Agent Foskett Academy • Microsoft Defender for Cloud

Microsoft Defender for Cloud Academy.

Cloud security is no longer just about checking whether a virtual machine is patched.

Modern environments span Azure subscriptions, containers, storage, identities, workloads, databases, networks and regulatory controls.

The Agent Foskett Microsoft Defender for Cloud Academy is designed to help learners understand cloud security posture management, workload protection and practical Azure security investigations through real-world Microsoft security guidance.

Agent Foskett Microsoft Defender for Cloud Academy
Academy overview

Learn how Microsoft Defender for Cloud helps security teams strengthen cloud posture, protect workloads and investigate risks across Azure and hybrid environments.

Cloud Security Posture Management
Workload protection and Defender plans
Secure Score and recommendations
Azure cloud investigation workflows

What you will learn

This Academy will focus on practical Defender for Cloud concepts that help security analysts and cloud administrators understand risk, reduce exposure and investigate cloud security findings.
Cloud security postureUnderstand how Defender for Cloud evaluates Azure resources, identifies misconfigurations and prioritises security recommendations.
Workload protectionExplore Defender plans for servers, storage, databases, containers, key vaults and other cloud workloads.
Security alertsLearn how Defender for Cloud alerts can support investigation, triage and response across hybrid and multi-cloud environments.
Regulatory complianceUse compliance dashboards and controls to understand risk against security frameworks and business requirements.
Attack path analysisUnderstand how exposed resources, identities and permissions can combine into dangerous cloud attack paths.
Cloud investigation workflowsConnect Defender for Cloud findings with Sentinel, Defender XDR, Entra ID and Azure activity logs for deeper investigations.
🔎 Take your cloud investigation skills into the SOC. Continue into the SOC Analyst Academy and combine Defender for Cloud findings with KQL, Microsoft Sentinel, Defender XDR, Entra and Security Copilot to triage alerts, investigate attack paths, contain affected resources and coordinate response.

Microsoft Defender for Cloud Academy Learning Path

A practical cloud security curriculum organised into four structured modules.
The learning path begins with Defender for Cloud foundations, then moves through security posture management, workload protection, compliance, investigation and response.

Module 1 — Defender for Cloud Foundations

Build a clear understanding of Microsoft Defender for Cloud, CSPM, CWPP, Defender plans, architecture, Azure Arc, multicloud protection and resource visibility.
📘 Module 1
Lesson 1 — What is Microsoft Defender for Cloud? Understand how Microsoft Defender for Cloud combines cloud security posture management, workload protection, recommendations, alerts and multicloud visibility.
📘 Module 1
Lesson 2 — Cloud Security Posture Management Learn how Microsoft Defender for Cloud continuously assesses cloud resources, generates security recommendations, calculates Cloud Secure Score, identifies attack paths and prioritises posture improvements.
📘 Module 1
Lesson 3 — Cloud Workload Protection Learn how Microsoft Defender plans protect servers, storage, databases, containers, APIs, Key Vault and other cloud workloads through runtime monitoring, threat detection and vulnerability assessment.
📘 Module 1
Lesson 4 — Microsoft Defender Plans Overview Learn how Microsoft Defender plans are enabled, scoped, licensed and matched to servers, storage, databases, containers, APIs and other cloud workloads.
📘 Module 1
Lesson 5 — Microsoft Defender for Servers Learn how Microsoft Defender for Servers protects Windows and Linux machines using Defender for Endpoint integration, vulnerability assessment, agentless scanning and hybrid cloud security.
📘 Module 1
Lesson 6 — Defender for Cloud Architecture Learn how Microsoft Defender for Cloud is architected, including management groups, subscriptions, Azure Policy, Azure Arc, connectors, agents, extensions and the flow of security telemetry.
📘 Module 1
Lesson 7 — Azure Arc Integration Learn how Azure Arc extends Microsoft Defender for Cloud to hybrid, on-premises and multicloud servers using the Connected Machine agent, Azure Policy, extensions and centralised security management.
📘 Module 1
Lesson 8 — Multicloud Protection Learn how Microsoft Defender for Cloud secures AWS, Google Cloud and hybrid environments using cloud connectors, posture management, workload protection and unified security visibility.
📘 Module 1
Lesson 9 — Resource Inventory Learn how Microsoft Defender for Cloud Resource Inventory provides unified visibility across Azure, AWS, Google Cloud and hybrid resources using filters, tags, ownership, recommendations and security coverage.
📘 Module 1
Lesson 10 — Secure Score Overview Learn how Microsoft Defender for Cloud Secure Score measures security posture, calculates improvement opportunities and helps prioritise cloud security remediation.

Module 2 — Security Posture and Recommendations

Move from visibility into practical posture improvement, remediation prioritisation, governance and attack path reduction.
📘 Module 2
Lesson 11 — Understanding Security Recommendations Learn how Microsoft Defender for Cloud security recommendations identify security weaknesses, explain risk, list affected resources and provide remediation guidance.
📘 Module 2
Lesson 12 — Prioritising Recommendations Learn how to prioritise Microsoft Defender for Cloud security recommendations using risk, internet exposure, attack paths, business criticality and remediation effort.
📘 Module 2
Lesson 13 — Recommendation Remediation Learn how to remediate Microsoft Defender for Cloud recommendations using manual fixes, Azure Policy, automation, Infrastructure as Code and post-remediation validation.
📘 Module 2
Lesson 14 — Governance Rules Learn how Microsoft Defender for Cloud Governance Rules assign owners, set remediation due dates, track accountability and improve security operations.
📘 Module 2
Lesson 15 — Cloud Security Explorer Learn how Microsoft Defender for Cloud Security Explorer queries cloud assets, identities and security relationships to investigate exposure and identify risky resource combinations.
📘 Module 2
Lesson 16 — Environment Settings Learn how Microsoft Defender for Cloud Environment Settings configures Defender plans, monitoring coverage, security extensions, cloud connectors and subscription-level protection.
📘 Module 2
Lesson 17 — Security Policies Learn how Microsoft Defender for Cloud Security Policies use Azure Policy, security initiatives and compliance evaluations to assess cloud resources and generate security recommendations.
📘 Module 2
Lesson 18 — Exemptions and Suppression Learn how Microsoft Defender for Cloud uses exemptions and suppression to manage accepted risk while maintaining accurate security posture and compliance reporting.
📘 Module 2
Lesson 19 — Cloud Security Posture Best Practices Build a repeatable cloud security posture program using Secure Score, prioritisation, ownership, automation and measurable risk reduction.
📘 Module 2
Lesson 20 — Operationalising Microsoft Defender for Cloud Learn how to operate Microsoft Defender for Cloud through daily reviews, governance, automation, reporting and continuous security improvement.

Module 3 — Workload Protection

Explore Defender plan capabilities for the major cloud workloads that organisations depend on.
📘 Module 3
Lesson 21 — Just-In-Time VM Access Learn how Microsoft Defender for Cloud reduces attack surfaces by keeping RDP, SSH and other management ports closed until temporary, approved administrator access is required.
📘 Module 3
Lesson 22 — Microsoft Defender for Storage Learn how Microsoft Defender for Storage protects Azure Storage accounts using threat detection, malware scanning, sensitive data protection and suspicious activity monitoring.
📘 Module 3
Lesson 23 — Microsoft Defender for SQL Learn how Microsoft Defender for SQL protects Azure SQL databases, SQL servers on machines and database workloads using vulnerability assessments, threat detection and advanced attack monitoring.
📘 Module 3
Lesson 24 — Microsoft Defender for Containers Learn how Microsoft Defender for Containers protects Kubernetes clusters, container images, registries and runtime workloads using posture management, vulnerability assessment and runtime threat detection.
📘 Module 3
Lesson 25 — Microsoft Defender for Key Vault Learn how Microsoft Defender for Key Vault detects unusual secret, key and certificate access using Azure-native threat detection, identity analysis and investigation workflows.
📘 Module 3
Lesson 26 — Microsoft Defender for App Service Learn how Microsoft Defender for App Service protects Azure web applications, APIs and application workloads using native threat detection, platform telemetry and security investigation workflows.
📘 Module 3
Lesson 27 — Microsoft Defender for APIs Learn how Microsoft Defender for APIs provides API inventory, security posture assessment and runtime threat detection for APIs published through Azure API Management.
📘 Module 3
Lesson 28 — Microsoft Defender for Azure Cosmos DB Learn how Microsoft Defender for Azure Cosmos DB detects potential SQL injection, suspicious access patterns, compromised identities and malicious database activity.
📘 Module 3
Lesson 29 — Microsoft Defender for Open-Source Relational Databases Learn how Microsoft Defender for Open-Source Relational Databases detects anomalous access, brute-force activity and suspicious behaviour across supported PostgreSQL, MySQL and MariaDB workloads.
📘 Module 3
Lesson 30 — Workload Protection Best Practices Learn how to validate Defender plan coverage, monitor deployment health and build a consistent workload protection programme across cloud environments.

Module 4 — Compliance, Investigation and Response

Use Defender for Cloud findings to support governance, investigate alerts and connect cloud security operations with Microsoft Sentinel and Defender XDR.
📘 Module 4
Lesson 31 — Regulatory Compliance Dashboard Learn how to review compliance standards, controls, assessments and affected resources using the Microsoft Defender for Cloud Regulatory Compliance Dashboard.
📘 Module 4
Lesson 32 — Compliance Standards and Controls Learn how compliance standards, controls, Azure Policy initiatives and technical assessments work together to support governance, remediation and compliance reporting.
📘 Module 4
Lesson 33 — Defender for Cloud Security Alerts Learn how Microsoft Defender for Cloud security alerts present severity, entities, evidence, affected resources and recommended response actions.
📘 Module 4
Lesson 34 — Investigating Cloud Alerts Learn how to follow identities, resources, activity logs, related alerts and workload evidence through a structured cloud investigation.
📘 Module 4
Lesson 35 — Investigating Attack Paths Learn how to trace exposed entry points, permissions, identities and connected assets to understand realistic attacker movement across cloud environments.
📘 Module 4
Lesson 36 — Cloud Incident Response Learn how to contain affected resources, preserve evidence, reduce exposure and coordinate recovery after a cloud security incident.
📘 Module 4
Lesson 37 — Microsoft Sentinel Integration Learn how to connect Defender for Cloud alerts to Microsoft Sentinel for centralised incidents, analytics, automation, hunting and coordinated response.
📘 Module 4
Lesson 38 — Microsoft Defender XDR Integration Learn how Defender for Cloud alerts, cloud workload evidence and incidents connect with Microsoft Defender XDR for unified investigation and response.
📘 Module 4
Lesson 39 — Cloud Investigation Playbook Learn how to build a repeatable investigation workflow covering identities, resources, permissions, exposure, timelines, attack paths and containment.
📘 Module 4
Lesson 40 — Defender for Cloud Best Practices Learn how to bring cloud security posture, workload protection, compliance, investigation, response and continuous improvement into one operational security programme.

Related Agent Foskett Academies

Defender for Cloud connects naturally with the other Microsoft security academies.
Microsoft Sentinel AcademyUse Sentinel to centralise alerts, hunting, automation and response across cloud and hybrid environments.
Microsoft Entra Security AcademyIdentity, access and permissions are central to cloud attack paths and Defender for Cloud investigations.
Defender for Endpoint AcademyServer protection, endpoint telemetry and device exposure all connect back to cloud workload security.
SOC Analyst AcademyBring cloud alerts and attack-path evidence into realistic SOC triage, investigation, containment and escalation workflows.
KQL AcademyUse KQL to correlate cloud telemetry with identity, endpoint, email and security alert evidence.
Security Copilot AcademyUse AI-assisted investigation to accelerate cloud triage while keeping the analyst responsible for validating the evidence.

Final thought

Cloud security is not just about finding misconfigurations. It is about understanding how identity, workload exposure and attack paths combine into real business risk.
Agent Foskett mindsetDo not treat cloud alerts as isolated events. Follow the resource, the identity, the permission, the exposure and the attack path.
40 lessons publishedThe complete Defender for Cloud learning path is now available across foundations, security posture, workload protection, compliance, investigation and response.
Develop IT. Protect IT.GEMXIT PTY LTD | GEMXIT UK LTD

Microsoft Defender for Cloud Academy

The Agent Foskett Microsoft Defender for Cloud Academy teaches cloud security posture management, workload protection, Secure Score, recommendations, compliance, attack path analysis and Azure security investigations.

Learn Microsoft Defender for Cloud

Defender for Cloud helps security teams identify cloud risks, protect workloads, investigate alerts and improve cloud security posture across Azure, hybrid and multi-cloud environments.

Microsoft cloud security training

This Academy supports learners working with Defender for Cloud, Azure security, CSPM, CWPP, secure score, regulatory compliance, cloud workload protection and Sentinel integration. The SOC Analyst Academy then applies these cloud security skills inside realistic triage, investigation, containment and escalation workflows.