Microsoft Defender for Cloud uses a feature called Secure Score to measure how well a cloud environment is protected. The score is calculated by checking security controls across subscriptions and resources, giving a percentage that shows the current security posture. Higher scores mean fewer vulnerabilities and better protection. The Inventory feature provides a complete list of all resources in Azure, AWS, or GCP, allowing security teams to see what exists and assess each item's security status.
The relationship between Secure Score and Inventory works because the inventory feeds data into the scoring system. When a resource is discovered, Defender for Cloud evaluates it against security recommendations and assigns points based on how many controls are in place. Remediation happens when teams fix the issues identified in the inventory, which then raises the Secure Score. This creates a continuous improvement cycle where identifying risks, fixing them, and measuring progress all depend on each other.
Defender for Cloud can check an environment against established security frameworks such as Azure Security Benchmark, NIST, CIS, and PCI-DSS. These frameworks provide predefined sets of controls that define what secure configurations look like for different industries and regulatory requirements. When enabled, the compliance dashboard shows which controls are met, partially met, or not met at all.
The assessment works by mapping security recommendations to framework controls, so when a recommendation is satisfied, the corresponding framework control shows as compliant. Teams can see compliance scores for each framework and track improvements over time. This mapping relationship means that fixing a single security issue can improve compliance across multiple frameworks simultaneously.
Within Defender for Cloud, compliance standards can be turned on or off depending on what regulations apply to the organization. The platform supports multiple built-in standards and allows teams to prioritize which ones to track based on their industry or geographic location. Managing standards involves selecting the appropriate frameworks, reviewing the current compliance status, and assigning remediation tasks.
Standards management also includes setting up continuous monitoring so that any new resource that gets deployed automatically gets checked against the selected frameworks. This ensures that compliance does not degrade over time as the environment grows. The relationship here is between the standard selected and the security controls that get evaluated, because each standard triggers a specific set of recommendations.
Organizations with unique security requirements can create custom standards in Defender for Cloud. These custom standards define specific security controls that are not covered by the built-in frameworks. Creating a custom standard involves specifying the control description, the logic to evaluate it, and the remediation steps if the control fails.
Custom standards are useful when companies have internal security policies or when they operate in industries with specialized regulations. The custom standard gets treated the same as built-in standards in the compliance dashboard, meaning it contributes to the overall compliance score. This extends the platform's flexibility while maintaining the same assessment and remediation workflow.
Defender for Cloud can protect resources not only in Azure but also in Amazon Web Services (AWS) and Google Cloud Platform (GCP). Connecting these external clouds involves installing the Defender for Cloud agent or enabling the connection through the cloud provider's console. Once connected, Defender for Cloud discovers resources in those environments and applies the same security recommendations.
The multi-cloud capability creates a unified security view across all environments, so teams do not need separate tools for each cloud provider. Security findings from AWS and GCP appear alongside Azure findings in the same dashboard. This unified view depends on the connector being properly configured, and the data flows from each cloud provider into Defender for Cloud for analysis and scoring.
Microsoft Defender External Attack Surface Management (EASM) discovers and monitors the external-facing assets of an organization that could be targeted by attackers. These assets include public IP addresses, domains, SSL certificates, and web applications that are visible from the internet. EASM continuously scans the internet to find new assets and identify potential vulnerabilities.
The relationship between EASM and Defender for Cloud is complementary because EASM focuses on what attackers can see from outside, while Defender for Cloud focuses on internal security controls. Findings from EASM can be imported into Defender for Cloud to create a complete picture of the attack surface. This helps security teams prioritize remediation of externally exposed risks that might otherwise be missed.
A system architecture diagram showing how Microsoft Defender for Cloud uses Azure Arc and least-privilege service principals to connect on-premises, AWS, and GCP environments, ingesting telemetry to calculate a unified Secure Score.
Are you a guardian of your domain? Lean how to leverage your aptitude in security to protect Microsoft Azure technologies, with a goal of earning the Microsoft Certified: Azure Security Engineer Associate certification!
Prepare and test your skills

Prepare and test your skills

Microsoft Defender for Cloud Secure Score is a percentage that measures how well a cloud environment is protected by checking security controls across subscriptions and resources. The Inventory feature provides a complete list of all resources, and it feeds data into the scoring system, creating a continuous improvement cycle where fixing issues identified in the inventory raises the Secure Score.
Microsoft Defender for Cloud assesses compliance by mapping its security recommendations to the controls of established frameworks such as Azure Security Benchmark, NIST, CIS, and PCI-DSS. When a recommendation is satisfied, the corresponding framework control shows as compliant, and fixing a single security issue can improve compliance across multiple frameworks simultaneously.
Yes, Microsoft Defender for Cloud can protect resources in Amazon Web Services (AWS) and Google Cloud Platform (GCP) by using an agent or enabling a connection through the cloud provider's console. Once connected, it discovers resources and applies the same security recommendations, creating a unified security view across all environments.