Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 16

Lesson 16 — Environment Settings

Defender for Cloud protection begins with the settings applied to each connected environment.

This lesson explains how environment settings control Defender plans, monitoring coverage, security extensions, connectors, data collection and subscription-level security configuration.

A security control cannot protect a workload that was never enabled, connected or monitored.
Agent Foskett Environment Settings lesson
What you will learn

This lesson explains how Defender for Cloud protection is configured at environment level.

Defender plans
Monitoring coverage
Extensions and agents
Connectors and scope

Environment configuration flow

Open Defender for Cloud ↓ Select Environment settings ↓ Choose the Azure subscription, AWS account or GCP project ↓ Review enabled Defender plans ↓ Confirm monitoring coverage ↓ Review data collection and extensions ↓ Validate cloud connectors ↓ Check workspace and agent configuration ↓ Confirm security contacts and notifications ↓ Review policy assignments ↓ Save the configuration ↓ Validate that resources appear as protected ↓ Monitor coverage and drift over time

Key environment settings

SettingPurposeOperational impact
Defender plansEnable workload protection capabilities for supported resource types.Determines which resources receive advanced threat protection.
Monitoring coverageShows whether resources are connected and protected.Highlights gaps that may leave workloads unmonitored.
Security extensionsDeploy additional sensors, agents or integrations.Expands telemetry and protection capability.
Cloud connectorsConnect Azure, AWS and GCP environments.Brings multicloud assets into Defender for Cloud visibility.
Data collectionControls how security telemetry is collected.Affects detection, posture and investigation quality.
Workspace configurationDefines the Log Analytics workspace used by supported features.Influences data location, access and retention.
Security contactsIdentifies recipients for alerts and notifications.Ensures incidents and posture issues reach the right people.
Policy assignmentsApplies security initiatives and configuration requirements.Controls compliance evaluation and recommendation generation.

Environment settings review checklist

  • Confirm every production subscription is connected.
  • Review which Defender plans are enabled and why.
  • Check that expected workloads appear as protected.
  • Review agentless scanning, endpoint integration and workload extensions.
  • Validate AWS and GCP connector health where applicable.
  • Confirm Log Analytics workspaces and data collection settings.
  • Review security contacts and notification routing.
  • Check that policy assignments match the intended security baseline.
  • Identify subscriptions with inconsistent configuration.
  • Document approved exceptions and cost decisions.

Agent Foskett investigation: “The server was in Defender for Cloud… but it was never protected.”

A production server appeared in Defender for Cloud ↓ The team assumed it was protected ↓ A security incident occurred ↓ Expected workload alerts were missing ↓ Agent Foskett reviewed Environment settings ↓ The subscription was connected ↓ But the relevant Defender plan was disabled ↓ Monitoring coverage showed the server as unprotected ↓ The endpoint extension had never been deployed ↓ Security contacts were also out of date ↓ The resource was visible ↓ But visibility had been mistaken for protection ↓ The Defender plan was enabled ↓ The extension was deployed ↓ Security contacts were corrected ↓ Coverage was validated across the subscription ↓ The organisation added a monthly environment settings review
The resource was listed in the portal, but the protection plan behind it had never been enabled.

Key takeaways

  • Environment settings control how Defender for Cloud protects each connected environment.
  • Visibility does not automatically mean advanced protection is enabled.
  • Defender plans should match the workloads that actually exist.
  • Monitoring coverage should be reviewed for gaps.
  • Extensions, agents and data collection affect detection quality.
  • Cloud connectors must remain healthy and authorised.
  • Workspace and policy configuration should be consistent across subscriptions.
  • Security contacts should be current and tested.
  • Configuration drift can create protection gaps over time.
  • Environment settings should be reviewed as part of regular security governance.

Learning objectives

After completing this lesson, you should be able to review environment settings, enable Defender plans and validate monitoring coverage.

What are environment settings?

Environment settings are the subscription, account and project-level controls used to configure Defender for Cloud protection.

Azure subscriptions

Each Azure subscription can have its own Defender plans, policies, contacts and monitoring configuration.

AWS accounts

Connected AWS accounts require connector health, permissions and enabled plans to maintain coverage.

GCP projects

Connected GCP projects require valid connectors, permissions and supported protection settings.

Defender plans

Defender plans enable workload-specific protection for supported resource types.

Plan selection

Enable plans based on actual workload risk, business importance and compliance requirements.

Cost awareness

Defender plans can introduce additional cost, so scope and value should be reviewed.

Servers protection

Server protection may include endpoint integration, vulnerability assessment and threat detection.

Storage protection

Storage protection can help detect suspicious access and data-related threats.

Database protection

Database plans provide workload-specific threat detection and recommendations.

Containers protection

Container plans can extend protection across registries, clusters and workloads.

App service protection

Application platform protection can provide tailored recommendations and detections.

Key vault protection

Key vault protection focuses on suspicious access and secret-management risk.

Resource Manager protection

Resource Manager protection helps detect suspicious control-plane activity.

Monitoring coverage

Coverage views show whether resources are protected, partially protected or unprotected.

Unprotected resources

Unprotected resources should be investigated for disabled plans, missing agents or unsupported configurations.

Agentless scanning

Agentless scanning can provide visibility without deploying a traditional agent to every supported workload.

Extensions

Extensions enable additional data collection, assessment and protection features.

Endpoint integration

Endpoint integration connects supported server workloads with Microsoft Defender for Endpoint.

Vulnerability assessment

Vulnerability assessment settings determine how weaknesses are discovered and reported.

Data collection

Data collection settings influence what telemetry Defender for Cloud can analyse.

Log Analytics workspace

Some features use a Log Analytics workspace for data storage and analysis.

Workspace selection

Use workspaces that align with security operations, access and retention requirements.

Security contacts

Security contacts receive alerts and important Defender for Cloud notifications.

Notification severity

Notification settings can determine which alert severities trigger email.

Contact testing

Security contact details should be reviewed and tested regularly.

Cloud connectors

Connectors provide authorisation and telemetry access to external cloud environments.

Connector permissions

Connector permissions must be sufficient for discovery, posture assessment and protection.

Connector health

Unhealthy connectors can silently reduce multicloud visibility.

Subscription ownership

Clear ownership helps ensure each environment is configured and reviewed.

Management groups

Management groups can support consistent security configuration across multiple subscriptions.

Policy assignments

Security initiatives can be assigned at management group, subscription or resource group scope.

Inherited settings

Inherited configuration can simplify consistency but may also hide unexpected scope decisions.

Configuration drift

Manual changes can cause subscriptions to diverge from the intended baseline.

Baseline settings

A documented baseline helps teams compare environments and identify gaps.

Production versus development

Production environments may require broader protection and stricter notification settings.

New subscriptions

New subscriptions should be onboarded to Defender for Cloud through a repeatable process.

Decommissioned subscriptions

Retired subscriptions and connectors should be removed or disabled cleanly.

Permissions

Administrative access to environment settings should be restricted and monitored.

Change control

Significant plan and connector changes should follow normal change-management processes.

Validation

After changing settings, confirm that coverage and recommendations update as expected.

Coverage reports

Coverage reports can identify resources missing plans, agents or extensions.

Operational review

Environment settings should be included in regular cloud security reviews.

Audit evidence

Retain records of enabled plans, exceptions, ownership and configuration decisions.

What Agent Foskett checked

Agent Foskett checked the enabled plan, extension deployment, monitoring coverage and security contacts.

Best practices

  • Document the required Defender plans for each environment type.
  • Use management groups and policy where appropriate.
  • Review monitoring coverage regularly.
  • Investigate every unprotected production resource.
  • Validate connector health across Azure, AWS and GCP.
  • Keep security contacts current.
  • Restrict access to environment settings.
  • Use change control for major configuration changes.
  • Track cost and risk together.
  • Revalidate settings after subscription or ownership changes.

Continue learning

Next, understand Azure Policy, security initiatives and how Defender for Cloud evaluates resource compliance.

What are Microsoft Defender for Cloud environment settings?

Microsoft Defender for Cloud environment settings control Defender plans, monitoring coverage, extensions, connectors, data collection, workspaces and subscription-level security configuration.

Environment Settings Lesson

This Agent Foskett lesson explains Defender plans, monitoring coverage, agents, extensions, cloud connectors, workspaces, security contacts, policy assignments and configuration drift.