Agent Foskett Academy • Microsoft Defender for Cloud • Module 4 • Lesson 40

Lesson 40 — Defender for Cloud Best Practices

Microsoft Defender for Cloud is most effective when posture management, workload protection, compliance, investigation and response operate as one programme.

Secure Score, recommendations, attack paths, Defender plans, alerts, regulatory compliance, Microsoft Sentinel and Defender XDR each solve a different part of the cloud security problem. The value comes from connecting them through ownership, prioritisation, automation, measurable risk reduction and continuous improvement.

This final lesson brings the entire Academy together into a practical operating model for managing cloud security across Azure, AWS, Google Cloud and hybrid environments.

The platform was not secured by one control. It was secured by a programme that kept improving.
Agent Foskett Defender for Cloud Best Practices lesson
What you will learn

This lesson brings every Defender for Cloud capability into one repeatable operating model.

Posture management
Workload protection
Investigation and response
Continuous improvement

Defender for Cloud operating model

Discover cloud and hybrid assets

Classify ownership, exposure and criticality

Assess posture with recommendations and Cloud Secure Score

Prioritise using risk factors and attack paths

Remediate through governance rules, policy and ownership

Protect workloads with the correct Defender plans

Detect threats through alerts and incidents

Investigate with Defender XDR and Microsoft Sentinel

Contain, recover and preserve evidence

Measure risk reduction and compliance

Improve the programme continuously

Defender for Cloud programme pillars

PillarPrimary purposeKey Defender capabilities
VisibilityKnow what exists and who owns it.Asset inventory and cloud connectors.
PostureIdentify and prioritise security weaknesses.Cloud Secure Score, recommendations and attack paths.
ProtectionDetect threats against running workloads.Defender plans and workload alerts.
ComplianceMeasure technical alignment with standards.Regulatory Compliance Dashboard.
InvestigationConnect identities, resources and evidence.Defender XDR, Sentinel and cloud security graph.
ResponseContain threats and restore trust.Incidents, automation rules and playbooks.
ImprovementReduce risk over time.Governance, metrics, reassessment and lessons learned.

Learning objectives

  • Build an operational Defender for Cloud programme.
  • Connect posture, protection, compliance and response.
  • Prioritise recommendations by real risk.
  • Validate multicloud and hybrid coverage.
  • Assign ownership and measure progress.
  • Integrate Defender XDR and Microsoft Sentinel.
  • Continuously improve cloud security.

Start with complete visibility

Connect Azure subscriptions, AWS accounts, Google Cloud projects and hybrid resources so the security programme can see the full environment.

Maintain asset inventory

Track resources, identities, owners, criticality, data sensitivity, internet exposure and protection status.

Use management-group governance

Apply consistent security policies and Defender plan settings through the correct management hierarchy.

Automate onboarding

New subscriptions and cloud accounts should receive the required security baseline automatically.

Validate connector health

Review cloud connectors, Azure Arc, agents, extensions and data ingestion regularly.

Enable the right CSPM plan

Use Foundational CSPM or Defender CSPM according to the required posture, exposure and risk-prioritisation capabilities.

Review Cloud Secure Score

Use Cloud Secure Score to monitor overall posture trends and identify broad improvement opportunities.

Do not chase the score

A higher score is useful, but risk reduction matters more than improving a percentage for its own sake.

Use risk-based recommendations

Prioritise recommendations using exploitability, internet exposure, identity privilege, attack paths and business impact.

Review recommendation context

Inspect risk factors, affected resources, attack paths, owners, due dates and current status.

Assign governance rules

Use governance rules to assign recommendations, set due dates and create accountability.

Track overdue remediation

Review overdue recommendations by owner, business unit, subscription and severity.

Review attack paths

Prioritise paths that connect exposed entry points to privileged identities or sensitive resources.

Use Cloud Security Explorer

Query resources, identities, permissions and relationships to test exposure hypotheses.

Reduce public exposure

Remove unnecessary public endpoints, open ports, broad firewall rules and unrestricted storage access.

Apply least privilege

Reduce Azure RBAC, cloud IAM and data-plane permissions to the smallest required scope.

Use managed identities

Replace static credentials with managed identities where practical and restrict their permissions.

Protect privileged access

Use MFA, Conditional Access, PIM, approval and time-limited role activation.

Protect secrets

Store secrets in Key Vault, rotate them, monitor access and remove secrets from code and deployment artefacts.

Use private connectivity

Use private endpoints, segmentation and restricted administrative access for sensitive workloads.

Enable Defender plans

Enable workload-protection plans according to the resources and business services in scope.

Validate workload coverage

Confirm servers, storage, databases, containers, Key Vaults, App Services and APIs are actually protected.

Monitor deployment health

Check Defender for Endpoint, vulnerability assessment, agents, extensions and monitoring coverage.

Protect servers

Use endpoint protection, vulnerability management, JIT access and attack-path context for server security.

Protect storage

Monitor malicious access, malware, exfiltration and unsafe public exposure.

Protect databases

Review suspicious authentication, query activity, identity use, public access and credential exposure.

Protect containers

Secure registries, images, clusters, service accounts and runtime behaviour.

Protect Key Vault

Monitor secrets, keys and certificates and protect them with least privilege, networking and recovery controls.

Protect App Service

Secure web apps, deployment pipelines, managed identities, networking and application telemetry.

Protect APIs

Maintain API inventory, validate authentication and authorisation, and monitor suspicious runtime behaviour.

Enable diagnostic logging

Collect identity, Activity Log, resource, network, endpoint and application telemetry needed for investigations.

Retain useful evidence

Set retention based on investigation needs, compliance obligations and cost.

Centralise incidents

Use Microsoft Defender XDR and Microsoft Sentinel to combine cloud alerts with identity, endpoint, email and third-party evidence.

Avoid duplicate workflows

Choose one incident-correlation model and avoid overlapping connectors and analytics that create duplicate cases.

Use automation rules

Automate assignment, tagging, enrichment, notifications and low-risk workflow actions.

Use playbooks carefully

Automate containment only where permissions, approval and rollback are understood.

Build investigation playbooks

Use a documented workflow for alert validation, identity review, timeline reconstruction, attack paths, scope and containment.

Preserve evidence

Save alerts, logs, snapshots and configurations before destructive remediation.

Validate containment

Confirm old credentials, network paths and identities can no longer be used.

Recover from trusted sources

Redeploy from approved images, code and infrastructure templates where compromise is confirmed.

Review regulatory compliance

Use the Regulatory Compliance Dashboard to monitor assigned standards and technical assessments.

Do not confuse compliance with security

A compliant assessment does not prove the absence of exploitable risk or replace an external audit.

Use exemptions sparingly

Every exemption should have an owner, reason, compensating control, review date and expiry.

Define security ownership

Assign platform, workload, identity, compliance and incident-response ownership clearly.

Use business context

Tag resources with owner, environment, business service, criticality and data sensitivity.

Measure risk reduction

Track critical recommendations closed, attack paths removed, exposed resources reduced and mean time to contain.

Review coverage gaps

Report unprotected workloads, unhealthy sensors, missing logs and disconnected environments.

Daily operating rhythm

Review critical alerts, new attack paths, failed monitoring components and newly exposed resources.

Weekly operating rhythm

Review recommendation ownership, overdue remediation, connector health and incident trends.

Monthly operating rhythm

Report secure score trends, coverage, risk reduction, compliance gaps and response metrics.

Quarterly operating rhythm

Review architecture changes, Defender plans, cloud scope, automation, policy and programme maturity.

Update for product changes

Microsoft Defender for Cloud evolves continuously, so review current documentation, portal changes and support matrices.

Test the programme

Use approved simulations, tabletop exercises and validation activities to prove detections and response workflows.

Learn from incidents

Convert every investigation into improvements for logging, permissions, deployment, ownership and playbooks.

Document decisions

Record why plans, policies, exemptions, playbooks and priorities were chosen.

Create executive visibility

Explain risk, business impact, ownership and progress in language leadership can act on.

Keep the model simple

Use a repeatable structure: discover, assess, prioritise, protect, detect, investigate, respond and improve.

Agent Foskett investigation: “The platform was secure…”

The organisation enabled Microsoft Defender for Cloud

Secure Score improved

Defender plans were enabled

Compliance reports looked healthy

But ownership remained unclear

Recommendations had no due dates

New subscriptions were not onboarded automatically

An exposed workload appeared outside the expected management group

Agent Foskett compared inventory, recommendations and attack paths

A public VM, managed identity and Key Vault formed a critical path

The path was prioritised by business impact

The VM was patched and public management access removed

The managed identity was restricted

Secrets were rotated

Governance rules assigned owners and due dates

New subscriptions were onboarded automatically

Sentinel and Defender XDR centralised investigations

Monthly reporting measured real risk reduction

The platform was not secured by one product setting

It was secured by a programme that kept improving
Tools create visibility. Ownership and continuous improvement create security.

Defender for Cloud best-practice checklist

AreaBest-practice checkEvidence
CoverageAll intended cloud and hybrid environments are connected.Asset inventory and connector health.
PostureCritical recommendations and attack paths are prioritised.Risk levels, owners and due dates.
ProtectionRelevant Defender plans are enabled and healthy.Environment settings and monitoring coverage.
IdentityPrivilege is limited and monitored.RBAC, PIM, MFA and identity logs.
ExposurePublic and administrative access is minimised.Network rules and private connectivity.
TelemetryInvestigators can access required evidence.Logs, retention and data connector health.
InvestigationAlerts follow a documented playbook.Incident tasks and evidence references.
ResponseContainment and recovery are tested.Playbooks, exercises and validation results.
GovernanceEvery recommendation has ownership and accountability.Governance rules and remediation tracking.
ImprovementMetrics show measurable risk reduction.Trends, removed attack paths and lessons learned.

Key takeaways

  • Defender for Cloud should operate as a programme, not a collection of portal settings.
  • Complete asset visibility is the foundation of posture and protection.
  • Cloud Secure Score shows posture trends, but risk-based recommendations and attack paths drive priority.
  • Defender plans must match the actual workload estate and be validated for healthy coverage.
  • Identity, network exposure, secrets and permissions are central to cloud risk.
  • Compliance reporting supports governance but does not replace security judgement or external assurance.
  • Microsoft Defender XDR and Sentinel connect cloud evidence to the broader attack story.
  • Governance rules, ownership and due dates turn findings into remediation.
  • Metrics should demonstrate risk reduction, not only activity.
  • Continuous improvement is the final and most important control.

What Agent Foskett checked

  • Cloud connectors
  • Asset inventory
  • Cloud Secure Score
  • Recommendations
  • Attack paths
  • Defender plans
  • Monitoring health
  • Compliance standards
  • Incident workflows
  • Sentinel and Defender XDR
  • Ownership and due dates
  • Risk-reduction metrics

Best practices

  • Automate onboarding.
  • Maintain complete inventory.
  • Prioritise by real risk.
  • Reduce public exposure.
  • Apply least privilege.
  • Validate workload coverage.
  • Centralise investigations.
  • Assign owners and due dates.
  • Measure risk reduction.
  • Improve continuously.

Related Agent Foskett resources

Continue reviewing the complete Defender for Cloud Academy and related Microsoft security learning paths.

What are Microsoft Defender for Cloud best practices?

Microsoft Defender for Cloud best practices include complete asset visibility, risk-based posture management, correct Defender plan coverage, least privilege, reduced exposure, centralised investigation, clear ownership, governance and continuous improvement.

Defender for Cloud Best Practices Lesson

This final Agent Foskett lesson brings Cloud Secure Score, recommendations, attack paths, workload protection, compliance, Defender XDR, Microsoft Sentinel, governance and incident response into one operational cloud security programme.