Microsoft Defender for Cloud is a security management platform that protects Azure and hybrid resources. Enabling workload protection requires provisioning Defender agents and configuring Defender plans. The platform integrates several services that work together to collect data, detect threats, and enforce security policies across your environment.
Activating Defender plans is the first step toward comprehensive security. Each plan targets a specific resource type and monitors it for threats:
These plans are independent of each other; you can enable them selectively based on which resources you need to protect. The plans share a common alert pipeline in Defender for Cloud, so all detected threats appear in a single dashboard.
Provisioning the Log Analytics Agent and Azure Monitor Agent across Azure and hybrid environments is essential for consistent data collection and monitoring. Auto-provisioning simplifies this process: when enabled, Defender for Cloud automatically installs the agent on new virtual machines as they are created. The agent collects security-related logs and performance data, which flows to a Log Analytics workspace. From there, Defender for Cloud analyzes the data for threats and compliance issues. For hybrid environments, the same agents can be deployed to on-premises servers using Azure Arc, extending the security monitoring boundary beyond Azure.
Implementing vulnerability assessments is another vital aspect of workload protection. Defender for Cloud integrates with vulnerability scanning solutions that run regular scans of virtual machines and container registries. The scanner compares the software inventory against known vulnerability databases and reports findings directly in the Defender for Cloud interface. You can then investigate each vulnerability, assess its severity, and apply remediation steps—such as patching the software or updating the container image—directly from the same interface. The scanning happens on a schedule you configure, and results are refreshed each time a scan completes.
Securing Kubernetes clusters through Microsoft Defender for Containers provides real-time threat protection and environment hardening. This solution protects both the cluster runtime and Linux nodes, detecting misconfigurations, suspicious pod activity, and privilege escalation attempts. Defender for Containers integrates with Azure Kubernetes Service (AKS) and can also monitor hybrid Kubernetes clusters. When a threat is detected, an alert is generated in Defender for Cloud, and you can investigate the affected pods, namespaces, or nodes to contain the issue.
Defender for Cloud also provides continuous compliance assessment against various security standards and regulatory benchmarks, such as Azure Security Benchmark, CIS, and PCI DSS. The platform maps your resources to these standards and reports which controls pass or fail. When a new compliance standard is added or updated, Defender for Cloud reassesses your environment automatically. This monitoring helps organizations maintain a secure and compliant posture without manual audits.
Are you a guardian of your domain? Lean how to leverage your aptitude in security to protect Microsoft Azure technologies, with a goal of earning the Microsoft Certified: Azure Security Engineer Associate certification!
Prepare and test your skills

Prepare and test your skills

Enabling Microsoft Defender plans activates comprehensive threat monitoring for specific resource types, such as storage accounts, databases, and App Service applications, with each plan detecting threats like malware uploads, SQL injection, or brute force attempts.
Microsoft Defender for Cloud can automatically provision the Log Analytics Agent and Azure Monitor Agent on new Azure virtual machines, and these same agents can be deployed to on-premises servers using Azure Arc to extend security monitoring beyond Azure.
Microsoft Defender for Containers provides real-time threat protection and environment hardening for Kubernetes clusters, detecting misconfigurations, suspicious pod activity, and privilege escalation attempts on both Azure Kubernetes Service (AKS) and hybrid clusters.