Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 19

Lesson 19 — Cloud Security Posture Best Practices

Knowing how Microsoft Defender for Cloud works is only half the battle.

This lesson explains how mature organisations build a repeatable Cloud Security Posture Management programme using Secure Score, risk-based prioritisation, ownership, automation and measurable risk reduction.

Good posture is not about fixing everything. It is about fixing the right things first.
Agent Foskett Cloud Security Posture Best Practices lesson
What you will learn

This lesson brings the entire Cloud Security Posture Management module together into one repeatable operating model.

Risk prioritisation
Secure Score strategy
Ownership and automation
Measurable improvement

A repeatable CSPM operating model

Discover cloud resources ↓ Assess current posture ↓ Identify attack paths and exposed assets ↓ Prioritise recommendations by business risk ↓ Assign accountable owners ↓ Remediate or formally accept the risk ↓ Automate repeatable controls ↓ Measure improvement ↓ Report outcomes ↓ Review the environment again ↓ Repeat continuously

Risk-based prioritisation model

PriorityTypical characteristicsExample response
CriticalInternet-facing, exploitable, privileged, sensitive or connected to a realistic attack path.Investigate immediately, contain exposure and assign an urgent remediation owner.
HighMaterial security weakness affecting important workloads or a large number of resources.Schedule rapid remediation and track progress through governance reporting.
MediumMeaningful weakness with lower immediate exposure or stronger compensating controls.Place into a planned remediation queue with a target date.
LowLimited exposure, minor hardening opportunity or low business impact.Bundle with routine maintenance or automate where practical.

Agent Foskett investigation: “Nothing was actually broken…”

Microsoft Defender for Cloud displayed more than 3,000 recommendations ↓ The team tried to fix everything ↓ Low-risk configuration issues consumed most of the effort ↓ Critical internet-facing servers remained exposed ↓ Public storage accounts still allowed unnecessary access ↓ Recommendation ownership was unclear ↓ Agent Foskett grouped findings by business impact and exposure ↓ Internet-facing assets were reviewed first ↓ Critical recommendations were assigned to named owners ↓ Duplicate and accepted-risk items were separated ↓ Automation was introduced for repeatable fixes ↓ The highest-risk exposures were removed ↓ Secure Score improved naturally ↓ Actual cloud risk fell
Good cloud security posture is not about fixing everything. It is about fixing the right things first.

Operational review cadence

CadenceFocusTypical output
DailyCritical recommendations, internet exposure, new attack paths and urgent alerts.Immediate triage, escalation and ownership.
WeeklyRecommendation progress, Secure Score movement, overdue actions and new assets.Updated remediation queue and owner actions.
MonthlyRisk trends, exceptions, plan coverage, compliance posture and recurring weaknesses.Management report and improvement priorities.
QuarterlyPolicy effectiveness, maturity, investment needs and long-running accepted risks.Executive review and roadmap decisions.

Key takeaways

  • Operate Defender for Cloud as a continuous programme rather than a one-time configuration project.
  • Prioritise business risk, internet exposure and attack paths before low-impact score improvements.
  • Use Secure Score to measure progress, not to replace security judgement.
  • Assign every material recommendation to an accountable owner.
  • Use governance rules, due dates and escalation to prevent findings from becoming permanent backlog.
  • Automate repeatable controls wherever practical.
  • Review exemptions and accepted risks regularly.
  • Measure risk reduction, remediation time and coverage—not only recommendation counts.
  • Report outcomes in language that technical teams and executives can understand.
  • Repeat the posture cycle as cloud environments change.

Learning objectives

After completing this lesson, you should be able to build and operate a repeatable cloud security posture programme.

Why programmes fail

Organisations often deploy Defender for Cloud without defining ownership, prioritisation, reporting or remediation processes.

Technology is not enough

The value of Defender for Cloud depends on how consistently teams act on its findings.

Start with business context

Identify critical services, sensitive data, regulatory obligations and operational dependencies before ranking recommendations.

Identify crown jewels

Crown-jewel workloads should receive stronger monitoring, faster remediation and tighter exception controls.

Prioritise exposure

Internet-facing resources and externally reachable attack paths normally require attention before isolated internal assets.

Prioritise exploitability

Give greater urgency to weaknesses that can realistically be exploited with available techniques.

Prioritise privilege

Recommendations involving privileged identities, broad permissions and management access deserve additional scrutiny.

Prioritise data sensitivity

Resources holding personal, financial, health or commercially sensitive information should receive higher priority.

Prioritise attack paths

An individual weakness becomes more urgent when it contributes to a realistic path towards a critical asset.

Secure Score

Secure Score provides a useful measure of posture improvement across assessed controls.

Secure Score is not the goal

A higher score does not automatically mean the organisation has addressed its most important risks.

Avoid score chasing

Do not complete easy low-impact actions simply because they produce quick score gains.

Use score trends

Track Secure Score over time to identify sustained improvement or unexpected deterioration.

Recommendation ownership

Every important recommendation should be assigned to a named team or individual.

Business owner

The business owner explains workload importance and accepts the consequences of delayed remediation.

Technical owner

The technical owner plans and implements the required configuration change.

Security owner

The security owner validates risk, prioritisation and evidence of completion.

Executive sponsor

An executive sponsor removes organisational blockers and supports required investment.

Governance rules

Use governance rules to assign owners, define due dates and monitor remediation progress.

Due dates

Set realistic target dates based on severity, exposure, complexity and business impact.

Escalation

Escalate overdue critical recommendations before they become accepted operational debt.

Automation

Automate repeatable configuration, assignment, notification and remediation tasks wherever practical.

Azure Policy

Use Azure Policy to prevent insecure configurations and deploy required controls consistently.

Logic Apps

Use Logic Apps and automation workflows to route findings, notify owners and create work items.

Infrastructure as code

Embed secure configuration into templates and deployment pipelines rather than fixing the same weakness repeatedly.

Shift left

Identify posture issues during design and deployment instead of waiting until production.

Prevent recurrence

After remediating a recommendation, determine how policy or automation can stop it returning.

Exception management

Use exemptions only when risk has been investigated, justified, approved and assigned an expiry date.

Temporary acceptance

Temporary accepted risk should include compensating controls and a documented remediation plan.

Recommendation backlog

Separate active risk, planned remediation, accepted risk and invalid findings so the backlog remains meaningful.

Daily review

Review new critical recommendations, attack paths and exposed resources every business day.

Weekly review

Review recommendation progress, owners, due dates and Secure Score movement each week.

Monthly reporting

Summarise risk reduction, remaining critical exposure, plan coverage and overdue remediation each month.

Executive reporting

Translate technical findings into business impact, trend, ownership and investment decisions.

Useful metrics

Track critical findings, mean remediation time, attack paths, internet exposure, coverage gaps and exception ageing.

Mean remediation time

Measure how long findings remain open from detection to verified closure.

Coverage metrics

Track subscriptions, servers, storage accounts and other workloads without appropriate Defender plan coverage.

Trend analysis

Look for repeated configuration weaknesses, recurring exceptions and teams with persistent remediation delays.

Evidence of closure

Verify that the resource changed and that Defender for Cloud reassessed the recommendation.

False completion

Closing a ticket without confirming the security state leaves risk hidden behind process.

Multicloud consistency

Apply the same prioritisation, ownership and reporting model across Azure, AWS, Google Cloud and hybrid assets.

Tagging strategy

Use resource tags to identify business owner, criticality, environment, application and data sensitivity.

Resource inventory

Maintain accurate visibility of new, changed and retired cloud resources.

Maturity level 1

Teams react to findings manually with limited ownership or reporting.

Maturity level 2

Recommendations are prioritised, assigned and reviewed on a regular schedule.

Maturity level 3

Policy, automation, metrics and executive governance support continuous improvement.

Common mistake: fixing everything

Trying to remediate every recommendation at once creates noise and delays important action.

Common mistake: no owner

Recommendations without accountable owners remain open indefinitely.

Common mistake: permanent exceptions

Exceptions without expiry dates can hide unresolved exposure for years.

Common mistake: no validation

Remediation should be confirmed through reassessment rather than assumed from implementation.

Common mistake: poor reporting

Recommendation counts alone do not explain business risk or security improvement.

What Agent Foskett checked

Agent Foskett checked exposure, attack paths, resource criticality, ownership, ageing, exceptions and evidence of closure.

Best-practice checklist

  • Review Defender for Cloud every business day.
  • Prioritise business risk over quick Secure Score gains.
  • Assign every material recommendation to an owner.
  • Use governance rules and due dates.
  • Automate repeatable controls.
  • Prevent remediated weaknesses from returning.
  • Review exceptions and overdue actions.
  • Validate completed remediation.
  • Measure risk reduction and remediation time.
  • Report clear outcomes to leadership.

Related Agent Foskett resources

Review the Defender for Cloud features that support a mature Cloud Security Posture Management programme.

Continue learning

Module 2 is complete. Next, begin Module 3 and explore workload protection capabilities for servers, storage, databases, containers and other cloud services.

What are cloud security posture best practices?

Cloud security posture best practices combine continuous assessment, Secure Score, risk-based prioritisation, accountable ownership, policy, automation, exception governance and measurable remediation across changing cloud environments.

Cloud Security Posture Best Practices Lesson

This Agent Foskett lesson explains how to operate Microsoft Defender for Cloud as a repeatable Cloud Security Posture Management programme that reduces real business risk rather than simply increasing recommendation completion counts.