Lesson 20 — Operationalising Microsoft Defender for Cloud
Deploying Microsoft Defender for Cloud is only the beginning.
This lesson explains how mature organisations embed Defender for Cloud into daily operations through structured reviews, accountable governance, automation, reporting and continuous security improvement.

What you will learn
This lesson turns Defender for Cloud from a dashboard into a repeatable operational security process.
Operationalising Defender for Cloud
Recommended operating cadence
| Cadence | Operational focus | Outcome |
|---|---|---|
| Daily | New critical recommendations, attack paths, exposed resources, severe alerts and failed assessments. | Urgent triage and immediate ownership. |
| Weekly | Secure Score movement, overdue actions, new subscriptions, ageing recommendations and exceptions nearing expiry. | Updated remediation priorities and accountable actions. |
| Monthly | Risk reduction, plan coverage, control effectiveness, recurring issues and compliance trends. | Management reporting and improvement decisions. |
| Quarterly | Programme maturity, policy effectiveness, investment requirements and long-running accepted risks. | Executive governance and roadmap changes. |
Operational maturity model
| Level | Description | Typical characteristics |
|---|---|---|
| Level 1 — Reactive | Teams respond only when serious findings are noticed. | Manual remediation, limited ownership and inconsistent reporting. |
| Level 2 — Managed | Recommendations are reviewed and assigned on a regular schedule. | Defined owners, due dates, recurring meetings and basic metrics. |
| Level 3 — Optimised | Automation and governance drive continuous improvement. | Policy enforcement, workflow automation, trend reporting and measured outcomes. |
| Level 4 — Predictive | Teams use risk trends and recurring patterns to prevent exposure. | Proactive control design, advanced analytics and strategic investment planning. |
Agent Foskett investigation: “The dashboard was perfect…”
Key operational KPIs
| KPI | What it measures | Why it matters |
|---|---|---|
| Secure Score trend | Movement in assessed security posture over time. | Shows whether posture is improving or deteriorating. |
| Mean remediation time | Average time from detection to verified closure. | Reveals how quickly teams reduce exposure. |
| Critical recommendations | Number and age of unresolved critical findings. | Highlights immediate operational risk. |
| Attack paths | Open paths that could lead an attacker to critical assets. | Focuses effort on realistic compromise scenarios. |
| Coverage gaps | Resources or subscriptions without appropriate Defender plans. | Identifies blind spots in workload protection. |
| Exception ageing | How long accepted-risk items remain active. | Prevents temporary exceptions from becoming permanent. |
Key takeaways
- Deploying Defender for Cloud is the start of the programme, not the end.
- Daily reviews should focus on new critical exposure and attack paths.
- Weekly governance should track ownership, due dates and ageing recommendations.
- Monthly reporting should demonstrate actual risk reduction.
- Automation should remove repeatable manual work.
- Every important recommendation requires an accountable owner.
- Exceptions should be reviewed before they expire.
- KPIs should measure outcomes rather than activity alone.
- Leadership reporting should explain risk, trend and required decisions.
- Mature programmes continuously improve as the cloud environment changes.
Learning objectives
After completing this lesson, you should be able to operate Defender for Cloud through structured reviews, governance, automation and reporting.
From deployment to operations
A successful deployment provides visibility; an operational programme turns that visibility into risk reduction.
Daily dashboard review
Review critical recommendations, attack paths, exposed assets, high-severity alerts and newly discovered resources.
New recommendations
Determine whether new findings represent immediate exposure, recurring configuration problems or expected changes.
Attack path review
Review attack paths first because they connect separate weaknesses into realistic routes towards critical assets.
Internet exposure
Identify public endpoints, open management ports, exposed storage and unrestricted services.
New resources
Confirm that newly created subscriptions, virtual machines, storage accounts and databases inherit the required protections.
Failed assessments
Investigate failed assessments to understand whether policy, configuration or resource ownership has changed.
Weekly governance meeting
Bring security, platform, application and business owners together to review outstanding risk.
Secure Score movement
Review why Secure Score changed rather than treating the number alone as the outcome.
Recommendation ageing
Older recommendations deserve scrutiny because exposure often becomes accepted through inaction.
Overdue actions
Escalate critical recommendations that have passed their remediation due dates.
Ownership checks
Confirm that every high-impact action still has a valid owner after organisational or workload changes.
Exception expiry
Review exemptions before expiry so risk is either remediated, renewed with evidence or returned to active reporting.
Coverage review
Check whether all supported workloads have the intended Defender plans enabled.
Monthly posture report
Summarise changes in risk, coverage, Secure Score, remediation and accepted exceptions.
Risk reduction
Report which critical exposures were removed and which material risks remain.
Control effectiveness
Measure whether policies and automation prevent remediated weaknesses from returning.
Recurring findings
Repeated recommendations often indicate a deployment, policy or ownership problem.
Executive dashboard
Present posture, trend, business impact, overdue actions and investment requirements clearly.
Leadership questions
Executives need to know whether risk is improving, what remains critical and what decisions are required.
Avoid technical overload
Use supporting technical detail when needed, but lead with business impact and trend.
Automation opportunities
Automate notifications, ticket creation, ownership assignment, policy enforcement and routine remediation.
Logic Apps
Use Logic Apps to route findings, notify owners, open service tickets and trigger approved workflows.
Azure Policy
Use Azure Policy to deploy required controls and prevent insecure configuration.
Workflow automation
Connect Defender for Cloud recommendations and alerts to repeatable operational processes.
Ticket integration
Create and update work items so remediation activity remains visible outside the security portal.
Resource tagging
Use tags to identify criticality, owner, environment, application and data classification.
Infrastructure as code
Correct insecure deployment templates so the same weakness does not return.
Automated validation
Where possible, verify that remediation changed the security state and closed the recommendation.
Secure Score KPI
Track Secure Score as one measure of progress, not as the only measure of programme success.
Critical finding KPI
Track the number, age and ownership of unresolved critical recommendations.
Mean remediation time
Measure the average time taken to move from detection to verified closure.
Attack path KPI
Track open attack paths and the time required to remove their highest-risk links.
Coverage KPI
Track subscriptions and workloads missing the intended Defender plan.
Exception ageing KPI
Track exceptions approaching expiry and those repeatedly renewed.
Recommendation closure rate
Measure how many recommendations are verified as closed during each reporting period.
Reopened findings
Track recommendations that return after remediation because they reveal weak preventive controls.
Evidence of completion
Confirm remediation through Defender for Cloud reassessment rather than relying only on a closed ticket.
Operational ownership
Security may coordinate the programme, but platform and application teams must own many remediation actions.
RACI model
Define who is responsible, accountable, consulted and informed for posture activities.
Security operations
Security Operations should review severe alerts and attack paths that may indicate active compromise.
Cloud platform team
Platform teams should own shared controls, subscription configuration and Defender plan coverage.
Application teams
Application owners should remediate workload-specific configuration and development issues.
Governance team
Governance teams should review exceptions, policy alignment and overdue business risk.
Continuous improvement
Use lessons from incidents, audits and recurring recommendations to strengthen the operating model.
Quarterly maturity review
Assess whether the programme is becoming more consistent, automated and preventive.
Operational debt
Unowned recommendations and permanent exceptions create hidden security debt.
Tool health
Confirm that connectors, agents, plans, policies and assessment processes continue working.
Change management
Review major cloud changes to ensure new subscriptions and services enter the operating model.
Multicloud operations
Apply the same cadence and ownership standards across Azure, AWS, Google Cloud and hybrid environments.
What Agent Foskett checked
Agent Foskett checked review cadence, owners, coverage, ageing findings, exceptions, reporting and evidence of action.
Best-practice checklist
- Review new critical exposure every business day.
- Hold weekly governance meetings.
- Assign named owners and due dates.
- Review Secure Score changes in context.
- Automate notifications and repeatable controls.
- Track coverage gaps and ageing findings.
- Review exceptions before expiry.
- Validate completed remediation.
- Report monthly risk reduction.
- Assess programme maturity quarterly.
Related Agent Foskett resources
Continue learning
How do organisations operationalise Microsoft Defender for Cloud?
Organisations operationalise Microsoft Defender for Cloud by establishing daily review routines, weekly governance, accountable ownership, workflow automation, measurable KPIs and executive reporting.
Operationalising Microsoft Defender for Cloud Lesson
This Agent Foskett lesson explains how to turn Defender for Cloud from a security dashboard into a continuous operational programme that drives remediation, accountability and measurable risk reduction.
