Skip to content
Jussi Metso
Jussi Metso

It’s all about The Cloud and The Security

  • Posts
  • About the blog
  • Activity
  • Connect!
  • Privacy Policy
Jussi Metso

It’s all about The Cloud and The Security

January 25, 2024May 25, 2025

Defender for Cloud – Part 1: Getting Started

Table of Contents

Getting started with Defender for Cloud

When you first time open Microsoft Defender for Cloud the overview page opens.

Defender for Cloud is now enabled on your subscription and you have access to the basic features provided by Defender for Cloud. These features include:

  • The Foundational Cloud Security Posture Management (CSPM) plan
  • Recommendations
  • Access to the Asset inventory
  • Workbooks
  • Secure score
  • Regulatory compliance with the Microsoft cloud security benchmark

The Defender for Cloud overview page provides a unified view into the security posture of your hybrid cloud workloads, helping you discover and assess the security of your workloads and to identify and mitigate risks.

I will introduce those features above in the coming posts.

Enable enhanced security features

When you first time click Getting Started from Defender for Cloud menu:

The view in the portal looks like this:

Upgrade tab

Like to text says you can enable Defender for Cloud’s enhanced security features for the selected subscription by clicking the Upgrade button below.

In my example there’s only one subscription which could be enabled.

You can start 30-day trial of enhanced security features which enables

  • Cloud Security Posture Management (CSPM)
  • Cloud Workload  Protection for machines (CWP)
  • Advanced threat protection for PaaS services

Get Started tab

In this view you can add non-Azure servers from on-prem datacenter(s) and connect multi-cloud environments such as Amazon Web Services (AWS) and Google Cloud Platform (GCP) and many other sites to get managed from the security point of view from Defender for Cloud. 

Add non-Azure servers

By pressing Configure above left you end up the page where you can onboard non-azure servers and collect logs with Log analytics Agent and store them to the existing Log analytics workspace or create a new one.  I’ll write more onboarding topics later on coming blogs.

Connect and protect external multi-cloud environments

By pressing Configure above right you end up to Environment Settings blade where you can  connect external services and also do a lot more but I concentrate now to the external services.

As you can see you can add connection to:

  • Amazon Web Services
  • Google Cloud Platform
  • GitHub
  • AzureDevOps
  • GitLab

The process will start when you press the Add environment button in the top.

It depends by the service what credentials you need to fill but eventually if everything is correct you see the connector below in this same view.

Part 14 is dedicated to Environment Settings.

 

Install agents tab

And finally if you have virtual machines in your subscription you can install log analytics agent automatically to your virtual machines.  Or continue without installing anything.

Here was the Getting Started section. I hope you get some knowledge about it. Next part is about the Defender for Cloud Inventory. Stay tuned.

The parts of the MDC blog series

 
  • Part 0: Microsoft Defender for Cloud – The EPIC blog series – introduction
  • Part 1: Getting started aka Setup 
  • Part 2: The Asset Inventory 
  • Part 3: Security posture
  • Part 4: Security recommendations
  • Part 5: Security alerts
  • Part 6: Attack path analysis
  • Part 7: Cloud security explorer
  • Part 8: Workbooks
  • Part 9: Regulatory compliance
  • Part 10: Workload protections
  • part 10.5: Advanced Workload protection
  • Part 11: Data and AI security – The end of the series
Picture of Jussi Metso
Jussi Metso
Author is a a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future.
Share on Social Media
xfacebooklinkedinwhatsapp

Discover more from Jussi Metso

Subscribe to get the latest posts sent to your email.

DEFENDER FOR CLOUD #cloudsecurity#mdcseries

Post navigation

Previous post
Next post

Related Posts

DEFENDER FOR CLOUD

AWS & GCP connectivity status in Defender for Cloud

May 23, 2023May 23, 2023

Microsoft Defender for Cloud have a new public preview feature which allows user to check…

Read More
DEFENDER FOR CLOUD

Defender for Cloud – Part 9: Regulatory compliance

March 13, 2025May 25, 2025

Microsoft Defender for Cloud provides Regulatory Compliance capabilities to help organizations assess and maintain compliance with industry standards, frameworks, and regulatory requirements. It continuously monitors cloud resources and provides insights into security posture, ensuring alignment with compliance benchmarks.

Read More
DEFENDER FOR CLOUD

Defender for Cloud – Part 8: Workbooks

March 7, 2025May 25, 2025

Workbooks provide a flexible canvas for data analysis and the creation of rich visual reports within the Azure portal. They allow you to tap into multiple data sources from across Azure and combine them into unified interactive experiences. Workbooks let you combine multiple kinds of visualizations and analyses, making them great for freeform exploration.

Read More

Link to my MVP profile:

Join our Security User Group:

Subscribe my blog to get updates!

Join 40 other subscribers

Recent Posts

  • Book review of Microsoft Security Copilot for Security Operations
  • Book review of The Azure Cloud Native Architecture Mapbook – 2nd Edition
  • NextGen Defender for Cloud: Phase 1 – public preview
  • Malware automated remediation in Defender for Storage
  • Microsoft Sentinel Data lake (preview)

Top posts:

Defender for Cloud – Part 10: Cloud Workload protection (CWP)
Defender for Cloud - Part 6: Attack Path Analysis
NextGen Defender for Cloud: Phase 1 - public preview
Defender for Cloud – Part 5: Security Alerts
Microsoft Sentinel Data lake (preview)

Categories

Tags

#architecture #azure #bookreview #cloudsecurity #defenderforcloud #defenderforstorage #defenderxdr #malwarescan #mdcseries #securitycopilot #sentinel #siem #soc

Archives

Visits on my site

20,448 hits

©2022-2026 Jussi Metso. All rights reserved.