We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender for Cloud
Microsoft Defender for Cloud

The posture management tier is free, and most Azure subscriptions have never switched it on.

The product scores your cloud security posture, measures it against a built-in benchmark that reaches across AWS and GCP as well as Azure, and defends servers, containers, storage, databases and APIs through separate plans you switch on only where each one earns its keep. That first part costs nothing whatsoever, and almost nobody has enabled it.

Book a cloud posture reviewSee what is free and what is not
Microsoft Defender for Cloud for US organizations
  • Free tierFoundational CSPM, including secure score
  • AWS and GCPMulticloud, agentless
  • Attack pathsHow an attacker would actually get in
  • Ten plansEnabled selectively, not all at once
Start with what costs nothing

Four capabilities are in the free foundational tier.

The documentation says plainly that free foundational CSPM capabilities are included. In our experience most American Azure estates have never enabled a single one of them, which makes this the cheapest security improvement any of them could make.

  • Secure score summarizes your posture out of the security recommendations and rises as you remediate them. It gives you a figure to report upward and a ranked list to work down, both running on subscriptions you are already paying for.
  • Centralized policy management turns your security conditions into recommendations naming the resources that violate them, with the Microsoft cloud security benchmark sitting there as a built-in standard spanning Azure, AWS and GCP alike.
  • Multicloud coverage connects AWS and GCP environments agentlessly for posture insight, letting a mixed estate be assessed against a single benchmark rather than turning into three separate conversations.
  • Code pipeline insights connect GitHub, Azure DevOps and GitLab to surface infrastructure as code misconfigurations and exposed secrets. Beyond the free tier, paid Defender CSPM adds attack path analysis, the cloud security explorer, regulatory compliance, governance and data security posture management. Those are the capabilities worth taking to a budget conversation, once the free tier has already shown you where you stand.
Have us switch on the free tier and interpret it before anything else
What it covers

Eight capabilities, and the line between free and paid.

It is described as a cloud native application protection platform built from three core components: cloud security posture management, development security operations, and cloud workload protection. The first of those three carries a free tier that most businesses have never once turned on.

Secure score, in the free foundational tier

Free foundational CSPM capabilities are included, and secure score sits among them. It summarizes your posture from the security recommendations and climbs as you remediate them. Any business holding Azure subscriptions with no posture management in place at all gets a genuine, immediate improvement here, costing nothing beyond the effort of acting on what it tells you.

AWS and GCP in the same view, also free

Multicloud coverage lives in that foundational tier as well, connecting AWS and GCP environments agentlessly for posture insight. Plenty of American businesses ended up multicloud through an acquisition, a particular workload requirement, or a decision a developer made that nobody ever reviewed. For those, a single posture view spanning all three providers is usually the first occasion anybody has seen the complete picture.

The Microsoft cloud security benchmark, applied across providers

Centralized policy management is another free tier capability, turning security conditions into recommendations that name the resources violating your policy. Behind it sits the Microsoft cloud security benchmark, a built-in standard applying security principles with detailed technical implementation guidance for Azure and, importantly, for other providers including AWS and GCP. What that hands a mixed estate is one consistent yardstick instead of three separate ones.

Attack path analysis is the paid capability that genuinely justifies its cost

It models traffic moving across your environment to identify potential risks before you change anything, with the cloud security explorer letting you query a map of that environment directly. This is what turns a list of eight hundred recommendations into the small handful that genuinely chain together into a route somebody could walk. Those two documents produce entirely different conversations at board level.

Workload plans you enable selectively

Individual plans cover servers, containers, storage, databases, App Service, Key Vault, Resource Manager, APIs and AI services. The design intent is that you enable whatever your estate genuinely contains rather than the full set, and the plan by plan decision is exactly where the cost conversation belongs. Most businesses need two or three of them. Almost none need ten.

Storage protection, including SAS token misuse

Protection here covers malware, threats specific to storage, leakage of sensitive data and misuse of Shared Access Signature tokens. That final item deserves emphasis. SAS tokens get handed around freely during projects, are almost never revoked afterwards, are frequently scoped far wider than they needed to be, and nobody monitors them. They come up as a finding in Azure estate after Azure estate.

DevOps security, from code rather than after deployment

Code pipeline insights connect your GitHub, Azure DevOps and GitLab repositories, surfacing infrastructure as code misconfigurations and exposed secrets, then correlating those findings against cloud security context so remediation can be prioritized where the code lives. This appears under the foundational free tier as well as under Defender CSPM, which makes it an unusually inexpensive place to begin.

AI workload security, which is newly relevant

AI security posture management discovers the generative AI applications running in your environment and identifies their vulnerabilities, producing what is termed an AI bill of materials, while AI threat protection watches for threats aimed at those workloads. Anyone building on Azure OpenAI needs this simply to know which AI workloads exist, and that list is regularly longer than anything the security team was told about.

How we approach it

Four things that stop this turning into a very expensive dashboard.

Enabling this everywhere is easy, and so is leaving it generating hundreds of recommendations that belong to nobody. Value comes from what actually gets fixed rather than from what gets flagged.

The free tier goes on and gets interpreted before we propose anything you pay for

At no cost, foundational CSPM hands you a secure score, recommendations driven by policy, multicloud posture and code pipeline insights. Working through that first shows you the shape of the problem, establishes a baseline you can measure future progress against, and ensures every plan decision afterwards rests on your own findings rather than on a sales conversation.

We prioritize by attack path, not by recommendation count

A large estate throws off hundreds of recommendations, and working through them by severity alone is both slow and demoralizing for the people doing it. Attack path analysis picks out the chains that genuinely lead somewhere, and that list is invariably far shorter. Break one link and the entire path disappears, which is a considerably better use of a limited engineering budget.

We enable plans selectively and say so

Ten plans exist and most estates warrant two or three of them. We map what you genuinely run against the plans covering it, and we name the ones we would leave switched off just as clearly, because recommending you buy everything is not advice. Where the free tier is sufficient for a given workload, we say so.

We settle ownership before turning on alerting

Every workload protection plan produces security alerts, and an alert needs somebody to respond to it. Before enabling any of them we establish who receives an alert, who owns remediating a misconfiguration inside a given subscription, and what happens when one arrives at two in the morning. Across a multi-subscription estate, ownership is the genuinely difficult question, and it is the one determining whether anything improves at all.

Where this matters most

Six US situations where cloud posture is the actual gap.

What connects these is an Azure estate that grew through a series of projects rather than to any plan, which describes the majority of the ones we are asked to assess.

An estate with subscriptions nobody can fully account for

Some were created for projects, some inherited through an acquisition, and some spun up by a developer holding a corporate card and formalized long afterwards. Turning the free posture tier on across every subscription is the fastest route to seeing what genuinely exists and how exposed each part is. The inventory on its own usually justifies the exercise.

A regulated firm needing cloud compliance evidence

When a SOC 2 auditor, a HIPAA assessor, an NYDFS Part 500 examiner or an enterprise customer asks how your cloud workloads are secured and against which standard, the regulatory compliance capability inside Defender CSPM maps your posture onto recognized standards and generates the evidence in a form that goes straight into the audit pack.

A development team shipping infrastructure as code

Connecting GitHub, Azure DevOps and GitLab through code pipeline insights surfaces infrastructure as code misconfigurations and exposed secrets while they are still text rather than deployed resources. Catching one in a pull request costs a few minutes of an engineer attention. Catching the same thing in production, after an auditor found it first, costs a great deal more than that.

An organization that ended up multicloud without deciding to

One workload on AWS because a vendor insisted, something on GCP that arrived with an acquisition, and everything else on Azure. Connecting AWS and GCP agentlessly for posture insight sits in the free tier, and assessing all three against the Microsoft cloud security benchmark is usually the first genuinely consistent view anybody in the business has had.

A business running production databases and storage in Azure

Defender for Databases reaches Azure SQL, SQL running on machines, the open-source relational databases and Cosmos DB. Defender for Storage handles malware, leakage of sensitive data and misuse of SAS tokens. Wherever the data effectively is the business, those two plans justify themselves faster than any of the others.

An organization building on Azure OpenAI

The posture side discovers your generative AI applications and identifies their vulnerabilities, producing an AI bill of materials in the process, while threat protection watches for attacks aimed at those workloads. For most businesses the first piece of value is simply establishing which AI workloads exist at all, since that list routinely runs longer than anything the security team was ever told about.

Three positions

What organizations actually know about their cloud security posture.

More organizations sit in the right column than will readily admit it, and negligence is rarely the reason. Subscriptions get created for individual projects, workloads move around, and nobody was ever made responsible for the posture of the estate as a whole.
A posture score you can track over time
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Misconfigurations surfaced against a benchmark
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
AWS and GCP in the same view
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Attack paths identified across resources
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Sensitive data located across cloud storage
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Regulatory compliance reporting
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Threat detection on servers and containers
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Storage and SAS token misuse detected
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Infrastructure as code issues caught before deployment
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Could answer a SOC 2 cloud question from a report
Defender for Cloud in useYes
Free tier onlyPartly
Nothing enabledNo
Feature
Defender for Cloud in use
Free tier only
Nothing enabled
A posture score you can track over time
YesYesNo
Misconfigurations surfaced against a benchmark
YesYesNo
AWS and GCP in the same view
YesYesNo
Attack paths identified across resources
YesNoNo
Sensitive data located across cloud storage
YesNoNo
Regulatory compliance reporting
YesNoNo
Threat detection on servers and containers
YesNoNo
Storage and SAS token misuse detected
YesNoNo
Infrastructure as code issues caught before deployment
YesYesNo
Could answer a SOC 2 cloud question from a report
YesPartlyNo
The plans

Ten plans, and what each one is actually protecting.

Taken from the published plan list. The decision in front of you is which of these your estate genuinely contains, because enabling every one is neither necessary nor the way this product was designed to be purchased.

Plan

Foundational CSPM, free

What it protects
Posture management, secure score, policy, the multicloud connection and code pipeline insights

Plan

Defender CSPM

What it protects
Attack path analysis, the cloud security explorer, governance, regulatory compliance, and posture for data and AI

Plan

Defender for Servers

What it protects
Windows and Linux machines wherever they run, whether Azure, AWS, GCP or your own building

Plan

Defender for Containers

What it protects
Kubernetes hardening, vulnerability assessment and runtime protection

Plan

Defender for Storage

What it protects
Malware, threats particular to storage, leakage of sensitive data, and misuse of SAS tokens

Plan

Defender for Databases

What it protects
Azure SQL, SQL running on machines, the open-source relational databases and Cosmos DB

Plan

Defender for App Service

What it protects
Attacks aimed at the web applications and APIs you run on App Service

Plan

Defender for Key Vault

What it protects
Unusual or hostile attempts to reach or exploit a Key Vault account

Plan

Defender for Resource Manager

What it protects
Unusual and potentially harmful resource management operations

Plan

Defender for APIs

What it protects
Visibility across the APIs your business depends on, with threat detection in real time

Plan

AI Services

What it protects
Threats to generative AI applications, detected in real time
PlanWhat it protects
Foundational CSPM, freePosture management, secure score, policy, the multicloud connection and code pipeline insights
Defender CSPMAttack path analysis, the cloud security explorer, governance, regulatory compliance, and posture for data and AI
Defender for ServersWindows and Linux machines wherever they run, whether Azure, AWS, GCP or your own building
Defender for ContainersKubernetes hardening, vulnerability assessment and runtime protection
Defender for StorageMalware, threats particular to storage, leakage of sensitive data, and misuse of SAS tokens
Defender for DatabasesAzure SQL, SQL running on machines, the open-source relational databases and Cosmos DB
Defender for App ServiceAttacks aimed at the web applications and APIs you run on App Service
Defender for Key VaultUnusual or hostile attempts to reach or exploit a Key Vault account
Defender for Resource ManagerUnusual and potentially harmful resource management operations
Defender for APIsVisibility across the APIs your business depends on, with threat detection in real time
AI ServicesThreats to generative AI applications, detected in real time
How an engagement runs

Five steps, and the first one is free.

Three to six weeks to reach a working state, depending on how large the estate is. Technical enablement happens quickly. What consumes the calendar is establishing ownership across your subscriptions.
  1. 1

    Enable foundational CSPM across every subscription

    That includes the subscriptions nobody remembered existed, plus connecting AWS and GCP wherever those are in play. All of this is the free tier. It produces a secure score and a ranked set of recommendations, and it sets the baseline everything afterwards gets measured against.

  2. 2

    Interpret the findings rather than forwarding them

    A large estate generates a great many recommendations, and handing over the raw list accomplishes nothing at all. We go through them alongside your team, separating what is genuinely exposed from what is merely theoretically imperfect, and produce a remediation list somebody could realistically finish inside a quarter.

  3. 3

    Decide which workload plans your estate warrants

    Plans get mapped against what you actually run, whether that is servers, containers, storage, databases, App Service, Key Vault, APIs or AI services. We name the ones we would leave off with the same clarity as the ones we would switch on, because enabling selectively is how this product was designed to be used.

  4. 4

    Add attack path analysis and prioritize by chain

    Wherever Defender CSPM is justified, attack path analysis and the cloud security explorer between them cut hundreds of findings down to the handful of chains genuinely leading somewhere. That is the moment the reporting stops being a compliance artifact and starts driving actual engineering decisions.

  5. 5

    Establish ownership and the response path

    Four questions get answered: who owns remediation within each subscription, how a recommendation turns into a ticket somebody works, who receives a security alert from a workload plan, and what happens to that alert outside working hours. Governance rules can assign tasks to resource owners and track their progress, and that mechanism is what keeps the score from drifting back down again.

Straight answers

What organizations ask about Defender for Cloud.

A meaningful proportion of it. Free foundational CSPM capabilities are included, and the free tier is documented as covering secure score, centralized policy management, multicloud coverage for AWS and GCP, the posture dashboard and code pipeline insights. In our experience most American Azure estates have never switched any of it on, which makes this both the cheapest security improvement available to them and the obvious place to begin.

The foundational tier costs nothing and delivers posture visibility, meaning your score, the recommendations, policy and the multicloud connection. Defender CSPM is the paid tier, and what it adds are the capabilities making those findings actionable at scale: attack path analysis, the cloud security explorer, regulatory compliance verification, security governance for assigning and tracking remediation, data security posture management and AI security posture management.

It does, and the connection requires no agents. Multicloud coverage is listed within the free foundational tier, and the Microsoft cloud security benchmark is described as a built-in standard offering detailed technical implementation guidance for Azure alongside other providers including AWS and GCP. What a mixed estate gets from that is one benchmark and one view, in place of three separate assessments nobody can reconcile.

What it does is model your environment to work out how individual risks chain together into a route somebody could genuinely walk, instead of listing misconfigurations one by one. A small estate throwing off few findings may not need it, and the free tier will do. A large estate producing hundreds of recommendations usually finds it the single most valuable paid capability on offer, because it converts an unmanageable backlog into a short list where breaking one link removes an entire path.

You should not, and there is no need. Ten plans exist, spanning servers, containers, storage, databases, App Service, Key Vault, Resource Manager, APIs, AI services and CSPM, and the whole product assumes you will enable selectively based on what your estate actually holds. Most of the businesses we work with need two or three. We will be as clear about the ones we would leave off as about the ones we would switch on.

An audit is a point-in-time assessment that produces a findings report and a remediation list, and it is the right choice when you need an independent view or a specific answer for a specific auditor. This is continuous posture management running inside the platform itself. The sequence that works is enabling the free tier first, since it may well answer most of what an audit would have told you, then commissioning the audit to cover whatever it does not reach.

From August 1, 2023, anyone holding an existing Defender for DNS subscription can carry on using it as a standalone plan. For new subscriptions, alerts about suspicious DNS activity arrive as part of Defender for Servers Plan 2 instead. The documentation is explicit that the protection scope has not changed at all. What changed is how DNS protection gets billed and bundled, not what it covers.

Four things are listed: malware, threats specific to storage, leakage of sensitive data, and misuse of Shared Access Signature tokens. That last one deserves highlighting. Across most Azure estates, tokens get issued freely during projects, scoped generously for convenience, almost never revoked afterwards and monitored by nobody. It comes up as a finding again and again, and it is exactly the kind of exposure that no amount of network security will ever address.

It does, and this is among the more underused capabilities in the whole product. Code pipeline insights connect your GitHub, Azure DevOps and GitLab repositories, surfacing infrastructure as code misconfigurations and exposed secrets, then correlating those against cloud security context so that remediation gets prioritized where the code actually is. It appears in the free foundational tier as well as in Defender CSPM, so there is very little standing between you and trying it.

On the posture side it discovers generative AI applications, identifies their vulnerabilities and reduces the risk through built-in recommendations and attack path analysis, producing what is described as an AI bill of materials. Threat protection then detects attacks aimed at those generative AI workloads in real time, and a data and AI security dashboard sits alongside both. The most common first finding, by a considerable margin, is how many AI workloads turn out to exist that the security team knew nothing about.

For the moment both, and the balance is shifting. The product is documented as expanding into the Defender portal to give one unified security experience across cloud and code environments, with a number of features already living there and more arriving. The documentation now tells you which portal any given article applies to. Practically speaking, plan for the Defender portal becoming the primary home over time.

Microsoft Defender Experts for Servers is a managed detection and response service that puts Microsoft analysts behind a Defender for Servers deployment, covering Windows and Linux servers across Azure, AWS, GCP and on-premises alike. It is sold separately from Plan 1 and Plan 2, and you opt in when you want detection and response operated on your behalf. We can also cover that response function through our own managed security services, and both options are worth putting side by side before you decide.

Most estates reach a working state in three to six weeks. Switching the free tier on takes hours. Interpreting what it reports takes a week or two depending on size. Deciding which workload plans you need goes quickly once the estate is understood. What genuinely consumes time is establishing who owns remediation inside each subscription, and that is a series of conversations rather than a configuration task. Commercially we scope each engagement individually, driven by subscription count, whether AWS and GCP are included, and whether you want remediation delivered or simply identified. Microsoft bills the plan costs separately. In the first conversation we will tell you at no charge whether the free foundational tier is already enabled, and if it is not, that is where we would start regardless of anything else you are considering.
Before deploying

Fifteen questions worth answering first.

Group one establishes what you actually run, which decides which plans matter to you. Group two covers what you already hold at no cost. Group three asks whether anybody will act on the findings, and that is what separates having a score from making an improvement.

What you actually run

  • How many Azure subscriptions do you have?
    Including the ones a project team created and forgot.
  • Do you also have AWS or GCP workloads?
    Multicloud posture is in the free tier.
  • Do you run containers or Kubernetes?
    A separate plan, and a common blind spot.
  • Do you have storage accounts with SAS tokens issued?
    SAS misuse is specifically covered.
  • Are you building anything on Azure OpenAI?
    AI posture management applies.

What you already have

  • Has foundational CSPM ever been enabled?
    It is free and frequently untouched.
  • Do you know your current secure score?
    If not, that is the first number to get.
  • Are your repositories connected?
    Code pipeline insights are in the free tier.
  • Is the Microsoft cloud security benchmark applied?
    Built in, and covers AWS and GCP too.
  • Do you have Defender for Servers Plan 2?
    It now includes suspicious DNS activity alerts.

Would findings be acted on

  • Who owns remediation of a cloud misconfiguration?
    Frequently nobody, which is the real finding.
  • Is there a change process for production subscriptions?
    Recommendations become tickets or they become noise.
  • Would attack path findings reach a decision maker?
    They are the ones worth escalating.
  • Do you need regulatory compliance reporting?
    That sits in the paid Defender CSPM plan.
  • Do you have anybody watching alerts out of hours?
    Workload plans generate alerts that need a responder.
Related reading

The pages around this one.

Cybersecurity audit and compliance

An independent point-in-time assessment, and where it differs from continuous posture management running inside the platform.

Learn more

Cloud migration services

The wider platform work: architecture, migration and the estate this posture applies to.

Learn more

Defender for Endpoint

The endpoint half of this same product family, which Defender for Servers builds on to protect servers.

Learn more
Next step

Go and find your secure score. It costs nothing and an afternoon covers it.

Foundational CSPM costs nothing, reaches every subscription including the ones nobody remembers creating, and connects AWS and GCP without agents. Should that number come back badly, you will know exactly what to do next. Should it come back well, you have just saved yourself a purchase.

Book a cloud posture reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Servers

Defender for Servers engagements for US organizations: estate

Learn more

Microsoft Defender for Storage

Defender for Storage deployment for US organizations: storage

Learn more

Microsoft Defender for Containers

Container and Kubernetes security for US organizations using Defender

Learn more

Microsoft Defender for SQL

Defender for SQL deployment for US organizations: the full SQL estate

Learn more

Microsoft Defender for APIs

API security for US organizations using Defender for APIs: APIs

Learn more

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA