Introduction

Completed

Contoso Financial Services operates a complex hybrid Azure environment with hundreds of Windows and Linux virtual machines, Azure SQL databases managing customer financial records, and Azure Blob Storage accounts storing transaction data and compliance reports. The environment also includes an Azure Kubernetes Service (AKS) cluster powering internal trading applications. The team is also rolling out a customer-facing financial assistant built on Azure OpenAI Service, adding generative AI workloads to an already broad attack surface. The security team recently enabled foundational Cloud Security Posture Management (CSPM) in Microsoft Defender for Cloud, which now generates configuration recommendations and tracks regulatory compliance. While compliance reports provide valuable security posture visibility, Contoso faces a critical gap: no Cloud Workload Protection Platform (CWPP) plans are enabled, leaving the organization without runtime threat detection and response capabilities.

Without active CWPP plans, Contoso's workloads remain vulnerable to active threats. When an attacker uploads malware to a storage account, no alert fires. When suspicious queries target databases containing sensitive financial data, the security team receives no notification. When vulnerabilities in virtual machines are actively exploited, there's no detection or automated response. The foundational CSPM layer identifies misconfigurations and policy violations. However, it can't detect malicious behavior, active exploitation, or runtime threats targeting specific workload types like servers, databases, storage accounts, or container environments.

In this module, you:

  • Identify the CWPP plans available in Defender for Cloud and explain what workloads each plan protects, including Defender for AI Services and Defender for APIs
  • Enable workload protection plans at the subscription level using Environment Settings in the Azure portal
  • Configure Defender for Servers (Plan 1 vs. Plan 2), Defender for Storage protection layers, and Defender for Databases subplans for your protection requirements
  • Deploy protection plans at scale using management groups and Azure Policy, and verify plan coverage using the Coverage workbook