Lesson 1 — What is Microsoft Defender for Cloud?
Microsoft Defender for Cloud is Microsoft’s Cloud Native Application Protection Platform, bringing cloud security posture management, DevSecOps security and cloud workload protection into one connected security experience.
It helps organisations understand what resources they have, where those resources are exposed, which security recommendations matter, how attack paths form and when cloud workloads show signs of active compromise.
This foundation lesson explains where Defender for Cloud fits, how CSPM differs from workload protection, what Secure Score and recommendations provide, how Azure, hybrid, AWS and Google Cloud environments connect, and how cloud findings support practical investigation and response.

What you will learn
This lesson introduces the platform, its core security pillars and the investigation mindset used throughout the academy.
Learning objectives
After completing this lesson, you should be able to explain the role of Microsoft Defender for Cloud and recognise its main security capabilities.
- Define Defender for Cloud as a CNAPP.
- Explain CSPM, DevSecOps and CWPP.
- Describe Secure Score and recommendations.
- Recognise the role of Defender plans.
- Explain hybrid and multicloud coverage.
- Understand alerts, attack paths and investigation context.
- Identify how Defender for Cloud connects with the Microsoft security ecosystem.
The problem this solves
Cloud environments change continuously. New resources, identities, permissions, networks and workloads can appear faster than security teams can review them manually.
Defender for Cloud provides a central way to discover risk, prioritise improvement and detect threats across those changing environments.
Defender for Cloud at a glance
What is a CNAPP?
A Cloud Native Application Protection Platform brings multiple cloud security capabilities together across the application lifecycle.
Instead of treating posture, development and runtime protection as separate problems, a CNAPP connects them into one security view.
The three core pillars
Defender for Cloud combines cloud security posture management, development security operations and cloud workload protection.
Each pillar answers a different question: what is exposed, what entered through development, and what is under active threat.
Core capability comparison
| Capability | Main question | Typical output |
|---|---|---|
| CSPM | Where is the environment weak or exposed? | Recommendations, Secure Score, attack paths and posture insights |
| DevSecOps | Can risk be identified before deployment? | Code, pipeline and infrastructure-as-code findings |
| CWPP | Is a protected workload under attack? | Security alerts, threat detections and workload-specific protection |
Cloud Security Posture Management
CSPM continuously evaluates cloud assets and configurations to identify weaknesses, exposed resources and security control gaps.
It helps security teams move from a long list of technical findings toward prioritised risk reduction.
Foundational and advanced posture
Defender for Cloud includes foundational posture capabilities, while the Defender CSPM plan adds advanced features.
Plan availability, included features and licensing should be reviewed before deployment because the platform continues to evolve.
Security recommendations
Recommendations describe security improvements that can reduce risk across affected resources.
A recommendation should be reviewed with its severity, affected assets, business impact, remediation steps and attack-path context.
Cloud Secure Score
Cloud Secure Score provides a measurable view of security posture based on supported recommendations.
The score is useful for tracking improvement, but it should not replace risk-based prioritisation or business judgement.
Posture workflow
Attack paths
An attack path shows how exposed resources, identities, permissions and vulnerabilities can combine into a realistic route toward a critical asset.
This is more useful than treating each misconfiguration as an isolated finding.
Cloud Security Explorer
Cloud Security Explorer helps analysts investigate relationships across cloud resources and security context.
Graph-style questions can reveal risky combinations that are difficult to identify from separate asset lists.
DevSecOps security
DevSecOps capabilities help connect cloud security with source code, pipelines and infrastructure-as-code.
The goal is to identify risk before vulnerable or misconfigured resources reach production.
Code-to-cloud context
When development and runtime information are connected, teams can trace a deployed resource back to the code or pipeline that created it.
This supports faster ownership, remediation and prevention of repeated mistakes.
Cloud Workload Protection
CWPP protects cloud workloads from threats after they are deployed and running.
Defender plans provide workload-specific capabilities for servers, storage, databases, containers, APIs and other supported services.
What are Defender plans?
Defender plans enable additional protection for selected workload types and deployment scopes.
They can add threat detection, vulnerability assessment, malware scanning, runtime monitoring and security alerts depending on the workload.
Workload protection examples
| Defender plan | Protected area | Example risk |
|---|---|---|
| Defender for Servers | Windows and Linux machines | Vulnerabilities, suspicious processes and server compromise |
| Defender for Storage | Azure Storage | Malware, suspicious access and data exfiltration |
| Defender for Containers | Kubernetes and container environments | Vulnerable images and suspicious runtime behaviour |
| Defender for Databases | Supported database services | Unusual queries, access and potential data compromise |
| Defender for Key Vault | Keys, secrets and certificates | Unusual or harmful access attempts |
| Defender for APIs | Managed APIs | API exposure, vulnerabilities and active threats |
Security alerts
Security alerts identify suspicious or potentially harmful activity affecting protected workloads.
An alert can include affected resources, entities, evidence, severity, attack techniques and recommended actions.
Recommendations versus alerts
A recommendation usually describes a weakness that could be exploited. An alert usually describes suspicious activity or a detected threat.
Both matter because an exposed resource and an active attacker can become part of the same incident.
Recommendation and alert comparison
| Finding | Meaning | Typical response |
|---|---|---|
| Recommendation | A security control or configuration should be improved | Prioritise and remediate the weakness |
| Attack path | Multiple weaknesses form a route to a critical asset | Break the path at the highest-value point |
| Security alert | Suspicious or malicious activity has been detected | Investigate, contain and respond |
| Compliance failure | A resource does not meet a mapped control | Review evidence, ownership and remediation |
Azure coverage
Azure subscriptions can be assessed for posture and configured with Defender plans at supported scopes.
Management groups, subscriptions, resource groups and individual resources all influence how coverage and policy are organised.
Hybrid resources
Azure Arc can connect supported non-Azure servers and Kubernetes environments so they can participate in Azure management and Defender for Cloud protection.
Coverage depends on onboarding, extensions, agents and selected plans.
Multicloud environments
Defender for Cloud can connect supported AWS accounts and Google Cloud projects for posture and workload visibility.
Connector permissions, deployment templates and plan enablement determine which capabilities are available.
Environment connection model
Resource inventory
Inventory helps security teams identify cloud assets and understand which resources are assessed, protected or exposed.
Good investigations begin by confirming what the resource is, where it lives, who owns it and which security plans cover it.
Regulatory compliance
The regulatory compliance experience maps technical assessments to supported standards and controls.
It supports governance and evidence gathering, but it does not automatically prove complete organisational compliance.
Microsoft Defender portal integration
Defender for Cloud capabilities are integrated into the Microsoft Defender portal, bringing cloud posture and threat protection closer to the wider security operations experience.
Portal availability and feature placement can change, so operational documentation should be reviewed regularly.
Microsoft Sentinel integration
Defender for Cloud findings can contribute to Microsoft Sentinel incidents, analytics, automation and hunting workflows.
This helps a SOC correlate cloud workload activity with identities, endpoints, applications and other telemetry.
Cloud investigation workflow
Agent Foskett investigation: “The virtual machine was secure… until the network path was followed.”
Investigation evidence
- Cloud resource details and inventory
- Security recommendations
- Attack paths
- Cloud Security Explorer queries
- Security alerts and incidents
- Azure Activity Logs
- Microsoft Entra sign-in and audit logs
- Defender XDR and Sentinel evidence
- Resource ownership and change history
Common mistakes
- Treating Defender for Cloud as antivirus for virtual machines.
- Chasing Secure Score without considering business risk.
- Reviewing recommendations without attack-path context.
- Assuming every resource is covered by a paid Defender plan.
- Connecting AWS or GCP without validating permissions and coverage.
- Ignoring identities attached to cloud resources.
- Treating compliance results as complete proof of compliance.
Best practices
- Start with an accurate inventory of environments and resources.
- Confirm Defender plan coverage and deployment scope.
- Prioritise attack paths and critical assets.
- Assign recommendation owners and due dates.
- Connect posture findings with active security alerts.
- Integrate cloud evidence with Sentinel and Defender XDR.
- Review Microsoft documentation as capabilities evolve.
Key takeaways
- Microsoft Defender for Cloud is a Cloud Native Application Protection Platform.
- Its core pillars are CSPM, DevSecOps and cloud workload protection.
- CSPM identifies posture weaknesses and prioritises improvement.
- Cloud Secure Score tracks supported posture improvements.
- Recommendations describe weaknesses; alerts describe suspicious activity.
- Attack paths connect separate weaknesses into realistic risk.
- Defender plans add workload-specific protection.
- Azure, hybrid, AWS and Google Cloud environments can be brought into the platform.
- Defender for Cloud connects with the Microsoft Defender portal and Microsoft Sentinel.
- Cloud investigations must follow the resource, identity, permission, exposure and attack path.
Related Agent Foskett resources
Continue learning
What is Microsoft Defender for Cloud?
Microsoft Defender for Cloud is a Cloud Native Application Protection Platform that combines cloud security posture management, DevSecOps security and cloud workload protection across Azure, hybrid and multicloud environments.
Microsoft Defender for Cloud Academy Lesson 1
This Agent Foskett lesson explains CNAPP, CSPM, CWPP, Cloud Secure Score, recommendations, attack paths, Defender plans, multicloud coverage and cloud investigation workflows.
