Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 20

Lesson 20 — Operationalising Microsoft Defender for Cloud

Deploying Microsoft Defender for Cloud is only the beginning.

This lesson explains how mature organisations embed Defender for Cloud into daily operations through structured reviews, accountable governance, automation, reporting and continuous security improvement.

Security posture is not something you configure once. It is something you operate every day.
Agent Foskett Operationalising Microsoft Defender for Cloud lesson
What you will learn

This lesson turns Defender for Cloud from a dashboard into a repeatable operational security process.

Daily operations
Governance cadence
Automation and KPIs
Executive reporting

Operationalising Defender for Cloud

Defender for Cloud is configured ↓ Resources are continuously assessed ↓ New recommendations and attack paths appear ↓ Security teams review critical exposure ↓ Owners receive assigned actions ↓ Remediation is tracked ↓ Automation handles repeatable work ↓ Exceptions are governed ↓ Metrics are measured ↓ Leadership receives clear reporting ↓ The programme improves continuously

Recommended operating cadence

CadenceOperational focusOutcome
DailyNew critical recommendations, attack paths, exposed resources, severe alerts and failed assessments.Urgent triage and immediate ownership.
WeeklySecure Score movement, overdue actions, new subscriptions, ageing recommendations and exceptions nearing expiry.Updated remediation priorities and accountable actions.
MonthlyRisk reduction, plan coverage, control effectiveness, recurring issues and compliance trends.Management reporting and improvement decisions.
QuarterlyProgramme maturity, policy effectiveness, investment requirements and long-running accepted risks.Executive governance and roadmap changes.

Operational maturity model

LevelDescriptionTypical characteristics
Level 1 — ReactiveTeams respond only when serious findings are noticed.Manual remediation, limited ownership and inconsistent reporting.
Level 2 — ManagedRecommendations are reviewed and assigned on a regular schedule.Defined owners, due dates, recurring meetings and basic metrics.
Level 3 — OptimisedAutomation and governance drive continuous improvement.Policy enforcement, workflow automation, trend reporting and measured outcomes.
Level 4 — PredictiveTeams use risk trends and recurring patterns to prevent exposure.Proactive control design, advanced analytics and strategic investment planning.

Agent Foskett investigation: “The dashboard was perfect…”

Defender for Cloud had been configured correctly ↓ Policies were assigned ↓ Recommendations were generated ↓ Secure Score updated every day ↓ Nobody reviewed the dashboard ↓ Six months passed ↓ Critical recommendations aged ↓ New subscriptions had no Defender plans ↓ Public storage accounts appeared ↓ Internet-facing virtual machines lacked protection ↓ Agent Foskett reviewed the operating process ↓ The technology had worked exactly as designed ↓ The operational process had failed ↓ Daily reviews were introduced ↓ Weekly governance meetings began ↓ Owners and due dates were assigned ↓ The backlog started shrinking
Defender for Cloud cannot reduce risk if nobody acts on what it finds.

Key operational KPIs

KPIWhat it measuresWhy it matters
Secure Score trendMovement in assessed security posture over time.Shows whether posture is improving or deteriorating.
Mean remediation timeAverage time from detection to verified closure.Reveals how quickly teams reduce exposure.
Critical recommendationsNumber and age of unresolved critical findings.Highlights immediate operational risk.
Attack pathsOpen paths that could lead an attacker to critical assets.Focuses effort on realistic compromise scenarios.
Coverage gapsResources or subscriptions without appropriate Defender plans.Identifies blind spots in workload protection.
Exception ageingHow long accepted-risk items remain active.Prevents temporary exceptions from becoming permanent.

Key takeaways

  • Deploying Defender for Cloud is the start of the programme, not the end.
  • Daily reviews should focus on new critical exposure and attack paths.
  • Weekly governance should track ownership, due dates and ageing recommendations.
  • Monthly reporting should demonstrate actual risk reduction.
  • Automation should remove repeatable manual work.
  • Every important recommendation requires an accountable owner.
  • Exceptions should be reviewed before they expire.
  • KPIs should measure outcomes rather than activity alone.
  • Leadership reporting should explain risk, trend and required decisions.
  • Mature programmes continuously improve as the cloud environment changes.

Learning objectives

After completing this lesson, you should be able to operate Defender for Cloud through structured reviews, governance, automation and reporting.

From deployment to operations

A successful deployment provides visibility; an operational programme turns that visibility into risk reduction.

Daily dashboard review

Review critical recommendations, attack paths, exposed assets, high-severity alerts and newly discovered resources.

New recommendations

Determine whether new findings represent immediate exposure, recurring configuration problems or expected changes.

Attack path review

Review attack paths first because they connect separate weaknesses into realistic routes towards critical assets.

Internet exposure

Identify public endpoints, open management ports, exposed storage and unrestricted services.

New resources

Confirm that newly created subscriptions, virtual machines, storage accounts and databases inherit the required protections.

Failed assessments

Investigate failed assessments to understand whether policy, configuration or resource ownership has changed.

Weekly governance meeting

Bring security, platform, application and business owners together to review outstanding risk.

Secure Score movement

Review why Secure Score changed rather than treating the number alone as the outcome.

Recommendation ageing

Older recommendations deserve scrutiny because exposure often becomes accepted through inaction.

Overdue actions

Escalate critical recommendations that have passed their remediation due dates.

Ownership checks

Confirm that every high-impact action still has a valid owner after organisational or workload changes.

Exception expiry

Review exemptions before expiry so risk is either remediated, renewed with evidence or returned to active reporting.

Coverage review

Check whether all supported workloads have the intended Defender plans enabled.

Monthly posture report

Summarise changes in risk, coverage, Secure Score, remediation and accepted exceptions.

Risk reduction

Report which critical exposures were removed and which material risks remain.

Control effectiveness

Measure whether policies and automation prevent remediated weaknesses from returning.

Recurring findings

Repeated recommendations often indicate a deployment, policy or ownership problem.

Executive dashboard

Present posture, trend, business impact, overdue actions and investment requirements clearly.

Leadership questions

Executives need to know whether risk is improving, what remains critical and what decisions are required.

Avoid technical overload

Use supporting technical detail when needed, but lead with business impact and trend.

Automation opportunities

Automate notifications, ticket creation, ownership assignment, policy enforcement and routine remediation.

Logic Apps

Use Logic Apps to route findings, notify owners, open service tickets and trigger approved workflows.

Azure Policy

Use Azure Policy to deploy required controls and prevent insecure configuration.

Workflow automation

Connect Defender for Cloud recommendations and alerts to repeatable operational processes.

Ticket integration

Create and update work items so remediation activity remains visible outside the security portal.

Resource tagging

Use tags to identify criticality, owner, environment, application and data classification.

Infrastructure as code

Correct insecure deployment templates so the same weakness does not return.

Automated validation

Where possible, verify that remediation changed the security state and closed the recommendation.

Secure Score KPI

Track Secure Score as one measure of progress, not as the only measure of programme success.

Critical finding KPI

Track the number, age and ownership of unresolved critical recommendations.

Mean remediation time

Measure the average time taken to move from detection to verified closure.

Attack path KPI

Track open attack paths and the time required to remove their highest-risk links.

Coverage KPI

Track subscriptions and workloads missing the intended Defender plan.

Exception ageing KPI

Track exceptions approaching expiry and those repeatedly renewed.

Recommendation closure rate

Measure how many recommendations are verified as closed during each reporting period.

Reopened findings

Track recommendations that return after remediation because they reveal weak preventive controls.

Evidence of completion

Confirm remediation through Defender for Cloud reassessment rather than relying only on a closed ticket.

Operational ownership

Security may coordinate the programme, but platform and application teams must own many remediation actions.

RACI model

Define who is responsible, accountable, consulted and informed for posture activities.

Security operations

Security Operations should review severe alerts and attack paths that may indicate active compromise.

Cloud platform team

Platform teams should own shared controls, subscription configuration and Defender plan coverage.

Application teams

Application owners should remediate workload-specific configuration and development issues.

Governance team

Governance teams should review exceptions, policy alignment and overdue business risk.

Continuous improvement

Use lessons from incidents, audits and recurring recommendations to strengthen the operating model.

Quarterly maturity review

Assess whether the programme is becoming more consistent, automated and preventive.

Operational debt

Unowned recommendations and permanent exceptions create hidden security debt.

Tool health

Confirm that connectors, agents, plans, policies and assessment processes continue working.

Change management

Review major cloud changes to ensure new subscriptions and services enter the operating model.

Multicloud operations

Apply the same cadence and ownership standards across Azure, AWS, Google Cloud and hybrid environments.

What Agent Foskett checked

Agent Foskett checked review cadence, owners, coverage, ageing findings, exceptions, reporting and evidence of action.

Best-practice checklist

  • Review new critical exposure every business day.
  • Hold weekly governance meetings.
  • Assign named owners and due dates.
  • Review Secure Score changes in context.
  • Automate notifications and repeatable controls.
  • Track coverage gaps and ageing findings.
  • Review exceptions before expiry.
  • Validate completed remediation.
  • Report monthly risk reduction.
  • Assess programme maturity quarterly.

Continue learning

Module 2 is now complete. Next, begin Module 3 and explore how Microsoft Defender for Cloud protects individual workloads.
⬅ Previous lesson
Lesson 19 — Cloud Security Posture Best PracticesBuild a repeatable CSPM programme using risk-based prioritisation, ownership, automation and measurable improvement.
🏠 Academy home
Microsoft Defender for Cloud AcademyReview the complete roadmap across posture, workloads, compliance and investigation.
📚 Next lesson
Lesson 21 — Just-In-Time VM Access Learn how Microsoft Defender for Cloud reduces attack surfaces by keeping RDP, SSH and other management ports closed until temporary, approved administrator access is required.

How do organisations operationalise Microsoft Defender for Cloud?

Organisations operationalise Microsoft Defender for Cloud by establishing daily review routines, weekly governance, accountable ownership, workflow automation, measurable KPIs and executive reporting.

Operationalising Microsoft Defender for Cloud Lesson

This Agent Foskett lesson explains how to turn Defender for Cloud from a security dashboard into a continuous operational programme that drives remediation, accountability and measurable risk reduction.