Glossary
Defender for Cloud
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft's cloud workload protection platform for Azure, AWS, and GCP resources.
Microsoft Defender for Cloud is Microsoft's Cloud-Native Application Protection Platform (CNAPP) — covering security posture management and workload protection across Azure, AWS, and GCP. It bundles Cloud Security Posture Management (CSPM) for configuration assessment against regulatory benchmarks, Cloud Workload Protection for runtime defence of VMs, containers, databases, storage, AI services, and DevSecOps for code-to-cloud security. Signals flow into Microsoft Defender XDR alongside endpoint, identity, and email signals. Different from Defender for Cloud Apps (CASB for SaaS) — same brand, different scope. Licensed per resource per hour by workload type.
Worked example
A company running a mix of Azure virtual machines and an AWS-hosted database connects both clouds to Defender for Cloud. Its CSPM layer immediately flags an Azure storage account left publicly accessible and an AWS database missing encryption at rest, scoring the whole environment against a regulatory benchmark like CIS or NIST. Once workload protection is enabled on the VMs, Defender for Cloud also starts detecting runtime threats — a suspicious process trying to disable antivirus, an unusual outbound connection — and those alerts flow into the same Defender XDR incident view used for email and endpoint threats elsewhere in the organisation.
Common pitfalls
Confusing Defender for Cloud with Defender for Cloud Apps is an extremely common naming collision — one protects cloud infrastructure and workloads (VMs, containers, databases across Azure/AWS/GCP), the other is a CASB protecting SaaS application usage (Salesforce, Dropbox, and similar); they share a brand name and nothing else. Enabling CSPM (posture scanning) without ever enabling the paid workload protection plans leaves an organisation with a list of findings but no runtime defence against active attacks — posture and protection are separately licensed and often need to be turned on deliberately. And assuming multicloud coverage is automatic once Defender for Cloud is enabled on Azure misses that AWS and GCP connectors have to be explicitly configured; without that step, only the Azure side of the environment is actually being watched.