azureblog.co.uk
← cd ~/posts

Turning on Defender CSPM across a landing zone

Foundational CSPM is free and already on. Defender CSPM adds attack paths and agentless scanning. Here's how I'd roll it out across many subscriptions.

2 min read⚠ checked 3 Dec 2025Azure · Security
On this page
  1. Plan before you switch it on
  2. One subscription by CLI
  3. Many subscriptions with Azure Policy
  4. Getting value in the first month
  5. Checking coverage

Microsoft Defender for Cloud has two levels of cloud security posture management. Foundational CSPM is free and enabled by default: it gives you the secure score and security recommendations. Defender CSPM is a paid plan that adds features like attack path analysis, the cloud security explorer and agentless scanning.

Foundational CSPM (free, on by default)Secure score, recommendations, asset inventory
Defender CSPM (paid)Attack paths, cloud security explorer, governance rules
Plan extensionsAgentless scanning, sensitive data discovery and others, each switchable
Foundational CSPM is the base. The paid plan builds on it.

Plan before you switch it on

  • Scope. Decide which subscriptions get the paid plan. Production first is a common choice.
  • Cost. Defender is billed per billable resource. Check the current pricing page and estimate it against your resource counts before going further.
  • Extensions. Features like agentless scanning are extensions within the plan, each with its own on/off switch. Decide which you want.
  • Change control. It's a security improvement, but it's still a billing change across many subscriptions. Raise it through your normal change process.

One subscription by CLI

The Defender CSPM plan is called CloudPosture in the pricing API:

shell
az account set --subscription "<subscription-id>"
az security pricing create --name CloudPosture --tier Standard
az security pricing show --name CloudPosture

Many subscriptions with Azure Policy

For a landing zone, assign the built-in policy that enables Defender CSPM at the . Search the policy definitions for "Defender CSPM" to find it. A policy with a DeployIfNotExists effect means new subscriptions pick up the plan automatically, so nothing slips through.

  1. Assign the policy at the right management group.
  2. Run a remediation task to apply it to existing subscriptions.
  3. Check the Environment settings page in Defender for Cloud to confirm each subscription shows the plan as on.
After rollout: give agentless scanning a day or so to complete its first pass before judging the results. Then start with the attack paths, which show which recommendations actually matter most.
Management groupAzure PolicySubscriptionDefender for CloudAssign enable-CSPMpolicy (DINE)1New subscription joinsthe management group2Evaluate: plan notenabled3Deploy: set CloudPosture to Standard4Plan on, extensions asconfigured5
How a DeployIfNotExists policy keeps every subscription covered.

The assignment needs a with rights to set pricing on subscriptions, and existing subscriptions need a remediation task. New ones are covered automatically.

Getting value in the first month

  1. Attack paths. Start with the paths marked critical. They join several weaknesses into a real route to something valuable, which makes them easier to prioritise than a long list of recommendations.
  2. Cloud security explorer. Use the built-in templates, such as internet-exposed VMs with high-severity vulnerabilities, to answer questions that used to need a spreadsheet.
  3. Governance rules. Assign owners and due dates to recommendations automatically, so findings go to the team that can fix them.

Checking coverage

kql
// Azure Resource Graph: Defender CSPM status per subscription
securityresources
| where type == "microsoft.security/pricings" and name == "CloudPosture"
| project subscriptionId, tier = tostring(properties.pricingTier)
| order by tier asc
Do I lose anything by staying on foundational CSPM?

You keep secure score and recommendations. You miss the context features, such as attack paths and the explorer, that help you decide what to fix first.

Is Defender CSPM the same as Defender for Servers?

No. CSPM is about posture across your cloud estate. Workload plans like Defender for Servers protect specific resource types and are billed separately.

This post was last checked against Microsoft's documentation over six months ago. The approach should still hold, but check the linked sources for anything that has changed before you act on it.

Next in Azure landing zone guardrails · part 5 of 5Private endpoints and DNS: why your private endpoint isn't being used →