Lesson 40 — Defender for Cloud Best Practices
Microsoft Defender for Cloud is most effective when posture management, workload protection, compliance, investigation and response operate as one programme.
Secure Score, recommendations, attack paths, Defender plans, alerts, regulatory compliance, Microsoft Sentinel and Defender XDR each solve a different part of the cloud security problem. The value comes from connecting them through ownership, prioritisation, automation, measurable risk reduction and continuous improvement.
This final lesson brings the entire Academy together into a practical operating model for managing cloud security across Azure, AWS, Google Cloud and hybrid environments.
What you will learn
This lesson brings every Defender for Cloud capability into one repeatable operating model.
Defender for Cloud operating model
↓
Classify ownership, exposure and criticality
↓
Assess posture with recommendations and Cloud Secure Score
↓
Prioritise using risk factors and attack paths
↓
Remediate through governance rules, policy and ownership
↓
Protect workloads with the correct Defender plans
↓
Detect threats through alerts and incidents
↓
Investigate with Defender XDR and Microsoft Sentinel
↓
Contain, recover and preserve evidence
↓
Measure risk reduction and compliance
↓
Improve the programme continuously
Defender for Cloud programme pillars
| Pillar | Primary purpose | Key Defender capabilities |
|---|---|---|
| Visibility | Know what exists and who owns it. | Asset inventory and cloud connectors. |
| Posture | Identify and prioritise security weaknesses. | Cloud Secure Score, recommendations and attack paths. |
| Protection | Detect threats against running workloads. | Defender plans and workload alerts. |
| Compliance | Measure technical alignment with standards. | Regulatory Compliance Dashboard. |
| Investigation | Connect identities, resources and evidence. | Defender XDR, Sentinel and cloud security graph. |
| Response | Contain threats and restore trust. | Incidents, automation rules and playbooks. |
| Improvement | Reduce risk over time. | Governance, metrics, reassessment and lessons learned. |
Learning objectives
- Build an operational Defender for Cloud programme.
- Connect posture, protection, compliance and response.
- Prioritise recommendations by real risk.
- Validate multicloud and hybrid coverage.
- Assign ownership and measure progress.
- Integrate Defender XDR and Microsoft Sentinel.
- Continuously improve cloud security.
Start with complete visibility
Connect Azure subscriptions, AWS accounts, Google Cloud projects and hybrid resources so the security programme can see the full environment.
Maintain asset inventory
Track resources, identities, owners, criticality, data sensitivity, internet exposure and protection status.
Use management-group governance
Apply consistent security policies and Defender plan settings through the correct management hierarchy.
Automate onboarding
New subscriptions and cloud accounts should receive the required security baseline automatically.
Validate connector health
Review cloud connectors, Azure Arc, agents, extensions and data ingestion regularly.
Enable the right CSPM plan
Use Foundational CSPM or Defender CSPM according to the required posture, exposure and risk-prioritisation capabilities.
Review Cloud Secure Score
Use Cloud Secure Score to monitor overall posture trends and identify broad improvement opportunities.
Do not chase the score
A higher score is useful, but risk reduction matters more than improving a percentage for its own sake.
Use risk-based recommendations
Prioritise recommendations using exploitability, internet exposure, identity privilege, attack paths and business impact.
Review recommendation context
Inspect risk factors, affected resources, attack paths, owners, due dates and current status.
Assign governance rules
Use governance rules to assign recommendations, set due dates and create accountability.
Track overdue remediation
Review overdue recommendations by owner, business unit, subscription and severity.
Review attack paths
Prioritise paths that connect exposed entry points to privileged identities or sensitive resources.
Use Cloud Security Explorer
Query resources, identities, permissions and relationships to test exposure hypotheses.
Reduce public exposure
Remove unnecessary public endpoints, open ports, broad firewall rules and unrestricted storage access.
Apply least privilege
Reduce Azure RBAC, cloud IAM and data-plane permissions to the smallest required scope.
Use managed identities
Replace static credentials with managed identities where practical and restrict their permissions.
Protect privileged access
Use MFA, Conditional Access, PIM, approval and time-limited role activation.
Protect secrets
Store secrets in Key Vault, rotate them, monitor access and remove secrets from code and deployment artefacts.
Use private connectivity
Use private endpoints, segmentation and restricted administrative access for sensitive workloads.
Enable Defender plans
Enable workload-protection plans according to the resources and business services in scope.
Validate workload coverage
Confirm servers, storage, databases, containers, Key Vaults, App Services and APIs are actually protected.
Monitor deployment health
Check Defender for Endpoint, vulnerability assessment, agents, extensions and monitoring coverage.
Protect servers
Use endpoint protection, vulnerability management, JIT access and attack-path context for server security.
Protect storage
Monitor malicious access, malware, exfiltration and unsafe public exposure.
Protect databases
Review suspicious authentication, query activity, identity use, public access and credential exposure.
Protect containers
Secure registries, images, clusters, service accounts and runtime behaviour.
Protect Key Vault
Monitor secrets, keys and certificates and protect them with least privilege, networking and recovery controls.
Protect App Service
Secure web apps, deployment pipelines, managed identities, networking and application telemetry.
Protect APIs
Maintain API inventory, validate authentication and authorisation, and monitor suspicious runtime behaviour.
Enable diagnostic logging
Collect identity, Activity Log, resource, network, endpoint and application telemetry needed for investigations.
Retain useful evidence
Set retention based on investigation needs, compliance obligations and cost.
Centralise incidents
Use Microsoft Defender XDR and Microsoft Sentinel to combine cloud alerts with identity, endpoint, email and third-party evidence.
Avoid duplicate workflows
Choose one incident-correlation model and avoid overlapping connectors and analytics that create duplicate cases.
Use automation rules
Automate assignment, tagging, enrichment, notifications and low-risk workflow actions.
Use playbooks carefully
Automate containment only where permissions, approval and rollback are understood.
Build investigation playbooks
Use a documented workflow for alert validation, identity review, timeline reconstruction, attack paths, scope and containment.
Preserve evidence
Save alerts, logs, snapshots and configurations before destructive remediation.
Validate containment
Confirm old credentials, network paths and identities can no longer be used.
Recover from trusted sources
Redeploy from approved images, code and infrastructure templates where compromise is confirmed.
Review regulatory compliance
Use the Regulatory Compliance Dashboard to monitor assigned standards and technical assessments.
Do not confuse compliance with security
A compliant assessment does not prove the absence of exploitable risk or replace an external audit.
Use exemptions sparingly
Every exemption should have an owner, reason, compensating control, review date and expiry.
Define security ownership
Assign platform, workload, identity, compliance and incident-response ownership clearly.
Use business context
Tag resources with owner, environment, business service, criticality and data sensitivity.
Measure risk reduction
Track critical recommendations closed, attack paths removed, exposed resources reduced and mean time to contain.
Review coverage gaps
Report unprotected workloads, unhealthy sensors, missing logs and disconnected environments.
Daily operating rhythm
Review critical alerts, new attack paths, failed monitoring components and newly exposed resources.
Weekly operating rhythm
Review recommendation ownership, overdue remediation, connector health and incident trends.
Monthly operating rhythm
Report secure score trends, coverage, risk reduction, compliance gaps and response metrics.
Quarterly operating rhythm
Review architecture changes, Defender plans, cloud scope, automation, policy and programme maturity.
Update for product changes
Microsoft Defender for Cloud evolves continuously, so review current documentation, portal changes and support matrices.
Test the programme
Use approved simulations, tabletop exercises and validation activities to prove detections and response workflows.
Learn from incidents
Convert every investigation into improvements for logging, permissions, deployment, ownership and playbooks.
Document decisions
Record why plans, policies, exemptions, playbooks and priorities were chosen.
Create executive visibility
Explain risk, business impact, ownership and progress in language leadership can act on.
Keep the model simple
Use a repeatable structure: discover, assess, prioritise, protect, detect, investigate, respond and improve.
Agent Foskett investigation: “The platform was secure…”
↓
Secure Score improved
↓
Defender plans were enabled
↓
Compliance reports looked healthy
↓
But ownership remained unclear
↓
Recommendations had no due dates
↓
New subscriptions were not onboarded automatically
↓
An exposed workload appeared outside the expected management group
↓
Agent Foskett compared inventory, recommendations and attack paths
↓
A public VM, managed identity and Key Vault formed a critical path
↓
The path was prioritised by business impact
↓
The VM was patched and public management access removed
↓
The managed identity was restricted
↓
Secrets were rotated
↓
Governance rules assigned owners and due dates
↓
New subscriptions were onboarded automatically
↓
Sentinel and Defender XDR centralised investigations
↓
Monthly reporting measured real risk reduction
↓
The platform was not secured by one product setting
↓
It was secured by a programme that kept improving
Defender for Cloud best-practice checklist
| Area | Best-practice check | Evidence |
|---|---|---|
| Coverage | All intended cloud and hybrid environments are connected. | Asset inventory and connector health. |
| Posture | Critical recommendations and attack paths are prioritised. | Risk levels, owners and due dates. |
| Protection | Relevant Defender plans are enabled and healthy. | Environment settings and monitoring coverage. |
| Identity | Privilege is limited and monitored. | RBAC, PIM, MFA and identity logs. |
| Exposure | Public and administrative access is minimised. | Network rules and private connectivity. |
| Telemetry | Investigators can access required evidence. | Logs, retention and data connector health. |
| Investigation | Alerts follow a documented playbook. | Incident tasks and evidence references. |
| Response | Containment and recovery are tested. | Playbooks, exercises and validation results. |
| Governance | Every recommendation has ownership and accountability. | Governance rules and remediation tracking. |
| Improvement | Metrics show measurable risk reduction. | Trends, removed attack paths and lessons learned. |
Key takeaways
- Defender for Cloud should operate as a programme, not a collection of portal settings.
- Complete asset visibility is the foundation of posture and protection.
- Cloud Secure Score shows posture trends, but risk-based recommendations and attack paths drive priority.
- Defender plans must match the actual workload estate and be validated for healthy coverage.
- Identity, network exposure, secrets and permissions are central to cloud risk.
- Compliance reporting supports governance but does not replace security judgement or external assurance.
- Microsoft Defender XDR and Sentinel connect cloud evidence to the broader attack story.
- Governance rules, ownership and due dates turn findings into remediation.
- Metrics should demonstrate risk reduction, not only activity.
- Continuous improvement is the final and most important control.
What Agent Foskett checked
- Cloud connectors
- Asset inventory
- Cloud Secure Score
- Recommendations
- Attack paths
- Defender plans
- Monitoring health
- Compliance standards
- Incident workflows
- Sentinel and Defender XDR
- Ownership and due dates
- Risk-reduction metrics
Best practices
- Automate onboarding.
- Maintain complete inventory.
- Prioritise by real risk.
- Reduce public exposure.
- Apply least privilege.
- Validate workload coverage.
- Centralise investigations.
- Assign owners and due dates.
- Measure risk reduction.
- Improve continuously.
Related Agent Foskett resources
Academy complete
What are Microsoft Defender for Cloud best practices?
Microsoft Defender for Cloud best practices include complete asset visibility, risk-based posture management, correct Defender plan coverage, least privilege, reduced exposure, centralised investigation, clear ownership, governance and continuous improvement.
Defender for Cloud Best Practices Lesson
This final Agent Foskett lesson brings Cloud Secure Score, recommendations, attack paths, workload protection, compliance, Defender XDR, Microsoft Sentinel, governance and incident response into one operational cloud security programme.
