What the free posture management tier includes and what the paid Defender CSPM plan adds.
From Ultra Transcenders SC-900 by Tony Rough (publishing soon)
Posture management comes in a free tier and a paid tier. The free tier gives every subscription a baseline, while the paid tier adds context and prioritisation that large estates need.
Foundational CSPM is free and switched on with Defender for Cloud. It includes secure score, security recommendations based on the Microsoft cloud security benchmark, and asset inventory (a single list of all monitored resources and their security state), plus data export, workbooks, remediation tools and workflow automation.
The paid Defender CSPM plan adds governance, regulatory compliance assessments, cloud security explorer, attack path analysis and agentless scanning for machines, among other features.
| Feature | Foundational CSPM (free) | Defender CSPM (paid) |
|---|---|---|
| Asset inventory | Yes | Yes |
| Secure score | Yes | Yes |
| Security recommendations based on MCSB | Yes | Yes |
| Workflow automation and remediation tools | Yes | Yes |
| Multicloud (AWS, GCP) and Azure Arc coverage | Yes | Yes |
| Regulatory compliance assessments | No | Yes |
| Governance rules (assign fixes to owners and track progress) | No | Yes |
| Cloud security explorer (query a map of the environment for risks) | No | Yes |
| Attack path analysis | No | Yes |
| Agentless VM vulnerability and secrets scanning | No | Yes |
| Data security posture management (sensitive data discovery) | No | Yes |
| Custom recommendations | No | Yes |
| AI security posture management | No | Yes |
A few terms from the table:
Defender CSPM is billed per protected resource, such as VMs, storage accounts and database servers.
Common trap: Expecting attack path analysis or regulatory compliance assessments from the free tier - Foundational CSPM gives secure score, MCSB recommendations and asset inventory. Attack path analysis, cloud security explorer, governance, regulatory compliance and agentless machine scanning need the paid Defender CSPM plan.
This note is one section of Ultra Transcenders SC-900: Microsoft Security, Compliance, and Identity Fundamentals, an independent study guide that explains every topic the exam covers by technology, with comparison tables, diagrams and the common traps, plus a glossary linked to Microsoft Learn.
Publishing soon on Amazon in Kindle and paperback editions.
About the book · SC-900 terms in the glossary · All SC-900 study notes
How security duties move between customer and Microsoft across on-premises, IaaS, PaaS and SaaS, and the duties that never move.
Verify explicitly, use least privilege access and assume breach, and the areas a Zero Trust approach covers.
How Conditional Access combines signals into decisions after first-factor sign-in, and what it is not designed to stop.
The kinds of DDoS attack, what every public IP gets free, and what the paid tiers add.
What security information and event management and security orchestration, automation and response each do, and how they fit together.
The built-in mailbox protection every tenant has, and the protections each Defender for Office 365 plan adds.
The unified audit log, how long each audit tier keeps records, and what Audit (Premium) adds.