Almost everything an Azure security audit runs on is already sitting unused in your subscription at no cost.
The secure score, the cloud security benchmark and the ability to pull in other cloud providers all live in the free Foundational tier of Defender for Cloud. Hardly anybody has ever turned them on. We look at what your estate genuinely contains and then tell you which parts actually warrant paying for.

- Foundational CSPMFree, and usually not enabled
- Subscription-wideIdentity, network, data, workloads
- Free firstWe use what you already have
- AWS and GCP tooMulticloud connection is free
Eight areas, starting with the tooling you already own.
Turn on what is free before buying anything
Defender for Cloud ships with a free foundational tier, and that tier explicitly covers the secure score, centralized policy management with the cloud security benchmark built in, the posture dashboard, and connecting AWS and Google Cloud environments alongside. In most estates we assess, not one of those is switched on. That is a real finding, and fixing it costs nothing at all.
Who can do what, across subscriptions
Who holds what at management group, subscription and resource group level, how many people carry Owner or Contributor, whether those assignments are permanent or activated only when needed, and which service principals and managed identities hold anything significant. Service principals are the ones companies lose sight of, because each was created during a deployment and nobody was ever handed responsibility for it afterward.
What is reachable from the internet
Public addresses, management ports facing the internet, storage accounts and databases reachable from the public network, application endpoints, and anything still listening from a project that wrapped up two years ago. This section produces something urgent more often than any other, and the cause is nearly always a temporary arrangement nobody ever undid rather than anybody deciding it was fine.
Where the data is and how it is protected
Storage accounts and databases, and how access to them actually works. Network restrictions, how shared access signatures get issued, encryption and where the keys live, and whether anything holding personal or regulated data is reachable more widely than anybody meant. Shared access tokens come up again and again, because they are trivially easy to issue, long lived unless somebody says otherwise, and awkward to revoke one at a time.
Key Vault, secrets, and whatever is sitting in plain text somewhere
Whether secrets actually live in Key Vault or are scattered through application settings, pipeline variables and configuration files, who is able to read them, whether anybody would know if they had been read, and whether something is due to expire that nobody is watching. The pattern we see constantly is a Key Vault that exists, is used correctly by the newest workload, and is quietly bypassed by everything built before it.
Policy, and whether anything is actually enforced
Which policies are assigned, how many of them merely observe rather than prevent, and whether exemptions handed out as a temporary measure were ever revisited. Centralized policy management is in the free tier, so an estate carrying no policy assignments does not have a licensing problem, it has an unconfigured one. Policy that actually enforces is the only thing that stops the estate sliding back after you have tidied it.
Logging, retention, and whether an investigation is possible
Which resources are sending diagnostic logs anywhere, where those end up, how long they survive, and whether an alert would reach a person who would act on it. Retention here is a decision somebody made rather than a default that happens to suit you, and companies typically discover exactly how far back their logs go in the middle of an investigation rather than before one.
Which paid plans are actually worth it for you
The paid posture plan adds attack path analysis, the security explorer, regulatory compliance reporting and governance. The workload plans are separate again, covering servers, containers, storage, databases, Key Vault, App Service, APIs and Resource Manager individually. Which of them earns a place depends entirely on what you actually run, and for a small estate the honest answer is usually rather fewer than a vendor would put in a proposal.
Turn the free tier on and go and read the score.
Of everything on this page, this is the most useful, and you can do it yourself before the end of the day. What is included at no cost is published openly, and it covers considerably more than most people assume.
- Defender for Cloud comes with a free foundational tier. Explicitly named within it: the secure score, centralized policy management with the cloud security benchmark built in as a standard, the posture dashboard, and multicloud coverage so AWS and Google Cloud environments can be brought into the same view.
- What you get from that is a ranked list of misconfigurations across the whole estate without spending a cent. What you do not get is attack path analysis, the security explorer, compliance reporting or governance rules, all of which sit in the paid posture plan, nor any of the workload protection. It will however tell you whether there is a problem here worth looking into properly.
- What the score is emphatically not is a rating to be optimized. It is computed against a baseline that knows nothing whatsoever about your business, so it hands out points for controls you have no use for while saying nothing at all about the one thing that would genuinely hurt you. Treat it as a starting index and a trend line. Never as an answer.
- This matters commercially because a great many proposals open with purchasing Defender plans. Occasionally that is the right call. But an estate where the free tier has never been switched on has no idea what its actual problems are, and buying advanced tooling before establishing that is simply the wrong order to do things in.
Four things that stop this turning into a licensing proposal.
The free tier gets used before any paid one is recommended
The foundational tier hands you the secure score, policy management, the cloud security benchmark and multicloud connection for nothing. We switch that on and read it before anything else, because it establishes what your real problems are. Recommending the paid posture plan or workload protection before knowing that is selling ahead of diagnosing, and it produces spending that bears no relationship to the actual risk.
We separate what is urgent from what is untidy
Any Azure estate will produce a long list of recommendations, and most of them are housekeeping. A management port facing the internet, a service principal with far more rights than it needs, and a storage account holding personal data reachable from anywhere are a different category altogether. The report opens with that second group, because a list of a hundred items gets filed and a list of five gets fixed.
We connect findings to the obligations you actually carry
Where HIPAA applies, or GLBA and the FTC Safeguards Rule, or a state privacy law, or SOC 2 commitments, or simply the security terms in a contract with a large customer, the findings worth caring about are the ones touching those obligations. We map them rather than reporting generically, which also makes the fixes easier to get funded, because the justification is a specific obligation rather than a security preference.
We look at the estate you actually have, including whatever sits outside Azure
Connecting AWS and Google Cloud is part of the free tier, so where you run workloads across more than one provider they can all come into a single view rather than assessing Azure on its own. A great many American companies have a primary platform and a second one that arrived through an acquisition or a single project, and the second one is always, without exception, the less governed of the two.
Six situations that bring US organizations to an Azure audit.
A customer or insurer has asked specific questions
Questions about who can reach what, how it is encrypted, what gets logged and what is exposed to the network, all of which somebody has to answer accurately and in writing, whether on a security questionnaire, an insurance application or a SOC 2 evidence request. The audit produces those answers and, more valuably, tells you which ones you ought to fix before you answer them. This is the most common reason people call and the one with the clearest finish line.
Azure grew from one project into an estate
It began with one workload, it worked, and five years on there are several subscriptions, resources nobody will claim ownership of, and access granted for reasons long since forgotten. Nothing is exactly wrong, and nobody has ever examined the whole thing at once. These audits dependably turn up things worth fixing and rarely turn up a crisis, which is precisely the right moment to be looking.
A financial firm under GLBA, FTC Safeguards, or NYDFS Part 500
Governance of the cloud, control over access, and the ability to prove both come up in every examination and assessment, and for a firm running anything material in Azure that proof lives inside the subscription itself. Where NYDFS Part 500 applies, lining up its requirements against your actual configuration is work worth doing on your own schedule rather than during an examination.
An organization holding personal or regulated data in Azure
HIPAA if you are a covered entity or a business associate, and CCPA and CPRA alongside the other state privacy laws where consumer data is involved. The practical questions are where that data physically sits in the estate, who can reach it, whether anything outside can reach it, and whether you could prove who has opened it. Every one of those is an audit question long before it becomes a legal one.
A company that inherited an estate from an engineer who left
One person built the whole thing, understood the whole thing, and has since moved on. What is left is infrastructure nobody can fully account for, carrying service principals, automation and access whose purpose was never written down anywhere. The first value of an audit here is simply an accurate picture, well before anybody starts talking about improving it.
After a cost review raised uncomfortable questions
When finance goes looking at Azure spend, what usually surfaces is resources nobody can account for, and that is a security question every bit as much as a cost one. Anything running without an owner is also anything running without anybody patching it, watching it or securing it. The two exercises overlap far more than people expect and are worth running together.
What we find when we audit an Azure estate.
| Feature | Governed | Grown by accretion | Unexamined |
|---|---|---|---|
Complete inventory of subscriptions and owners | Partial | ||
Defender for Cloud switched on, at minimum on the free tier | Sometimes | ||
Secure score tracked as a trend | |||
Privileged role assignments reviewed | Rarely | ||
Service principals owned and understood | |||
Internet exposure known and intentional | Partly | ||
Secrets held in Key Vault | Newer workloads only | In config files | |
Policy enforces rather than only audits | Audit only | None | |
Diagnostic logging with deliberate retention | Default or absent | ||
Resources from finished projects removed |
Defender for Cloud capabilities by plan.
Capability
Secure score
- Plan
- Foundational CSPM, free
Capability
Centralized policy management
- Plan
- Foundational CSPM, free
Capability
Microsoft cloud security benchmark as a built-in standard
- Plan
- Foundational CSPM, free
Capability
CSPM dashboard
- Plan
- Foundational CSPM, free
Capability
Connect AWS and GCP environments
- Plan
- Foundational CSPM, free
Capability
Code pipeline insights
- Plan
- Foundational CSPM and Defender CSPM
Capability
Attack path analysis
- Plan
- Defender CSPM
Capability
Cloud security explorer
- Plan
- Defender CSPM
Capability
Regulatory compliance reporting
- Plan
- Defender CSPM
Capability
Security governance rules
- Plan
- Defender CSPM
Capability
Data security posture management
- Plan
- Defender CSPM or Defender for Storage
Capability
Server, container, storage, database and other workload protection
- Plan
- Separate CWPP plans, per workload type
Five stages, typically one to two weeks.
- 1
Inventory the estate and enable what is free
Every subscription, who owns it, what runs in it, and Defender for Cloud enabled at least on Foundational CSPM so the secure score and benchmark recommendations are available. For many organizations this stage alone produces the first useful output, because the complete subscription list does not currently exist anywhere.
- 2
Identity and access review
Role assignments across management groups, subscriptions, and resource groups, privileged role holders, whether access is standing or activated when needed, and the service principals and managed identities that hold meaningful rights. This is where the highest-severity findings usually sit, and it is the part most often missing from automated reports.
- 3
Exposure and data review
What the internet can currently reach, which network restrictions exist on storage and databases, how shared access tokens get issued and whether anybody could revoke one, encryption and where keys are held, and where regulated data physically sits. We work from the configuration as it stands rather than from whatever the policy says it ought to be.
- 4
Logging, policy, and detection review
Diagnostic settings resource type by resource type, where the logs land and how long they survive there, whether an alert reaches a person, which policies are assigned and whether they prevent anything or merely observe, and which exemptions were handed out temporarily and never looked at again.
- 5
Report, prioritize, and decide what to buy
Findings ordered by how exploitable they actually are rather than by whatever severity a tool assigned, and split between what costs configuration effort and what would cost money. Where a paid plan genuinely earns its place given what you run, we name it and explain why. Where it does not, you hear that too, and the recommendation is the free tier plus some configuration work.
What organizations ask about Azure security audits.
Fifteen questions about your own subscriptions.
What actually exists
- How many Azure subscriptions do you have, and who owns each?Shadow subscriptions on a departmental card are common.
- Has Defender for Cloud been enabled at all, even on the free tier?Free, and usually not switched on.
- What does the secure score say, and has anybody actually opened it?A starting index, not a target to optimize.
- Are there resources from projects that finished?They keep running, keep costing, and keep being exposed.
- Can you name which resources are holding personal or regulated data?Needed for HIPAA, GLBA, and state privacy laws alike.
Exposure
- How many resources have a public IP address?Count them. The number is usually a surprise.
- Are any management ports reachable from the internet?The most common route into a cloud estate.
- Do storage accounts or databases allow public network access?Check per resource, not per policy intention.
- At subscription level, how many people are carrying Owner or Contributor?And is that access permanent or activated when needed.
- Which service principals hold significant permissions?Created during deployments, rarely owned afterwards.
Could you investigate
- Are diagnostic logs enabled on resources that matter?Off by default on many resource types.
- Where do the logs actually end up, and how far back do they reach?Retention is a configuration decision, not a sensible default.
- Would an alert ever reach somebody who would do something about it?Collection without response is not detection.
- Do the secrets live in Key Vault, or in application settings and build pipelines?The older the workload, the more likely the latter.
- Does any policy assignment actually prevent anything, or do they all just observe?A policy that only observes records the drift. It does not prevent any of it.
The pages around this one.
Microsoft 365 security audit
The tenant side of the same Microsoft estate. Identity, mail, sharing, devices, and how far back your evidence genuinely goes.
Microsoft Defender for Cloud
The posture and workload protection platform this audit works with, and what each plan actually adds.
Cybersecurity audit and compliance
The broader audit practice, and how to work out which sort of engagement your situation genuinely needs.
Turn on the free tier, then go and count your public addresses.
Both are free, both fit in an afternoon, and between them they will tell you whether there is a problem here. If you want help making sense of what comes back, or a proper look at the estate behind it, that is a short conversation and we will tell you what we would open first.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Independent Microsoft 365 tenant security audit for US organizations
Learn moreCloud Security Posture Audit
Cloud security posture audits for US organizations: true inventory
Learn moreActive Directory Security Audit
On-premises Active Directory security audit for US organizations:
Learn moreMicrosoft Defender
Advanced endpoint and email threat protection
Learn moreVulnerability Assessment
Vulnerability assessment for US businesses across external attack
Learn more