Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Cloud Security Posture Management (CSPM) is a core feature of Microsoft Defender for Cloud. CSPM provides continuous visibility into the security state of your cloud assets and workloads, offering actionable guidance to improve your security posture in Azure, AWS, and GCP.
Defender for Cloud continually assesses your cloud infrastructure against security standards defined for your Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. Defender for Cloud issues security recommendations to help you identify and reduce cloud misconfigurations and security risks.
For Azure Database for PostgreSQL flexible server, Defender CSPM continuously evaluates server-level and database-level configurations against PostgreSQL security best practices. The assessments identify network security, auditing, and operational resilience issues. If Defender CSPM is already enabled, the assessments provide risk-prioritized recommendations without requiring other configuration.
When Foundational CSPM is enabled, the Microsoft Cloud Security Benchmark (MCSB) standard provides recommendations to help secure your multicloud environment. The secure score based on some of the MCSB recommendations helps you monitor cloud compliance. A higher score indicates a lower identified risk level.
Important
Starting October 27, 2026, Foundational CSPM will move to an opt-in model and will no longer be enabled by default for new Azure subscriptions. The free plan will continue to be available at no cost and can be enabled at any time based on your organization's needs. Existing subscriptions that already have Foundational CSPM enabled will remain enabled unless you turn off the plan. For more information, see Opt in to Foundational CSPM.
CSPM plans
Defender for Cloud offers two CSPM plans:
- Foundational CSPM (free): Available at no cost. Starting October 27, 2026, new Azure subscriptions must opt in. AWS and GCP onboarding isn't affected.
- Defender CSPM (paid): Provides extra capabilities beyond the Foundational CSPM plan, including advanced CSPM tools for cloud visibility and compliance monitoring. This plan offers advanced security posture features such as AI security posture, attack path analysis, and risk prioritization.
Plan availability
Defender CSPM supports multiple deployment models and cloud environments:
- Commercial clouds: Available in all Azure commercial regions.
- Government clouds: Available in Azure Government and Azure Government Secret.
- Multi-cloud: Support for Azure, AWS, and GCP environments.
- Hybrid: On-premises resources connected through Azure Arc.
- DevOps: GitHub, Azure DevOps, and GitLab integration.
- External registries: Docker Hub and JFrog Artifactory connectors support selected Foundational CSPM and Defender CSPM capabilities. Defender for Containers also supports selected container image capabilities. For plan-specific availability, see external registry capabilities and Defender for Containers feature access patterns.
For specific regional availability and government cloud support details, see the support matrix for cloud environments.
Plan pricing
Defender CSPM billing is based on specific resources enabled in your subscriptions or connectors.
- See Defender for Cloud pricing and use the cost calculator to estimate costs.
- Advanced DevOps security posture features (pull request annotations, code-to-cloud mapping, attack path analysis, and security explorer) require the paid Defender CSPM plan. The free plan provides basic Azure DevOps recommendations. For details, see DevOps security features.
- The Azure and AWS billable-resource tables in this article list covered resource types, activation requirements, and billing-effective dates for Serverless protection and Serverless containers.
Azure Cloud Security Posture Management
Defender CSPM provides Cloud Security Posture Management for Azure infrastructure, compute, data, and application workloads. Learn how to enable Defender CSPM on your Azure subscription.
Azure billable resources
Defender CSPM protects all Azure workloads, but billing applies only to specific resources listed in the following table:
| Service | Resource Types | Exclusions |
|---|---|---|
| Compute | Virtual machines, Virtual Machine scale sets, classic VMs | Deallocated VMs, Databricks VMs |
| Storage | Storage accounts | Accounts without blob containers or file shares |
| Databases | SQL servers, Azure Database for PostgreSQL flexible servers, Azure Database for MySQL flexible servers, Synapse workspaces | - |
| Serverless protection 1 | Function Apps, Web Apps | - |
| Serverless containers 2 | Azure Container Apps (ACA), Azure Container Instances (ACI) | - |
1 To protect Function Apps and Web Apps and begin billing for this capability, enable Serverless protection in Defender CSPM. Billing became effective April 1, 2026.
2 To protect Azure Container Apps and Azure Container Instances and begin billing for this capability, enable the Serverless Containers component in Defender CSPM. Enable Registry access for full Serverless Containers coverage. Billing became effective July 1, 2026.
Azure features and capabilities
The following table summarizes Azure features available in Foundational CSPM and Defender CSPM:
AWS Cloud Security Posture Management
Defender CSPM connects to Amazon Web Services (AWS) accounts to provide Cloud Security Posture Management, security assessments, vulnerability scanning, and risk context for AWS resources. Learn how to connect your AWS accounts to Defender for Cloud and review AWS prerequisites.
AWS billable resources
The following table lists billable resources and exclusions when you enable Defender CSPM on AWS connectors:
| Service | Resource Types | Exclusions |
|---|---|---|
| Compute | EC2 instances | Deallocated VMs |
| Storage | S3 buckets | – |
| Databases | RDS instances | – |
| Serverless protection 3 | AWS Lambda functions | – |
| Serverless containers 4 | Amazon ECS on AWS Fargate | – |
3 To protect AWS Lambda functions and begin billing for this capability, enable Serverless protection in Defender CSPM. Billing became effective April 1, 2026. A billable resource represents eight AWS Lambda functions.
4 To protect Amazon ECS on AWS Fargate workloads and begin billing for this capability, enable the Serverless Containers component in Defender CSPM. Enable Registry access for full Serverless Containers coverage. Billing became effective July 1, 2026. A billable resource represents two Amazon ECS on AWS Fargate workloads.
AWS features and capabilities
The following table summarizes AWS capabilities available in Foundational CSPM and Defender CSPM:
GCP Cloud Security Posture Management
Defender CSPM connects to Google Cloud Platform (GCP) projects to provide Cloud Security Posture Management and vulnerability assessment for GCP environments. Learn how to connect your GCP projects to Defender for Cloud and review GCP prerequisites.
GCP billable resources
The following table lists billable resources and exclusions when you enable Defender CSPM on GCP projects:
| Service | Resource Types | Exclusions |
|---|---|---|
| Compute | Compute instances, Instance Groups | Nonrunning instances |
| Storage | Storage buckets | Nearline/coldline/archive classes, unsupported regions |
| Databases | Cloud SQL instances | – |
GCP features and capabilities
The following table summarizes GCP capabilities available in Foundational CSPM and Defender CSPM:
| Feature | Foundational CSPM | Defender CSPM |
|---|---|---|
| Asset inventory | ||
| Data exporting | ||
| Data visualization and reporting with Azure Workbooks | ||
| Microsoft Cloud Security Benchmark | ||
| Secure score | ||
| Security recommendations | ||
| Tools for remediation | ||
| Workflow automation | ||
| Agentless code-to-cloud containers vulnerability assessment | - | |
| Agentless discovery for Kubernetes | - | |
| Agentless VM secrets scanning | - | |
| Agentless VM vulnerability scanning | - | |
| AI security posture management | - | |
| Attack path analysis | - | |
| Critical assets protection | - | |
| Custom Recommendations | - | |
| Data security posture management (DSPM), Sensitive data scanning | - | |
| External attack surface management | - | |
| Governance to drive remediation at-scale | - | |
| Internet exposure analysis | - | |
| Regulatory compliance assessments | - | |
| Risk hunting with security explorer | - | |
| Risk prioritization | - |
5 GCP sensitive data discovery only supports Cloud Storage.
Azure Arc Cloud Security Posture Management
Defender for Cloud extends Cloud Security Posture Management to on-premises and hybrid resources connected through Azure Arc. Learn how to connect on-premises machines to Azure Arc and review hybrid onboarding prerequisites. Use Foundational CSPM to view Arc-enabled resources in asset inventory, assess their security configuration, and review security recommendations and secure score.
The following Foundational CSPM capabilities support Arc-enabled resources:
| Feature | Foundational CSPM | Defender CSPM |
|---|---|---|
| Asset inventory | ||
| Data exporting | ||
| Data visualization and reporting with Azure Workbooks | ||
| Secure score | ||
| Security recommendations | ||
| Tools for remediation | ||
| Workflow automation | ||
| Container registry vulnerability assessment for Arc-connected clusters | - |
Container registry vulnerability assessment requires Registry access and is also available through Defender for Containers.
Defender CSPM adds advanced posture management capabilities for supported Arc-enabled resources. Availability depends on the resource type and connected environment. For supported Arc scenarios and cloud availability, see the support matrix for cloud environments.
DevOps Cloud Security Posture Management
DevOps Cloud Security Posture Management capabilities provide code-to-cloud contextualization, pull request annotations, security explorer risk hunting, and attack path analysis for DevOps environments.
For feature availability, prerequisites, the complete feature matrix, and permission requirements, see Support and prerequisites for DevOps security. You can also go directly to Azure DevOps or external registry requirements.
Integrations and external posture
Defender for Cloud integrates with partner systems and external security platforms for unified security posture and incident response.
- External attack surface management (EASM): Discovers internet-facing assets and security risks in cloud and on-premises environments.
- ServiceNow Integration: Integrates Defender for Cloud recommendations with ServiceNow for automated ticketing and incident management (preview).
Azure cloud support
For commercial and national cloud coverage, see Azure cloud environment support matrix.
Next steps
- Watch Cloud Security Posture Management with Microsoft Defender
- Learn about security standards and recommendations
- Learn about secure score