Threat detection and malware scanning for Azure Files and Blob Storage, Data Lake Storage Gen2 included, but not for Queue or Table storage. You switch it on for a whole subscription or for individual accounts.
Also called Advanced Threat Protection for Storage.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Microsoft Defender for Storage in context, with comparison tables and the common traps.
Terms in this definition
- Azure Files
Azure's managed file shares over SMB or NFS. There is no Archive tier, and a single encryption key applies across the whole storage account.
- Blob storage
Azure's object store for unstructured content like images and video; a single block blob can reach roughly 190.7 TiB.
- Data lake
Holds files of every kind, structured, semi-structured or unstructured, usually spread over a distributed file system, and lets engines like Spark apply a schema when reading. In Azure this is Data Lake Storage: Blob Storage with a hierarchical namespace enabled.
- General-purpose v1
The older storage account kind (
Storage), which lacks access tiers, Archive and premium file shares and retires on 13 October 2026. Converting to ZRS requires first upgrading to GPv2, a one-way change. - Table storage
Low-cost key-value tables indexed solely on RowKey and PartitionKey, limited to a single write region and entities of 1 MB.
- SWITCH
Checks one expression against several candidate values, returning whichever result pairs with the match (or a fallback otherwise). Writing SWITCH ( TRUE (), ... ) avoids nested IF chains: whichever condition is first true wins.
- subscription
Entitlement bought for a product under VCF 9.0 licensing, carrying a set capacity. Where active ones share the same site, unit and product, their capacity is combined into licences, which are then allocated to vCenters.
- AGDLP
Nesting pattern: users go into global groups, which go into domain local groups, which receive the permissions. AGUDLP adds universal groups for forests with several domains.