Defender for Cloud's paid posture tier. On top of the free foundations it brings agentless scanning, attack path analysis, AI security posture management and the cloud security explorer.
Read more: Microsoft Learn
In the Ultra Transcenders books
AZ-700SC-500AZ-900SC-900AZ-400ALZ
Each book explains Defender CSPM in context, with comparison tables and the common traps.
Terms in this definition
- Archive
Offline access tier for blobs, cheapest to store yet dearest to access. Reading a blob means rehydrating it first, which can take as long as 15 hours.
- Agentless scanning
Defender for Cloud technique that inspects snapshots of VM disks for secrets, vulnerabilities and installed software, with nothing installed on the VM.
- Attack paths
Defender CSPM capability showing how an attacker could chain exploitable weaknesses together to reach critical assets.
- AI security posture management
Part of Defender CSPM, absent from Foundational CSPM, that finds generative AI workloads, compiles an AI bill of materials and highlights AI-specific recommendations and attack paths.
- Cloud security explorer
Part of Defender CSPM where you write graph queries, or start from templates, against the cloud security graph to ask about inventory, internet exposure or OS; it searches what is already known rather than scanning or capturing traffic.
Related terms
- Agentless discovery for Kubernetes
Capability in Defender CSPM and Defender for Containers that inventories Kubernetes clusters and assesses their posture through APIs, using the Kubernetes Agentless Operator role. Pod admission and blocking are outside its scope.
- Agentless malware scanning
Snapshot-based malware check for VM disks that runs Microsoft Defender Antivirus engines with no agent installed. It comes with Defender for Servers Plan 2, not with Defender CSPM by itself.
- AI bill of materials
Catalogue compiled by AI security posture management in Defender CSPM listing what a generative AI app is built from, including its models, SDKs and data sources.
- Cloud security graph
Context engine in Defender for Cloud that links inventory, exposure, permissions, vulnerabilities and lateral movement paths; attack path analysis and cloud security explorer both build on it, and Defender CSPM is required.
- CSPM
Short for Cloud Security Posture Management: spotting and fixing weak configuration across cloud resources, guided by recommendations, a secure score and checks against compliance standards. Everyone using Microsoft Defender for Cloud gets the Foundational level at no charge, while the fuller Defender CSPM is a paid option.
- Defender for Cloud Data and AI security dashboard
A per-subscription overview of data and AI resources showing their coverage, internet exposure and leading issues. A complete picture depends on enabling Defender for Storage, Defender for Databases, AI threat protection and Defender CSPM including sensitive data discovery.
- Defender for Cloud pull request annotations
DevOps security comments on IaC problems, posted only against the lines a pull request changes, in GitHub or Azure DevOps. Defender CSPM is a prerequisite; on Azure DevOps you also need Contributor or Owner rights and a Build Validation policy on main.
- Google Artifact Registry
Google Cloud's registry service for containers and packages. Defender CSPM and Defender for Containers both scan images held there for vulnerabilities.