Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2024)

Edit

Share via

One of Microsoft Defender for Cloud's main pillars is cloud security posture management (CSPM). CSPM provides detailed visibility into the security state of your assets and workloads, and provides hardening guidance to help you efficiently and effectively improve your security posture.

Defender for Cloud continually assesses your resources against security standards that are defined for your Azure subscriptions, AWS accounts, and GCP projects. Defender for Cloud issues security recommendations based on these assessments.

By default, when you enable Defender for Cloud on an Azure subscription, the Microsoft Cloud Security Benchmark (MCSB) compliance standard is turned on. It provides recommendations. Defender for Cloud provides an aggregated secure score based on some of the MCSB recommendations. The higher the score, the lower the identified risk level.

CSPM features

Defender for Cloud provides the following CSPM offerings:

  • Foundational CSPM - Defender for Cloud offers foundational multicloud CSPM capabilities for free. These capabilities are automatically enabled by default for subscriptions and accounts that onboard to Defender for Cloud.

  • Defender Cloud Security Posture Management (CSPM) plan - The optional, paid Defender for Cloud Secure Posture Management plan provides more, advanced security posture features.

Plan availability

Learn more about Defender CSPM pricing.

The following table summarizes each plan and their cloud availability.

FeatureFoundational CSPMDefender CSPMCloud availability
Security recommendationsCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (1)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2)Azure, AWS, GCP, on-premises
Asset inventoryCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (3)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (4)Azure, AWS, GCP, on-premises
Secure scoreCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (5)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (6)Azure, AWS, GCP, on-premises
Data visualization and reporting with Azure WorkbooksCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (7)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (8)Azure, AWS, GCP, on-premises
Data exportingCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (9)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (10)Azure, AWS, GCP, on-premises
Workflow automationCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (11)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (12)Azure, AWS, GCP, on-premises
Tools for remediationCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (13)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (14)Azure, AWS, GCP, on-premises
Microsoft Cloud Security BenchmarkCloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (15)Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (16)Azure, AWS, GCP
AI security posture management-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (17)Azure, AWS
Agentless VM vulnerability scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (18)Azure, AWS, GCP
Agentless VM secrets scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (19)Azure, AWS, GCP
Attack path analysis-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (20)Azure, AWS, GCP
Risk prioritization-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (21)Azure, AWS, GCP
Risk hunting with security explorer-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (22)Azure, AWS, GCP
Code-to-cloud mapping for containers-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (23)GitHub, Azure DevOps
Code-to-cloud mapping for IaC-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (24)Azure DevOps
PR annotations-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (25)GitHub, Azure DevOps
Internet exposure analysis-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (26)Azure, AWS, GCP
External attack surface management-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (27)Azure, AWS, GCP
Permissions Management (CIEM)-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (28)Azure, AWS, GCP
Regulatory compliance assessments-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (29)Azure, AWS, GCP
ServiceNow Integration-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (30)Azure, AWS, GCP
Critical assets protection-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (31)Azure, AWS, GCP
Governance to drive remediation at-scale-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (32)Azure, AWS, GCP
Data security posture management (DSPM), Sensitive data scanning-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (33)Azure, AWS, GCP1
Agentless discovery for Kubernetes-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (34)Azure, AWS, GCP
Custom Recommendations-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (35)Azure, AWS, GCP
Agentless code-to-cloud containers vulnerability assessment-Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (36)Azure, AWS, GCP

1: GCP sensitive data discovery only supports Cloud Storage.

Note

Starting March 7, 2024, Defender CSPM must be enabled to have premium DevOps security capabilities that include code-to-cloud contextualization powering security explorer and attack paths and pull request annotations for Infrastructure-as-Code security findings. See DevOps security support and prerequisites to learn more.

Integrations

Microsoft Defender for Cloud now has built-in integrations to help you use third-party systems to seamlessly manage and track tickets, events, and customer interactions. You can push recommendations to a third-party ticketing tool, and assign responsibility to a team for remediation.

Integration streamlines your incident response process, and improves your ability to manage security incidents. You can track, prioritize, and resolve security incidents more effectively.

You can choose which ticketing system to integrate. For preview, only ServiceNow integration is supported. For more information about how to configure ServiceNow integration, see Integrate ServiceNow with Microsoft Defender for Cloud (preview).

Plan pricing

  • Review the Defender for Cloud pricing page to learn about Defender CSPM pricing.

  • From March 7, 2024, advanced DevOps security posture capabilities will only be available through the paid Defender CSPM plan. Free foundational security posture management in Defender for Cloud will continue providing a number of Azure DevOps recommendations. Learn more about DevOps security features.

  • For subscriptions that use both Defender CSPM and Defender for Containers plans, free vulnerability assessment is calculated based on free image scans provided via the Defender for Containers plan, as summarized in the Microsoft Defender for Cloud pricing page.

  • Defender CSPM protects all multicloud workloads, but billing is applied only on specific resources. The following tables list the billable resources when Defender CSPM is enabled on Azure subscriptions, AWS accounts, or GCP projects.

    Azure ServiceResource typesExclusions
    ComputeMicrosoft.Compute/virtualMachines
    Microsoft.Compute/virtualMachineScaleSets/virtualMachines
    Microsoft.ClassicCompute/virtualMachines
    - Deallocated VMs
    - Databricks VMs
    StorageMicrosoft.Storage/storageAccountsStorage accounts without blob containers or file shares
    DBsMicrosoft.Sql/servers
    Microsoft.DBforPostgreSQL/servers
    Microsoft.DBforMySQL/servers
    Microsoft.Sql/managedInstances
    Microsoft.DBforMariaDB/servers
    Microsoft.Synapse/workspaces
    ---
    AWS ServiceResource typesExclusions
    ComputeEC2 instancesDeallocated VMs
    StorageS3 Buckets---
    DBsRDS instances---
    GCP ServiceResource typesExclusions
    Compute1. Google Compute instances
    2. Google Instance Group
    Instances with non-running states
    StorageStorage buckets- Buckets from classes: ‘nearline’, ‘coldline’, ‘archive’
    - Buckets from regions other than: europe-west1, us-east1, us-west1, us-central1, us-east4, asia-south1, northamerica-northeast1
    DBsCloud SQL Instances---

Azure cloud support

For commercial and national cloud coverage, review the features supported in Azure cloud environments.

Support for Resource type in AWS and GCP

For multicloud support of resource types (or services) in our foundational multicloud CSPM tier, see the table of multicloud resource and service types for AWS and GCP.

Next steps

Feedback

Was this page helpful?

Ask the community

Cloud Security Posture Management (CSPM) - Microsoft Defender for Cloud (2024)
Top Articles
How Much Does It Cost to Deploy a Smart Contract on Ethereum?
Should You Use Your Credit Card Before It Arrives in the Mail?
Bm1 Bus Tracker
Obituary Times Herald Record
Uvalde Topic
Legend Piece Trello
[PDF] Latin America/US Hispanic Media - Free Download PDF
Fantasy Football Week 3: 5 players who could make or break your lineups
Cvs Stage And Covington Pike
683 Job Calls
6100 Steps To Miles
Labcorp | Patient - MyLabCorp
Violent Night Showtimes Near R/C Hanover Movies 16
Facebook Levels Fyi
Hewn New Bedford
Stetson Exam Schedule
WelcHOME Lakeside Holiday Homes - Official Website
Longhorn Steakhouse Hiring Age
Stewartville Star Obituaries
Haul auf deutsch: Was ist das? Übersetzung, Bedeutung, Erklärung - Bedeutung Online
Lorain County Busted Mugshots
8er Reihe Einmaleins - Kostenlose Arbeitsblätter
Zits Comic Arcamax
George Hamilton Deck Commercial
Express Employment Sign In
Nail Salon Goodman Plaza
Freightliner Cascadia d'occasion à vendre | tracteur routier
Cadillacs On Craigslist
R/Altfeet
Medfusion/Toa Portal
St Patrick Catholic Church Palm Beach Gardens Mass Times
Boondock Eddie's Menu
Magma Lozenge Location
Craigslist Rooms For Rent Winston-Salem Nc
Обзор открытых наушников Sanag Z66 pro с высокой автономностью
Stellaris Ultima Vigilis
Southwest Flight 238
Vocabulary Workshop Level C Final Mastery Test Answers
Joanna Fabric Near Me
Burlington Antioch Ca
Habbowidget
Grab this ice cream maker while it's discounted in Walmart's sale | Digital Trends
He bought a cruise ship on Craigslist and spent over $1 million restoring it. Then his dream sank | CNN
Stellaris Leader Cap
Aultman.mysecurebill
Klay Thompson Finals Stats
Serenity Nail Salon Brentwood Tn
Pokemon Mmo Rom
RuneMarkers - Alchemical Hydra Tile Markers
Vinoteca East Rutherford Menu
O’Fallon, Illinois | Build Your Life and Family Here
Latest Posts
Article information

Author: Reed Wilderman

Last Updated:

Views: 6132

Rating: 4.1 / 5 (52 voted)

Reviews: 91% of readers found this page helpful

Author information

Name: Reed Wilderman

Birthday: 1992-06-14

Address: 998 Estell Village, Lake Oscarberg, SD 48713-6877

Phone: +21813267449721

Job: Technology Engineer

Hobby: Swimming, Do it yourself, Beekeeping, Lapidary, Cosplaying, Hiking, Graffiti

Introduction: My name is Reed Wilderman, I am a faithful, bright, lucky, adventurous, lively, rich, vast person who loves writing and wants to share my knowledge and understanding with you.