in the baseline
cosmosdbs = false # Cosmos DB RU accounts only (vCore is not covered)
cspm = false # Defender CSPM: attack paths, CIEM (~$5 per billable resource)
api = false # API Management only
}
defender_storage_malware_scanning = false # @optional: on-upload malware scanning ($0.15/GB scanned)

The subscription-baseline unit (modules/subscription-baseline/defender.tf) writes all eight plans in every subscription, Standard when switched on and Free otherwise, so a plan changed by hand in the portal shows up as drift in the next plan. Storage uses the DefenderForStorageV2 subplan, and on-upload malware scanning is added only with defender_storage_malware_scanning = true (capped at 5,000 GB per account per month). Prices are list prices as the switch file states them. Defender for Containers also scans the images in the platform's container registry.

Each subscription also gets:

  • the security contact from security_alert_email, with alert notifications on, once the mailbox is set;
  • the security workspace setting, pointing Defender's data at law-acme-eus2-security-security in acme-core-security;
  • a continuous export automation, acme-defender-export (observability-link, enable_defender_export = true), that sends alerts, recommendations, regulatory compliance and secure score to that workspace, so the whole tenant is visible from one place.

In the security workspace, the scheduled query rule acme-defender-high-severity (observability-sink) runs every five minutes over the SecurityAlert table and fires on any alert of severity High or Critical, routing it to the ag-acme-security-alerts action group, the single route by which every security alert of the platform reaches people. The same workspace is where Microsoft Sentinel is onboarded when it is switched on, and a data-export rule keeps a long-term copy of the security tables in the immutable audit storage.

The regulatory compliance view shows the initiatives that Azure Policy assigns, the custom BuiltForProd-soc2-baseline and the Microsoft cloud security benchmark by default.

Terms you will see​

TermMeaning
Defender planPaid threat protection for one resource type, enabled per subscription.
Standard, FreeThe two tiers a plan can be set to; the Baseline writes one or the other explicitly.
RecommendationA configuration finding from posture management.
Security alertA threat detection from a plan, with a severity.
Continuous exportThe automation that streams Defender data to a workspace.
Secure scoreThe posture score computed from recommendations.

Where to read more​