Lesson 16 — Environment Settings
Defender for Cloud protection begins with the settings applied to each connected environment.
This lesson explains how environment settings control Defender plans, monitoring coverage, security extensions, connectors, data collection and subscription-level security configuration.

What you will learn
This lesson explains how Defender for Cloud protection is configured at environment level.
Environment configuration flow
Key environment settings
| Setting | Purpose | Operational impact |
|---|---|---|
| Defender plans | Enable workload protection capabilities for supported resource types. | Determines which resources receive advanced threat protection. |
| Monitoring coverage | Shows whether resources are connected and protected. | Highlights gaps that may leave workloads unmonitored. |
| Security extensions | Deploy additional sensors, agents or integrations. | Expands telemetry and protection capability. |
| Cloud connectors | Connect Azure, AWS and GCP environments. | Brings multicloud assets into Defender for Cloud visibility. |
| Data collection | Controls how security telemetry is collected. | Affects detection, posture and investigation quality. |
| Workspace configuration | Defines the Log Analytics workspace used by supported features. | Influences data location, access and retention. |
| Security contacts | Identifies recipients for alerts and notifications. | Ensures incidents and posture issues reach the right people. |
| Policy assignments | Applies security initiatives and configuration requirements. | Controls compliance evaluation and recommendation generation. |
Environment settings review checklist
- Confirm every production subscription is connected.
- Review which Defender plans are enabled and why.
- Check that expected workloads appear as protected.
- Review agentless scanning, endpoint integration and workload extensions.
- Validate AWS and GCP connector health where applicable.
- Confirm Log Analytics workspaces and data collection settings.
- Review security contacts and notification routing.
- Check that policy assignments match the intended security baseline.
- Identify subscriptions with inconsistent configuration.
- Document approved exceptions and cost decisions.
Agent Foskett investigation: “The server was in Defender for Cloud… but it was never protected.”
Key takeaways
- Environment settings control how Defender for Cloud protects each connected environment.
- Visibility does not automatically mean advanced protection is enabled.
- Defender plans should match the workloads that actually exist.
- Monitoring coverage should be reviewed for gaps.
- Extensions, agents and data collection affect detection quality.
- Cloud connectors must remain healthy and authorised.
- Workspace and policy configuration should be consistent across subscriptions.
- Security contacts should be current and tested.
- Configuration drift can create protection gaps over time.
- Environment settings should be reviewed as part of regular security governance.
Learning objectives
After completing this lesson, you should be able to review environment settings, enable Defender plans and validate monitoring coverage.
What are environment settings?
Environment settings are the subscription, account and project-level controls used to configure Defender for Cloud protection.
Azure subscriptions
Each Azure subscription can have its own Defender plans, policies, contacts and monitoring configuration.
AWS accounts
Connected AWS accounts require connector health, permissions and enabled plans to maintain coverage.
GCP projects
Connected GCP projects require valid connectors, permissions and supported protection settings.
Defender plans
Defender plans enable workload-specific protection for supported resource types.
Plan selection
Enable plans based on actual workload risk, business importance and compliance requirements.
Cost awareness
Defender plans can introduce additional cost, so scope and value should be reviewed.
Servers protection
Server protection may include endpoint integration, vulnerability assessment and threat detection.
Storage protection
Storage protection can help detect suspicious access and data-related threats.
Database protection
Database plans provide workload-specific threat detection and recommendations.
Containers protection
Container plans can extend protection across registries, clusters and workloads.
App service protection
Application platform protection can provide tailored recommendations and detections.
Key vault protection
Key vault protection focuses on suspicious access and secret-management risk.
Resource Manager protection
Resource Manager protection helps detect suspicious control-plane activity.
Monitoring coverage
Coverage views show whether resources are protected, partially protected or unprotected.
Unprotected resources
Unprotected resources should be investigated for disabled plans, missing agents or unsupported configurations.
Agentless scanning
Agentless scanning can provide visibility without deploying a traditional agent to every supported workload.
Extensions
Extensions enable additional data collection, assessment and protection features.
Endpoint integration
Endpoint integration connects supported server workloads with Microsoft Defender for Endpoint.
Vulnerability assessment
Vulnerability assessment settings determine how weaknesses are discovered and reported.
Data collection
Data collection settings influence what telemetry Defender for Cloud can analyse.
Log Analytics workspace
Some features use a Log Analytics workspace for data storage and analysis.
Workspace selection
Use workspaces that align with security operations, access and retention requirements.
Security contacts
Security contacts receive alerts and important Defender for Cloud notifications.
Notification severity
Notification settings can determine which alert severities trigger email.
Contact testing
Security contact details should be reviewed and tested regularly.
Cloud connectors
Connectors provide authorisation and telemetry access to external cloud environments.
Connector permissions
Connector permissions must be sufficient for discovery, posture assessment and protection.
Connector health
Unhealthy connectors can silently reduce multicloud visibility.
Subscription ownership
Clear ownership helps ensure each environment is configured and reviewed.
Management groups
Management groups can support consistent security configuration across multiple subscriptions.
Policy assignments
Security initiatives can be assigned at management group, subscription or resource group scope.
Inherited settings
Inherited configuration can simplify consistency but may also hide unexpected scope decisions.
Configuration drift
Manual changes can cause subscriptions to diverge from the intended baseline.
Baseline settings
A documented baseline helps teams compare environments and identify gaps.
Production versus development
Production environments may require broader protection and stricter notification settings.
New subscriptions
New subscriptions should be onboarded to Defender for Cloud through a repeatable process.
Decommissioned subscriptions
Retired subscriptions and connectors should be removed or disabled cleanly.
Permissions
Administrative access to environment settings should be restricted and monitored.
Change control
Significant plan and connector changes should follow normal change-management processes.
Validation
After changing settings, confirm that coverage and recommendations update as expected.
Coverage reports
Coverage reports can identify resources missing plans, agents or extensions.
Operational review
Environment settings should be included in regular cloud security reviews.
Audit evidence
Retain records of enabled plans, exceptions, ownership and configuration decisions.
What Agent Foskett checked
Agent Foskett checked the enabled plan, extension deployment, monitoring coverage and security contacts.
Best practices
- Document the required Defender plans for each environment type.
- Use management groups and policy where appropriate.
- Review monitoring coverage regularly.
- Investigate every unprotected production resource.
- Validate connector health across Azure, AWS and GCP.
- Keep security contacts current.
- Restrict access to environment settings.
- Use change control for major configuration changes.
- Track cost and risk together.
- Revalidate settings after subscription or ownership changes.
Related Agent Foskett resources
Continue learning
What are Microsoft Defender for Cloud environment settings?
Microsoft Defender for Cloud environment settings control Defender plans, monitoring coverage, extensions, connectors, data collection, workspaces and subscription-level security configuration.
Environment Settings Lesson
This Agent Foskett lesson explains Defender plans, monitoring coverage, agents, extensions, cloud connectors, workspaces, security contacts, policy assignments and configuration drift.
