Agent Foskett Academy • Microsoft Defender for Cloud • Module 1 • Lesson 1

Lesson 1 — What is Microsoft Defender for Cloud?

Microsoft Defender for Cloud is Microsoft’s Cloud Native Application Protection Platform, bringing cloud security posture management, DevSecOps security and cloud workload protection into one connected security experience.

It helps organisations understand what resources they have, where those resources are exposed, which security recommendations matter, how attack paths form and when cloud workloads show signs of active compromise.

This foundation lesson explains where Defender for Cloud fits, how CSPM differs from workload protection, what Secure Score and recommendations provide, how Azure, hybrid, AWS and Google Cloud environments connect, and how cloud findings support practical investigation and response.

Defender for Cloud does not protect only one virtual machine. It evaluates posture, relationships and threats across the wider cloud environment.
Agent Foskett Microsoft Defender for Cloud Academy lesson
What you will learn

This lesson introduces the platform, its core security pillars and the investigation mindset used throughout the academy.

CNAPP and cloud security
CSPM and Secure Score
Cloud workload protection
Cloud investigation workflows

Learning objectives

After completing this lesson, you should be able to explain the role of Microsoft Defender for Cloud and recognise its main security capabilities.

  • Define Defender for Cloud as a CNAPP.
  • Explain CSPM, DevSecOps and CWPP.
  • Describe Secure Score and recommendations.
  • Recognise the role of Defender plans.
  • Explain hybrid and multicloud coverage.
  • Understand alerts, attack paths and investigation context.
  • Identify how Defender for Cloud connects with the Microsoft security ecosystem.

The problem this solves

Cloud environments change continuously. New resources, identities, permissions, networks and workloads can appear faster than security teams can review them manually.

Defender for Cloud provides a central way to discover risk, prioritise improvement and detect threats across those changing environments.

Defender for Cloud at a glance

Azure subscriptions ──────────────┐ Hybrid and Arc-enabled resources ─┤ AWS accounts ─────────────────────┤ Google Cloud projects ────────────┤ DevOps environments ──────────────┘ ↓ Microsoft Defender for Cloud ↓ ┌────────────────┼────────────────┐ ↓ ↓ ↓ CSPM DevSecOps CWPP ↓ ↓ ↓ Posture Code-to-cloud Workload and risk visibility protection ↓ Recommendations • Secure Score • Attack Paths • Alerts

What is a CNAPP?

A Cloud Native Application Protection Platform brings multiple cloud security capabilities together across the application lifecycle.

Instead of treating posture, development and runtime protection as separate problems, a CNAPP connects them into one security view.

The three core pillars

Defender for Cloud combines cloud security posture management, development security operations and cloud workload protection.

Each pillar answers a different question: what is exposed, what entered through development, and what is under active threat.

Core capability comparison

CapabilityMain questionTypical output
CSPMWhere is the environment weak or exposed?Recommendations, Secure Score, attack paths and posture insights
DevSecOpsCan risk be identified before deployment?Code, pipeline and infrastructure-as-code findings
CWPPIs a protected workload under attack?Security alerts, threat detections and workload-specific protection

Cloud Security Posture Management

CSPM continuously evaluates cloud assets and configurations to identify weaknesses, exposed resources and security control gaps.

It helps security teams move from a long list of technical findings toward prioritised risk reduction.

Foundational and advanced posture

Defender for Cloud includes foundational posture capabilities, while the Defender CSPM plan adds advanced features.

Plan availability, included features and licensing should be reviewed before deployment because the platform continues to evolve.

Security recommendations

Recommendations describe security improvements that can reduce risk across affected resources.

A recommendation should be reviewed with its severity, affected assets, business impact, remediation steps and attack-path context.

Cloud Secure Score

Cloud Secure Score provides a measurable view of security posture based on supported recommendations.

The score is useful for tracking improvement, but it should not replace risk-based prioritisation or business judgement.

Posture workflow

Resources discovered ↓ Security controls assessed ↓ Recommendations generated ↓ Risk and attack-path context added ↓ Owners prioritise remediation ↓ Configuration improved ↓ Posture and Secure Score reassessed

Attack paths

An attack path shows how exposed resources, identities, permissions and vulnerabilities can combine into a realistic route toward a critical asset.

This is more useful than treating each misconfiguration as an isolated finding.

Cloud Security Explorer

Cloud Security Explorer helps analysts investigate relationships across cloud resources and security context.

Graph-style questions can reveal risky combinations that are difficult to identify from separate asset lists.

DevSecOps security

DevSecOps capabilities help connect cloud security with source code, pipelines and infrastructure-as-code.

The goal is to identify risk before vulnerable or misconfigured resources reach production.

Code-to-cloud context

When development and runtime information are connected, teams can trace a deployed resource back to the code or pipeline that created it.

This supports faster ownership, remediation and prevention of repeated mistakes.

Cloud Workload Protection

CWPP protects cloud workloads from threats after they are deployed and running.

Defender plans provide workload-specific capabilities for servers, storage, databases, containers, APIs and other supported services.

What are Defender plans?

Defender plans enable additional protection for selected workload types and deployment scopes.

They can add threat detection, vulnerability assessment, malware scanning, runtime monitoring and security alerts depending on the workload.

Workload protection examples

Defender planProtected areaExample risk
Defender for ServersWindows and Linux machinesVulnerabilities, suspicious processes and server compromise
Defender for StorageAzure StorageMalware, suspicious access and data exfiltration
Defender for ContainersKubernetes and container environmentsVulnerable images and suspicious runtime behaviour
Defender for DatabasesSupported database servicesUnusual queries, access and potential data compromise
Defender for Key VaultKeys, secrets and certificatesUnusual or harmful access attempts
Defender for APIsManaged APIsAPI exposure, vulnerabilities and active threats

Security alerts

Security alerts identify suspicious or potentially harmful activity affecting protected workloads.

An alert can include affected resources, entities, evidence, severity, attack techniques and recommended actions.

Recommendations versus alerts

A recommendation usually describes a weakness that could be exploited. An alert usually describes suspicious activity or a detected threat.

Both matter because an exposed resource and an active attacker can become part of the same incident.

Recommendation and alert comparison

FindingMeaningTypical response
RecommendationA security control or configuration should be improvedPrioritise and remediate the weakness
Attack pathMultiple weaknesses form a route to a critical assetBreak the path at the highest-value point
Security alertSuspicious or malicious activity has been detectedInvestigate, contain and respond
Compliance failureA resource does not meet a mapped controlReview evidence, ownership and remediation

Azure coverage

Azure subscriptions can be assessed for posture and configured with Defender plans at supported scopes.

Management groups, subscriptions, resource groups and individual resources all influence how coverage and policy are organised.

Hybrid resources

Azure Arc can connect supported non-Azure servers and Kubernetes environments so they can participate in Azure management and Defender for Cloud protection.

Coverage depends on onboarding, extensions, agents and selected plans.

Multicloud environments

Defender for Cloud can connect supported AWS accounts and Google Cloud projects for posture and workload visibility.

Connector permissions, deployment templates and plan enablement determine which capabilities are available.

Environment connection model

Azure tenant ├─ Management groups ├─ Subscriptions └─ Resources │ ├──────── Azure Arc ─────── Hybrid resources │ ├──────── AWS connector ─── AWS accounts │ └──────── GCP connector ─── GCP projects ↓ Defender for Cloud ↓ Posture • Inventory • Recommendations • Alerts • Compliance

Resource inventory

Inventory helps security teams identify cloud assets and understand which resources are assessed, protected or exposed.

Good investigations begin by confirming what the resource is, where it lives, who owns it and which security plans cover it.

Regulatory compliance

The regulatory compliance experience maps technical assessments to supported standards and controls.

It supports governance and evidence gathering, but it does not automatically prove complete organisational compliance.

Microsoft Defender portal integration

Defender for Cloud capabilities are integrated into the Microsoft Defender portal, bringing cloud posture and threat protection closer to the wider security operations experience.

Portal availability and feature placement can change, so operational documentation should be reviewed regularly.

Microsoft Sentinel integration

Defender for Cloud findings can contribute to Microsoft Sentinel incidents, analytics, automation and hunting workflows.

This helps a SOC correlate cloud workload activity with identities, endpoints, applications and other telemetry.

Cloud investigation workflow

Identify the affected cloud resource ↓ Confirm environment, subscription and owner ↓ Review recommendations and exposure ↓ Check attack paths and connected identities ↓ Review security alerts and activity evidence ↓ Correlate with Entra, Defender XDR and Sentinel ↓ Contain immediate risk ↓ Remediate the underlying weakness ↓ Validate posture after recovery

Agent Foskett investigation: “The virtual machine was secure… until the network path was followed.”

1. A virtual machine showed no active malware alert ↓ 2. The operations team considered the resource secure ↓ 3. Defender for Cloud showed a high-risk recommendation ↓ 4. The machine had a public management port ↓ 5. An attached identity held excessive permissions ↓ 6. The identity could reach a sensitive storage account ↓ 7. Attack path analysis connected the exposed VM to critical data ↓ 8. The problem was not one isolated configuration ↓ 9. Network access was restricted and permissions were reduced ↓ 10. The attack path disappeared after remediation
The resource looked quiet. The relationship between exposure, identity and data revealed the real risk.

Investigation evidence

  • Cloud resource details and inventory
  • Security recommendations
  • Attack paths
  • Cloud Security Explorer queries
  • Security alerts and incidents
  • Azure Activity Logs
  • Microsoft Entra sign-in and audit logs
  • Defender XDR and Sentinel evidence
  • Resource ownership and change history

Common mistakes

  • Treating Defender for Cloud as antivirus for virtual machines.
  • Chasing Secure Score without considering business risk.
  • Reviewing recommendations without attack-path context.
  • Assuming every resource is covered by a paid Defender plan.
  • Connecting AWS or GCP without validating permissions and coverage.
  • Ignoring identities attached to cloud resources.
  • Treating compliance results as complete proof of compliance.

Best practices

  • Start with an accurate inventory of environments and resources.
  • Confirm Defender plan coverage and deployment scope.
  • Prioritise attack paths and critical assets.
  • Assign recommendation owners and due dates.
  • Connect posture findings with active security alerts.
  • Integrate cloud evidence with Sentinel and Defender XDR.
  • Review Microsoft documentation as capabilities evolve.

Key takeaways

  • Microsoft Defender for Cloud is a Cloud Native Application Protection Platform.
  • Its core pillars are CSPM, DevSecOps and cloud workload protection.
  • CSPM identifies posture weaknesses and prioritises improvement.
  • Cloud Secure Score tracks supported posture improvements.
  • Recommendations describe weaknesses; alerts describe suspicious activity.
  • Attack paths connect separate weaknesses into realistic risk.
  • Defender plans add workload-specific protection.
  • Azure, hybrid, AWS and Google Cloud environments can be brought into the platform.
  • Defender for Cloud connects with the Microsoft Defender portal and Microsoft Sentinel.
  • Cloud investigations must follow the resource, identity, permission, exposure and attack path.

Continue learning

Continue Module 1 by learning how Cloud Security Posture Management continuously identifies and prioritises cloud risk.
🚀 Academy start
Lesson 1 — What is Microsoft Defender for Cloud?You have started the Defender for Cloud learning path with the platform foundations.
🏠 Academy home
Microsoft Defender for Cloud AcademyReview the complete 40-lesson roadmap across posture, workloads, compliance and investigation.
📚 Next lesson
Lesson 2 — Cloud Security Posture ManagementLearn how CSPM discovers misconfigurations, exposure and security control gaps across cloud resources.

What is Microsoft Defender for Cloud?

Microsoft Defender for Cloud is a Cloud Native Application Protection Platform that combines cloud security posture management, DevSecOps security and cloud workload protection across Azure, hybrid and multicloud environments.

Microsoft Defender for Cloud Academy Lesson 1

This Agent Foskett lesson explains CNAPP, CSPM, CWPP, Cloud Secure Score, recommendations, attack paths, Defender plans, multicloud coverage and cloud investigation workflows.