Microsoft Defender for Cloud serves as the central platform for securing Azure environments. It provides advanced threat detection, automated response capabilities, and continuous compliance monitoring across different workload types. The service collects telemetry from protected resources and analyzes it to identify suspicious activities, then forwards alerts to security teams and integrates with response tools. Organizations enable Defender plans at the subscription level, and those plans then apply to all eligible resources within that subscription, though granular controls allow enabling protections on specific resources when needed.
Microsoft Defender for Servers protects virtual machines running in Azure by monitoring them for threats and configuration weaknesses. The service analyzes system behavior, network traffic, and operating system events to detect attacks such as malware installation, unauthorized access attempts, and cryptocurrency mining. When a threat is identified, an alert is generated and sent through Microsoft Defender for Cloud, while the service also provides hardening recommendations that help administrators close security gaps before attackers can exploit them. The server protection plan integrates with Azure Monitor to forward security data and with Microsoft Sentinel to enable automated incident response workflows.
Microsoft Defender for SQL extends protection to database workloads including Azure SQL Database, SQL Server on virtual machines, and open-source databases like MySQL and PostgreSQL. The service performs vulnerability assessments that scan databases for misconfigurations and missing patches, then ranks findings by severity so teams can address the most critical issues first. Threat detection capabilities monitor for attacks such as SQL injection, brute force login attempts, and anomalous data exfiltration, while data classification features automatically discover and tag sensitive information like credit card numbers or personal identifiers. These capabilities work together to protect data integrity and support compliance with regulations such as GDPR and HIPAA.
Microsoft Defender for Storage guards Azure storage accounts against threats targeting blobs, files, queues, and tables. The service learns normal access patterns for each storage account and uses machine learning models to flag unusual behavior, such as access from unexpected locations or unusual data transfer volumes that might indicate a compromised account. When suspicious activity is detected, alerts are generated that include details about the threat vector and recommended remediation steps. Storage protection operates continuously in the background without impacting performance, and the alerts flow into the same Microsoft Defender for Cloud dashboard that manages server and database security.
Enabling Defender protection requires selecting the appropriate plans at the subscription or resource scope and configuring settings that match organizational security requirements. Data collection thresholds control how much telemetry is gathered from protected resources, with higher thresholds providing more detailed analytics but also increasing storage and processing costs. Alert suppression rules allow security teams to filter out known false positives or low-priority notifications so analysts can focus on genuine threats. The configuration decisions at this level determine what data flows into monitoring tools and which events trigger automated responses.
The Defender services send security data to Azure Monitor for real-time visibility and to Microsoft Sentinel for advanced threat analytics and orchestration. Azure Monitor aggregates logs and metrics from all Defender plans, enabling security operations teams to build custom dashboards and set up metric-based alerts. Microsoft Sentinel takes this further by correlating Defender alerts with data from other sources, applying machine learning to detect multi-stage attacks, and triggering automated playbooks that can contain threats without human intervention. This integration creates a unified security ecosystem where servers, databases, and storage are all protected by the same threat intelligence and response framework.
Are you a guardian of your domain? Lean how to leverage your aptitude in security to protect Microsoft Azure technologies, with a goal of earning the Microsoft Certified: Azure Security Engineer Associate certification!
Prepare and test your skills

Prepare and test your skills

Microsoft Defender for Servers protects virtual machines running in Azure by monitoring them for threats and configuration weaknesses. The service analyzes system behavior, network traffic, and operating system events to detect attacks such as malware installation, unauthorized access attempts, and cryptocurrency mining.
Microsoft Defender for Databases performs vulnerability assessments that scan databases for misconfigurations and missing patches, then ranks findings by severity so teams can address the most critical issues first. Threat detection capabilities monitor for attacks such as SQL injection, brute force login attempts, and anomalous data exfiltration, while data classification features automatically discover and tag sensitive information like credit card numbers or personal identifiers.
Microsoft Defender for Storage guards Azure storage accounts against threats targeting blobs, files, queues, and tables. The service learns normal access patterns for each storage account and uses machine learning models to flag unusual behavior, such as access from unexpected locations or unusual data transfer volumes that might indicate a compromised account.
Enabling Defender protection requires selecting the appropriate plans at the subscription or resource scope and configuring settings that match organizational security requirements. Data collection thresholds control how much telemetry is gathered from protected resources, with higher thresholds providing more detailed analytics but also increasing storage and processing costs. Alert suppression rules allow security teams to filter out known false positives or low-priority notifications so analysts can focus on genuine threats.