Turning on Defender CSPM across a landing zone
Foundational CSPM is free and already on. Defender CSPM adds attack paths and agentless scanning. Here's how I'd roll it out across many subscriptions.
On this page
Microsoft Defender for Cloud has two levels of cloud security posture management. Foundational CSPM is free and enabled by default: it gives you the secure score and security recommendations. Defender CSPM is a paid plan that adds features like attack path analysis, the cloud security explorer and agentless scanning.
Plan before you switch it on
- Scope. Decide which subscriptions get the paid plan. Production first is a common choice.
- Cost. Defender CSPM is billed per billable resource. Check the current pricing page and estimate it against your resource counts before going further.
- Extensions. Features like agentless scanning are extensions within the plan, each with its own on/off switch. Decide which you want.
- Change control. It's a security improvement, but it's still a billing change across many subscriptions. Raise it through your normal change process.
One subscription by CLI
The Defender CSPM plan is called CloudPosture in the pricing API:
az account set --subscription "<subscription-id>"
az security pricing create --name CloudPosture --tier Standard
az security pricing show --name CloudPostureMany subscriptions with Azure Policy
For a landing zone, assign the built-in policy that enables Defender CSPM at the management group. Search the policy definitions for "Defender CSPM" to find it. A policy with a DeployIfNotExists effect means new subscriptions pick up the plan automatically, so nothing slips through.
- Assign the policy at the right management group.
- Run a remediation task to apply it to existing subscriptions.
- Check the Environment settings page in Defender for Cloud to confirm each subscription shows the plan as on.
The assignment needs a managed identity with rights to set pricing on subscriptions, and existing subscriptions need a remediation task. New ones are covered automatically.
Getting value in the first month
- Attack paths. Start with the paths marked critical. They join several weaknesses into a real route to something valuable, which makes them easier to prioritise than a long list of recommendations.
- Cloud security explorer. Use the built-in templates, such as internet-exposed VMs with high-severity vulnerabilities, to answer questions that used to need a spreadsheet.
- Governance rules. Assign owners and due dates to recommendations automatically, so findings go to the team that can fix them.
Checking coverage
// Azure Resource Graph: Defender CSPM status per subscription
securityresources
| where type == "microsoft.security/pricings" and name == "CloudPosture"
| project subscriptionId, tier = tostring(properties.pricingTier)
| order by tier ascDo I lose anything by staying on foundational CSPM?
You keep secure score and recommendations. You miss the context features, such as attack paths and the explorer, that help you decide what to fix first.
Is Defender CSPM the same as Defender for Servers?
No. CSPM is about posture across your cloud estate. Workload plans like Defender for Servers protect specific resource types and are billed separately.
This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.
Next in Azure landing zone guardrails · part 5 of 5Private endpoints and DNS: why your private endpoint isn't being used →