CNAPP, applied

Microsoft Defender for Cloud watches your posture and your workloads. Across Azure, AWS, and GCP.

CloudServus configures Defender CSPM, workload protection, and DevOps security scanning so your team can prioritize the risks that reach production, not just the ones flagged in a dashboard.

Talk to an Expert →

Cloud protection now means three different jobs

Microsoft Defender for Cloud is built as a cloud-native application protection platform (CNAPP): cloud security posture management (CSPM), DevOps security management, and cloud workload protection, in one platform, across Azure, AWS, GCP, and on-premises resources.

That's a wider scope than most teams assume when they hear "Defender." Foundational CSPM turns on by default and is free. Everything past that, attack path analysis, workload protection plans for servers, storage, and containers, DevOps pipeline scanning, is a plan you choose deliberately. Most environments we look at have the free tier running and stop there.

What's inside Defender for Cloud

Cloud security posture management (CSPM)

  • Foundational CSPM runs free on every onboarded subscription and account, scored against the Microsoft Cloud Security Benchmark
  • Defender CSPM adds attack path analysis, risk prioritization, and AI workload posture for teams that need to know which finding to fix first

Cloud workload protection

  • Defender for Servers layers vulnerability assessment, file integrity monitoring, and just-in-time VM access on top of your existing endpoint agent
  • Defender for Storage, Containers, and Databases run workload-specific threat detection, including malware scanning on upload for storage accounts

DevOps security management

  • Scans infrastructure-as-code templates and container images before they deploy, so a misconfiguration gets caught in the pipeline, not in production
  • Connects GitHub, Azure DevOps, or GitLab so findings from code show up next to the cloud resources they'll eventually touch

One posture view across Azure, AWS, and GCP

Defender for Cloud assesses AWS accounts and GCP projects with the same posture model and secure score it uses for Azure, so a real multicloud estate gets one view instead of three separate consoles.

Microsoft is also folding Defender for Cloud into its unified Defender security portal, bringing cloud and code security into the same experience as its other security products. The rollout is ongoing. CloudServus tracks it as it lands and adjusts your configuration, so a portal change doesn't quietly break a workflow your team depends on.

Where Defender for Cloud ends and endpoint protection begins

Defender for Cloud handles cloud security posture and workload protection. Endpoint antivirus and EDR live in Microsoft Defender for Endpoint and the broader Defender XDR suite, running at the OS level. Defender for Servers reads signal from that same endpoint agent rather than duplicating it.

Knowing where that line sits matters when you're deciding what to license and what you already have covered. CloudServus maps your existing Microsoft security stack before we recommend a Defender for Cloud plan, so you're not paying twice for the same protection.

Want a straight read on your Defender for Cloud coverage?

We'll show you which plans are on, which gaps are open across Azure, AWS, and GCP, and where you're already covered by something else in your Microsoft stack.

Talk to an Expert →