Lesson 30 — Workload Protection Best Practices
Enabling a Defender plan is not the same as proving that every important workload is protected.
Mature workload protection depends on consistent plan enablement, healthy monitoring components, complete asset coverage, clear ownership, usable telemetry and regular validation across Azure, AWS, Google Cloud and hybrid environments.
This lesson brings Lessons 21–29 together into one repeatable operating model for measuring coverage, finding protection gaps, validating deployment health and ensuring that critical workloads do not fall outside security monitoring.
What you will learn
This lesson turns individual Defender plans into a measurable workload-protection programme.
Workload protection operating model
↓
Classify ownership, environment and business criticality
↓
Match the workload to the correct Defender plan
↓
Enable the plan at the correct scope
↓
Deploy required connectors, agents and extensions
↓
Validate monitoring coverage and telemetry health
↓
Route alerts to an accountable security owner
↓
Review recommendations, vulnerabilities and attack paths
↓
Remediate gaps and validate reassessment
↓
Measure coverage and exceptions
↓
Repeat as the environment changes
Workload protection scorecard
| Area | Question | Evidence |
|---|---|---|
| Inventory | Do we know every relevant workload? | Asset inventory and cloud connectors. |
| Plan coverage | Is the correct Defender plan enabled? | Environment settings and coverage workbook. |
| Component health | Are required agents, sensors and extensions reporting? | Monitoring coverage and service health. |
| Telemetry | Can investigators access useful evidence? | Logs, alerts and connected workspaces. |
| Ownership | Who investigates and remediates? | Resource tags, CMDB and incident routing. |
| Remediation | Are findings being resolved? | Recommendations, tickets and reassessment. |
| Exceptions | Are accepted gaps documented and temporary? | Exemption record and expiry date. |
Learning objectives
- Design a repeatable workload-protection programme.
- Validate Defender plan coverage.
- Identify unprotected resources and subscriptions.
- Review monitoring-component health.
- Assign operational ownership.
- Measure alerting and logging gaps.
- Continuously improve multicloud protection.
What is workload protection?
Workload protection applies threat detection and runtime security to servers, storage, databases, containers, applications, APIs, secrets and other cloud services.
Coverage is the first control
Security teams cannot investigate a workload that is outside inventory, disconnected or missing the required Defender plan.
Plan enablement
Review Environment settings to confirm the correct Defender plans are enabled for every relevant subscription and connected cloud account.
Subscription consistency
New subscriptions should inherit the same security baseline as existing production subscriptions rather than relying on manual configuration.
Management groups
Use management-group governance and Azure Policy to drive consistent Defender for Cloud onboarding across subscriptions.
Resource-level overrides
Some plans support resource-specific settings. Track overrides carefully so exceptions do not become hidden protection gaps.
Coverage workbook
Use available Defender coverage workbooks and dashboards to understand which plans are enabled and which resources remain unprotected.
Workload protections dashboard
The Workload protections dashboard provides a unified view of workload security alerts, protected resources and plan coverage.
Asset inventory
Compare Defender coverage with Asset inventory so every critical workload has an owner, business classification and expected protection plan.
Server protection
Validate Defender for Servers plan selection, Defender for Endpoint integration, vulnerability assessment and sensor health.
Storage protection
Confirm Defender for Storage is enabled where sensitive files, uploads, backups or data exports are stored.
Database protection
Validate SQL, Cosmos DB and open-source database coverage according to platform, engine and service support.
Container protection
Confirm clusters, registries, images and runtime workloads are onboarded across AKS, EKS, GKE and Azure Arc-enabled Kubernetes.
Key Vault protection
Ensure critical vaults have Defender threat detection, logging, least-privilege access and recovery controls.
App Service protection
Protect internet-facing web apps and APIs and confirm application, identity and deployment telemetry are available for investigation.
API protection
Identify important APIs, onboard supported API Management collections and review unauthenticated, sensitive and internet-facing endpoints.
Plan scope
Understand exactly which subscriptions, resources, regions, tiers and workload types each Defender plan covers.
Feature dependencies
Some protections require sensors, extensions, cloud connectors, Azure Policy assignments or supporting agents.
Monitoring coverage
Review the Monitoring coverage column in Environment settings to identify missing or unhealthy components.
Extension health
Confirm required extensions are deployed, reporting and supported. Presence alone does not prove healthy telemetry.
Defender for Endpoint health
For servers, validate endpoint onboarding, sensor health, device visibility and recent telemetry.
Agentless coverage
Where agentless scanning is used, confirm the feature is enabled and supported resources are being assessed.
Cloud connectors
Review AWS and Google Cloud connectors, permissions, regions, organisational scope and onboarding status.
Azure Arc
Validate Arc-enabled servers and Kubernetes clusters remain connected and continue reporting current information.
New resource discovery
New resources should enter Defender inventory automatically and receive the expected plan before production use.
Decommissioning
Remove retired assets from inventory, connectors, monitoring and ownership records so stale resources do not distort coverage reporting.
Criticality tagging
Tag or classify workloads by environment, owner, data sensitivity and business criticality to support risk-based review.
Production prioritisation
Production, internet-facing and data-rich workloads should receive the strongest protection and fastest remediation.
Ownership
Every protected workload should have an accountable technical owner and a security contact.
Security operations ownership
Define who receives Defender alerts, who investigates them and who can contain the affected workload.
Platform ownership
Cloud platform teams should own plan deployment, connector health, policy assignment and shared monitoring components.
Application ownership
Application teams should remediate code, identity, configuration and dependency weaknesses identified through workload protection.
Alert routing
Ensure Defender alerts reach the correct SOC queue, incident platform, Microsoft Sentinel workspace or operational owner.
Alert fatigue
Do not suppress alerts simply because ownership or tuning is weak. Investigate recurring patterns and improve the underlying control.
Severity and context
Prioritise alerts using business impact, exposed entry points, privileged identities, sensitive data and attack-path context.
Logging coverage
Defender alerts are stronger when investigators can access platform, identity, application, network and workload logs.
Retention
Retain logs long enough to support investigation, compliance and threat hunting across delayed or low-and-slow attacks.
Time synchronisation
Accurate timestamps are essential when correlating activity across cloud platforms, endpoints, applications and identity systems.
Secure Score
Use Secure Score to identify plan and monitoring gaps, but validate actual protection rather than relying on the score alone.
Recommendations
Review recommendations for missing Defender plans, unhealthy agents, unprotected resources and weak workload configuration.
Attack paths
Use attack paths to identify when an unprotected workload creates a route toward critical assets.
Vulnerability management
Connect vulnerability findings to running, exposed and business-critical workloads rather than treating every CVE equally.
Remediation validation
After changing a plan or component, confirm Defender reassesses the resource and the coverage gap is actually closed.
Exception management
Document accepted gaps with an owner, reason, compensating controls, review date and expiry.
Cost governance
Review Defender pricing and usage, but do not leave critical workloads unprotected simply because ownership or budgeting is unclear.
Change management
Cloud architecture changes, mergers, new subscriptions and service migrations should trigger a coverage review.
Daily review
Review critical workload alerts, failed protection components and new unprotected production resources every business day.
Weekly review
Review plan coverage, connector health, overdue recommendations and unresolved ownership gaps each week.
Monthly review
Report coverage percentage, monitoring health, critical exceptions, alert trends and remediation progress each month.
Quarterly review
Reassess plan selection, cloud scope, data sensitivity, emerging workload types and programme maturity each quarter.
Agent Foskett investigation: “Every Defender plan was enabled…”
↓
Every known production subscription showed enabled plans
↓
A new project team created a separate Azure subscription
↓
The subscription bypassed the normal landing-zone process
↓
A public-facing App Service and storage account were deployed
↓
Defender plans were never enabled
↓
Diagnostic logs were not configured
↓
No security owner was assigned
↓
The application was exploited
↓
The SOC received no Defender alert
↓
Agent Foskett compared tenant inventory with Defender coverage
↓
The missing subscription appeared immediately
↓
Management-group policy was updated
↓
New subscriptions were automatically onboarded
↓
Coverage reporting included unknown and unprotected resources
↓
Ownership became mandatory before production deployment
↓
Every Defender plan had been enabled
↓
Except on the workload that was attacked
Workload protection validation checklist
| Check | Expected result | Evidence |
|---|---|---|
| Subscription scope | Every production subscription is onboarded. | Management-group inventory and Environment settings. |
| Plan selection | Relevant Defender plans are enabled. | Defender plans and pricing configuration. |
| Resource coverage | Critical workloads appear as protected. | Coverage workbook and workload dashboard. |
| Monitoring health | Required agents and extensions are reporting. | Monitoring coverage and endpoint health. |
| Alert routing | Security alerts reach an accountable owner. | Incident queue, Sentinel and notification testing. |
| Logging | Investigators can retrieve supporting telemetry. | Log Analytics, platform logs and application logs. |
| Exceptions | Every gap has an owner and expiry. | Exemption and risk-acceptance record. |
| Reassessment | Remediated gaps disappear from reporting. | Updated recommendation and coverage status. |
Key takeaways
- Workload protection begins with complete asset discovery and inventory.
- Plan enablement must be consistent across subscriptions and connected cloud accounts.
- Coverage workbooks and dashboards help identify unprotected resources.
- Monitoring-component health is as important as plan status.
- Agents, extensions, connectors and endpoint sensors must be validated continuously.
- Every protected workload requires a technical owner and a security-response path.
- Alerts need supporting identity, platform, application and network telemetry.
- Recommendations, Secure Score and attack paths help identify protection gaps.
- Exceptions must be documented, owned and temporary.
- Coverage must be measured against the entire environment, including newly created and previously unknown resources.
What Agent Foskett checked
- Management groups
- Subscriptions
- Cloud connectors
- Defender plans
- Coverage workbook
- Monitoring components
- Agent health
- Asset inventory
- Resource owners
- Alert routing
- Exceptions
- Reassessment status
Best practices
- Onboard subscriptions automatically.
- Use management-group policy.
- Review coverage workbooks.
- Validate monitoring health.
- Tag critical workloads.
- Assign named owners.
- Route alerts centrally.
- Retain investigation logs.
- Review exceptions regularly.
- Measure coverage continuously.
Related Agent Foskett resources
Continue learning
What are Microsoft Defender for Cloud workload protection best practices?
Workload protection best practices include consistent Defender plan enablement, complete asset coverage, healthy monitoring components, clear ownership, central alert routing, useful logging and continuous validation across cloud and hybrid environments.
Workload Protection Best Practices Lesson
This Agent Foskett lesson explains Defender plan coverage, monitoring health, multicloud onboarding, ownership, alert routing, exception management, validation and continuous improvement.
