Agent Foskett Academy • Microsoft Defender for Cloud • Module 3 • Lesson 30

Lesson 30 — Workload Protection Best Practices

Enabling a Defender plan is not the same as proving that every important workload is protected.

Mature workload protection depends on consistent plan enablement, healthy monitoring components, complete asset coverage, clear ownership, usable telemetry and regular validation across Azure, AWS, Google Cloud and hybrid environments.

This lesson brings Lessons 21–29 together into one repeatable operating model for measuring coverage, finding protection gaps, validating deployment health and ensuring that critical workloads do not fall outside security monitoring.

Every Defender plan was enabled—except on the workload that was attacked.
Agent Foskett Workload Protection Best Practices lesson
What you will learn

This lesson turns individual Defender plans into a measurable workload-protection programme.

Coverage validation
Monitoring health
Operational ownership
Continuous improvement

Workload protection operating model

Discover every cloud and hybrid workload

Classify ownership, environment and business criticality

Match the workload to the correct Defender plan

Enable the plan at the correct scope

Deploy required connectors, agents and extensions

Validate monitoring coverage and telemetry health

Route alerts to an accountable security owner

Review recommendations, vulnerabilities and attack paths

Remediate gaps and validate reassessment

Measure coverage and exceptions

Repeat as the environment changes

Workload protection scorecard

AreaQuestionEvidence
InventoryDo we know every relevant workload?Asset inventory and cloud connectors.
Plan coverageIs the correct Defender plan enabled?Environment settings and coverage workbook.
Component healthAre required agents, sensors and extensions reporting?Monitoring coverage and service health.
TelemetryCan investigators access useful evidence?Logs, alerts and connected workspaces.
OwnershipWho investigates and remediates?Resource tags, CMDB and incident routing.
RemediationAre findings being resolved?Recommendations, tickets and reassessment.
ExceptionsAre accepted gaps documented and temporary?Exemption record and expiry date.

Learning objectives

  • Design a repeatable workload-protection programme.
  • Validate Defender plan coverage.
  • Identify unprotected resources and subscriptions.
  • Review monitoring-component health.
  • Assign operational ownership.
  • Measure alerting and logging gaps.
  • Continuously improve multicloud protection.

What is workload protection?

Workload protection applies threat detection and runtime security to servers, storage, databases, containers, applications, APIs, secrets and other cloud services.

Coverage is the first control

Security teams cannot investigate a workload that is outside inventory, disconnected or missing the required Defender plan.

Plan enablement

Review Environment settings to confirm the correct Defender plans are enabled for every relevant subscription and connected cloud account.

Subscription consistency

New subscriptions should inherit the same security baseline as existing production subscriptions rather than relying on manual configuration.

Management groups

Use management-group governance and Azure Policy to drive consistent Defender for Cloud onboarding across subscriptions.

Resource-level overrides

Some plans support resource-specific settings. Track overrides carefully so exceptions do not become hidden protection gaps.

Coverage workbook

Use available Defender coverage workbooks and dashboards to understand which plans are enabled and which resources remain unprotected.

Workload protections dashboard

The Workload protections dashboard provides a unified view of workload security alerts, protected resources and plan coverage.

Asset inventory

Compare Defender coverage with Asset inventory so every critical workload has an owner, business classification and expected protection plan.

Server protection

Validate Defender for Servers plan selection, Defender for Endpoint integration, vulnerability assessment and sensor health.

Storage protection

Confirm Defender for Storage is enabled where sensitive files, uploads, backups or data exports are stored.

Database protection

Validate SQL, Cosmos DB and open-source database coverage according to platform, engine and service support.

Container protection

Confirm clusters, registries, images and runtime workloads are onboarded across AKS, EKS, GKE and Azure Arc-enabled Kubernetes.

Key Vault protection

Ensure critical vaults have Defender threat detection, logging, least-privilege access and recovery controls.

App Service protection

Protect internet-facing web apps and APIs and confirm application, identity and deployment telemetry are available for investigation.

API protection

Identify important APIs, onboard supported API Management collections and review unauthenticated, sensitive and internet-facing endpoints.

Plan scope

Understand exactly which subscriptions, resources, regions, tiers and workload types each Defender plan covers.

Feature dependencies

Some protections require sensors, extensions, cloud connectors, Azure Policy assignments or supporting agents.

Monitoring coverage

Review the Monitoring coverage column in Environment settings to identify missing or unhealthy components.

Extension health

Confirm required extensions are deployed, reporting and supported. Presence alone does not prove healthy telemetry.

Defender for Endpoint health

For servers, validate endpoint onboarding, sensor health, device visibility and recent telemetry.

Agentless coverage

Where agentless scanning is used, confirm the feature is enabled and supported resources are being assessed.

Cloud connectors

Review AWS and Google Cloud connectors, permissions, regions, organisational scope and onboarding status.

Azure Arc

Validate Arc-enabled servers and Kubernetes clusters remain connected and continue reporting current information.

New resource discovery

New resources should enter Defender inventory automatically and receive the expected plan before production use.

Decommissioning

Remove retired assets from inventory, connectors, monitoring and ownership records so stale resources do not distort coverage reporting.

Criticality tagging

Tag or classify workloads by environment, owner, data sensitivity and business criticality to support risk-based review.

Production prioritisation

Production, internet-facing and data-rich workloads should receive the strongest protection and fastest remediation.

Ownership

Every protected workload should have an accountable technical owner and a security contact.

Security operations ownership

Define who receives Defender alerts, who investigates them and who can contain the affected workload.

Platform ownership

Cloud platform teams should own plan deployment, connector health, policy assignment and shared monitoring components.

Application ownership

Application teams should remediate code, identity, configuration and dependency weaknesses identified through workload protection.

Alert routing

Ensure Defender alerts reach the correct SOC queue, incident platform, Microsoft Sentinel workspace or operational owner.

Alert fatigue

Do not suppress alerts simply because ownership or tuning is weak. Investigate recurring patterns and improve the underlying control.

Severity and context

Prioritise alerts using business impact, exposed entry points, privileged identities, sensitive data and attack-path context.

Logging coverage

Defender alerts are stronger when investigators can access platform, identity, application, network and workload logs.

Retention

Retain logs long enough to support investigation, compliance and threat hunting across delayed or low-and-slow attacks.

Time synchronisation

Accurate timestamps are essential when correlating activity across cloud platforms, endpoints, applications and identity systems.

Secure Score

Use Secure Score to identify plan and monitoring gaps, but validate actual protection rather than relying on the score alone.

Recommendations

Review recommendations for missing Defender plans, unhealthy agents, unprotected resources and weak workload configuration.

Attack paths

Use attack paths to identify when an unprotected workload creates a route toward critical assets.

Vulnerability management

Connect vulnerability findings to running, exposed and business-critical workloads rather than treating every CVE equally.

Remediation validation

After changing a plan or component, confirm Defender reassesses the resource and the coverage gap is actually closed.

Exception management

Document accepted gaps with an owner, reason, compensating controls, review date and expiry.

Cost governance

Review Defender pricing and usage, but do not leave critical workloads unprotected simply because ownership or budgeting is unclear.

Change management

Cloud architecture changes, mergers, new subscriptions and service migrations should trigger a coverage review.

Daily review

Review critical workload alerts, failed protection components and new unprotected production resources every business day.

Weekly review

Review plan coverage, connector health, overdue recommendations and unresolved ownership gaps each week.

Monthly review

Report coverage percentage, monitoring health, critical exceptions, alert trends and remediation progress each month.

Quarterly review

Reassess plan selection, cloud scope, data sensitivity, emerging workload types and programme maturity each quarter.

Agent Foskett investigation: “Every Defender plan was enabled…”

The organisation reported full Defender for Cloud coverage

Every known production subscription showed enabled plans

A new project team created a separate Azure subscription

The subscription bypassed the normal landing-zone process

A public-facing App Service and storage account were deployed

Defender plans were never enabled

Diagnostic logs were not configured

No security owner was assigned

The application was exploited

The SOC received no Defender alert

Agent Foskett compared tenant inventory with Defender coverage

The missing subscription appeared immediately

Management-group policy was updated

New subscriptions were automatically onboarded

Coverage reporting included unknown and unprotected resources

Ownership became mandatory before production deployment

Every Defender plan had been enabled

Except on the workload that was attacked
Coverage is measured against everything that exists—not only the subscriptions the security team already knows about.

Workload protection validation checklist

CheckExpected resultEvidence
Subscription scopeEvery production subscription is onboarded.Management-group inventory and Environment settings.
Plan selectionRelevant Defender plans are enabled.Defender plans and pricing configuration.
Resource coverageCritical workloads appear as protected.Coverage workbook and workload dashboard.
Monitoring healthRequired agents and extensions are reporting.Monitoring coverage and endpoint health.
Alert routingSecurity alerts reach an accountable owner.Incident queue, Sentinel and notification testing.
LoggingInvestigators can retrieve supporting telemetry.Log Analytics, platform logs and application logs.
ExceptionsEvery gap has an owner and expiry.Exemption and risk-acceptance record.
ReassessmentRemediated gaps disappear from reporting.Updated recommendation and coverage status.

Key takeaways

  • Workload protection begins with complete asset discovery and inventory.
  • Plan enablement must be consistent across subscriptions and connected cloud accounts.
  • Coverage workbooks and dashboards help identify unprotected resources.
  • Monitoring-component health is as important as plan status.
  • Agents, extensions, connectors and endpoint sensors must be validated continuously.
  • Every protected workload requires a technical owner and a security-response path.
  • Alerts need supporting identity, platform, application and network telemetry.
  • Recommendations, Secure Score and attack paths help identify protection gaps.
  • Exceptions must be documented, owned and temporary.
  • Coverage must be measured against the entire environment, including newly created and previously unknown resources.

What Agent Foskett checked

  • Management groups
  • Subscriptions
  • Cloud connectors
  • Defender plans
  • Coverage workbook
  • Monitoring components
  • Agent health
  • Asset inventory
  • Resource owners
  • Alert routing
  • Exceptions
  • Reassessment status

Best practices

  • Onboard subscriptions automatically.
  • Use management-group policy.
  • Review coverage workbooks.
  • Validate monitoring health.
  • Tag critical workloads.
  • Assign named owners.
  • Route alerts centrally.
  • Retain investigation logs.
  • Review exceptions regularly.
  • Measure coverage continuously.

Continue learning

Module 3 is complete. Next, begin Module 4 and use Defender for Cloud findings to support regulatory compliance, investigation and response.

What are Microsoft Defender for Cloud workload protection best practices?

Workload protection best practices include consistent Defender plan enablement, complete asset coverage, healthy monitoring components, clear ownership, central alert routing, useful logging and continuous validation across cloud and hybrid environments.

Workload Protection Best Practices Lesson

This Agent Foskett lesson explains Defender plan coverage, monitoring health, multicloud onboarding, ownership, alert routing, exception management, validation and continuous improvement.