Agent Foskett Academy • Microsoft Defender for Cloud • Module 4 • Lesson 31

Lesson 31 — Regulatory Compliance Dashboard

Workload protection tells you whether security controls are active. Regulatory compliance tells you how those controls align with an assigned standard.

The Microsoft Defender for Cloud Regulatory Compliance Dashboard shows enabled standards, their controls, the assessments beneath those controls and the resources that are compliant or noncompliant.

This lesson explains how standards are assigned through Azure Policy initiatives, how the dashboard presents compliance progress, how to drill from a standard to an affected resource, and how to distinguish technical compliance evidence from an external audit conclusion.

The audit said they were compliant. The dashboard showed that an entire subscription had never been assessed.
Agent Foskett Regulatory Compliance Dashboard lesson
What you will learn

This lesson follows compliance reporting from standard assignment through control review, remediation and reassessment.

Standards and controls
Assessments
Evidence and scope
Continuous compliance

Regulatory compliance drill-down

Select the required management group or subscription

Open the Regulatory Compliance Dashboard

Select an assigned standard

Review failed or incomplete controls

Open the underlying assessment

Identify affected resources

Review the linked recommendation or policy result

Assign remediation ownership

Correct the resource or document a justified exemption

Wait for reassessment

Confirm the updated control and resource status

Preserve dated evidence for reporting

Compliance hierarchy

LevelPurposeExample question
StandardRepresents the selected benchmark or framework.Which standard are we measuring?
ControlGroups related compliance requirements.Which area of the standard is failing?
AssessmentEvaluates a technical requirement.What condition is being checked?
ResourceShows the actual assessed cloud asset.Which workload is noncompliant?
RecommendationProvides security and remediation guidance.What action should be taken?
EvidenceSupports governance and audit review.What proves the status at this time?

Learning objectives

  • Explain the Regulatory Compliance Dashboard.
  • Understand how standards are assigned.
  • Navigate standards, controls and assessments.
  • Identify compliant and noncompliant resources.
  • Distinguish Cloud Secure Score from compliance status.
  • Review remediation and reassessment.
  • Use dashboard evidence responsibly.

What is regulatory compliance?

Regulatory compliance measures how technical and operational controls align with an assigned benchmark, framework or standard.

What is the dashboard?

The Regulatory Compliance Dashboard presents enabled compliance standards, their controls, assessments and affected resources in Microsoft Defender for Cloud.

Monitoring versus assignment

The dashboard is used to monitor assigned standards. Standards are configured and assigned through the Azure portal using Defender for Cloud and Azure Policy experiences.

Default benchmark

The Microsoft Cloud Security Benchmark is the default Microsoft-authored security and compliance benchmark shown in Defender for Cloud.

Additional standards

Other supported standards must be assigned explicitly before they appear for a scope with relevant assessed resources.

Azure Policy initiatives

Regulatory standards are represented through Azure Policy initiatives that group policy definitions and assessments into a compliance structure.

Scope

Standards can be assigned at management-group or subscription scope depending on governance requirements and permissions.

Management-group inheritance

A management-group assignment can provide consistent compliance coverage to child subscriptions.

Missing assignments

A new subscription that does not inherit the expected initiative can remain outside the intended compliance view.

Standards view

The dashboard lists enabled standards and their current compliance position for the selected scope.

Controls

Controls group related requirements within a standard and provide a higher-level view than individual technical findings.

Assessments

Assessments evaluate resources against technical requirements and feed status into the relevant control.

Recommendations

Many failed assessments are connected to Defender for Cloud recommendations that explain the security issue and remediation approach.

Affected resources

Drill into an assessment to identify which resources are healthy, unhealthy, exempt or not applicable.

Compliant resources

A compliant resource currently satisfies the assessed technical condition for that policy or recommendation.

Noncompliant resources

A noncompliant resource does not satisfy the assessed requirement and should be reviewed for remediation, exemption or scope accuracy.

Not applicable

An assessment may not apply to a resource because the control is irrelevant to that resource type or configuration.

Exempt resources

Exemptions document accepted risk or justified nonapplication. They should never be used merely to improve a percentage.

Unknown or unavailable status

Missing data, delayed evaluation or unsupported resources can prevent a clear compliance result and require investigation.

Customer responsibility

Customer-responsible controls require the organisation to implement and maintain the relevant technical or operational measure.

Microsoft responsibility

Microsoft-responsible controls relate to Microsoft-managed cloud service obligations and may include implementation or attestation information.

Shared responsibility

Shared controls require both Microsoft and the customer to fulfil different parts of the compliance requirement.

Compliance percentage

A compliance percentage summarises assessed status but does not explain risk, scope completeness or audit readiness on its own.

Cloud Secure Score

Cloud Secure Score measures security posture using open recommendations and risk context. It is not the same as compliance against a selected standard.

Compliance is not certification

A green dashboard does not automatically certify the organisation or replace legal, regulatory or independent audit conclusions.

Technical evidence

The dashboard provides technical assessment evidence that can support governance and audit processes.

Operational evidence

Policies, procedures, approvals, training, contracts and manual controls may sit outside Defender for Cloud and still be required by a standard.

Continuous assessment

Defender for Cloud continually reassesses the selected scope, but evaluation and display updates are not necessarily immediate.

Evaluation delay

Allow time for Azure Policy and Defender assessments to refresh after assignments or remediation.

Drill-down workflow

Start with the standard, open a control, select the failed assessment and then review affected resources and remediation guidance.

Resource context

Consider business criticality, internet exposure, data sensitivity and ownership when prioritising failed assessments.

Remediation

Follow the linked recommendation or policy guidance to correct the underlying resource configuration.

Bulk remediation

Some Azure Policy effects support remediation tasks that can correct existing resources at scale.

Automatic remediation

DeployIfNotExists and Modify policies can help bring new or existing resources into compliance when configured correctly.

Manual controls

Some compliance obligations require evidence or actions that cannot be assessed automatically.

Custom initiatives

Organisations can use custom Azure Policy initiatives to represent internal standards and control requirements.

Multicloud compliance

Connected AWS and Google Cloud resources can contribute to compliance views where supported policies and standards apply.

Resource inventory comparison

Compare compliance scope with Asset inventory so unassessed subscriptions or disconnected cloud accounts are not mistaken for compliant ones.

Permissions

Users require appropriate Azure and Defender for Cloud permissions to assign standards, view assessments and manage exemptions.

Exporting results

Exported or downloaded compliance data can support reporting, but the date, scope and evaluation status must be recorded.

Executive reporting

Leadership reporting should explain major failed controls, affected business services, remediation owners and trend—not only a percentage.

Audit preparation

Use the dashboard to identify technical evidence and gaps before an audit, then combine it with required operational documentation.

Common mistake: wrong scope

A high score for one subscription does not prove that the entire tenant or business environment is covered.

Common mistake: missing standard

If a standard was never assigned, its absence from the dashboard does not mean the environment satisfies it.

Common mistake: percentage chasing

Do not exempt difficult findings simply to increase the displayed compliance result.

Common mistake: stale evidence

Compliance exports are point-in-time evidence and should not be reused without confirming the environment and assessment date.

Common mistake: ignoring inheritance

Review management-group and subscription assignments so policy inheritance matches the intended governance design.

Initial investigation

When a control unexpectedly fails, confirm the selected scope, initiative assignment, policy parameters and affected-resource list.

Assignment investigation

Review which management group or subscription holds the initiative assignment and whether exclusions were configured.

Policy investigation

Confirm the policy definition, effect, parameters, applicability and latest evaluation result.

Resource investigation

Review the resource configuration, ownership, deployment history and whether remediation could affect production workloads.

Validation

After remediation, confirm the resource is reassessed and the control status changes rather than relying only on a closed ticket.

Secure Score and regulatory compliance

Cloud Secure ScoreRegulatory Compliance Dashboard
Measures overall cloud security posture.Measures technical alignment with assigned standards.
Uses open recommendations and risk context.Uses controls and assessments mapped to standards.
Helps prioritise security improvements.Helps monitor compliance progress and evidence.
Is not a regulatory certification.Is not an external audit or legal conclusion.
Can improve without satisfying every framework.Can vary by standard, scope and assignment.

Agent Foskett investigation: “The audit said they were compliant…”

The annual compliance report was completed

Management believed all Azure workloads were covered

A new subscription had been created after the audit scope was defined

The subscription was placed outside the expected management group

The compliance initiative was never inherited

Critical workloads in that subscription were not assessed

Agent Foskett compared Asset inventory with the compliance scope

The missing subscription appeared immediately

The management-group structure was corrected

The required standard was assigned

Azure Policy evaluated the resources

Several failed controls appeared

Owners remediated the affected resources

The dashboard was reassessed

The audit evidence was updated with the correct scope

The audit had described the environment it reviewed

The dashboard revealed the environment that had been missed
Unassessed resources are not compliant resources. They are resources outside the evidence.

Regulatory compliance investigation checklist

AreaQuestionEvidence
ScopeWhich management groups, subscriptions and clouds are included?Hierarchy, assignments and connected environments.
StandardIs the correct standard assigned?Compliance policy assignment.
ControlWhich control is failing or incomplete?Dashboard control view.
AssessmentWhat technical condition is being evaluated?Policy and recommendation details.
ResourceWhich asset is noncompliant?Affected-resource list.
ResponsibilityIs the control customer, Microsoft or shared responsibility?Control metadata and standard mapping.
RemediationWho owns the correction and by when?Ticket, governance rule and due date.
EvidenceIs the result current and correctly scoped?Timestamped export and reassessment.

Key takeaways

  • The Regulatory Compliance Dashboard monitors assigned compliance standards.
  • Standards are configured and assigned through the Azure portal using Azure Policy initiatives.
  • The dashboard organises results by standards, controls, assessments and resources.
  • The Microsoft Cloud Security Benchmark is the default Microsoft-authored benchmark.
  • Additional standards must be assigned explicitly.
  • Cloud Secure Score and regulatory compliance measure different things.
  • A compliant technical assessment does not automatically equal legal certification.
  • Scope completeness is essential; unassessed subscriptions can create false confidence.
  • Remediation should be followed by reassessment and updated evidence.
  • Dashboard results should be combined with operational and audit evidence outside Defender for Cloud.

What Agent Foskett checked

  • Management-group hierarchy
  • Subscriptions
  • Assigned standards
  • Policy initiatives
  • Controls
  • Assessments
  • Affected resources
  • Exemptions
  • Recommendations
  • Remediation owners
  • Evaluation time
  • Audit scope

Best practices

  • Assign standards at the correct scope.
  • Use management-group inheritance.
  • Compare compliance with inventory.
  • Review failed controls regularly.
  • Investigate unassessed resources.
  • Document exemptions.
  • Validate policy parameters.
  • Wait for reassessment.
  • Preserve dated evidence.
  • Do not confuse compliance with certification.

Related Agent Foskett resources

Continue developing practical Microsoft Defender for Cloud compliance, governance and investigation skills.

Continue learning

Continue Module 4 by examining how compliance standards, controls and technical assessments are mapped and evaluated.

What is the Microsoft Defender for Cloud Regulatory Compliance Dashboard?

The Regulatory Compliance Dashboard shows assigned compliance standards, controls, assessments and affected resources so organisations can monitor technical compliance progress across cloud environments.

Regulatory Compliance Dashboard Lesson

This Agent Foskett lesson explains standards, Azure Policy initiatives, controls, assessments, resource status, remediation, reassessment, evidence and the difference between compliance status and Cloud Secure Score.