Microsoft Disables Default CSPM for New Azure Subscriptions on October 27, 2026
Microsoft will no longer auto-enable Foundational CSPM for new Azure subscriptions starting October 27, 2026. Existing subscriptions remain enabled, but new tenants launch without posture monitoring unless admins activate it.
Microsoft Ends Automatic CSPM Activation
Microsoft will stop auto-enabling Foundational CSPM for new Azure subscriptions on October 27, 2026. The free tier remains available, but administrators must now activate it manually. Existing subscriptions with Foundational CSPM already enabled are not affected.
This change removes a significant Azure-native advantage: baseline posture monitoring turned on by default. Buyers comparing Microsoft to Wiz, Palo Alto Networks Prisma Cloud, CrowdStrike Falcon Cloud Security, Orca Security, and Sysdig must now distinguish "available at no cost" from "enabled by default." The difference matters when misconfigured resources go undetected during the window between subscription creation and manual CSPM activation.
Foundational CSPM provides posture monitoring at no cost. Microsoft's paid Defender CSPM tier adds attack-path analysis, AI-driven risk prioritization, DevOps security, pull-request annotations, and code-to-cloud mapping. The paid tier bills by onboarded resources across Azure, AWS, GCP, and Azure Arc environments.
What Azure Customers Must Do Before October
Azure customers onboarding new subscriptions should add an explicit CSPM-enablement step to landing-zone and subscription-provisioning controls before October 27. Enterprises that relied on Microsoft's default activation face a visibility gap unless they update policy-as-code, Azure management-group policies, or deployment templates.
The change forces a procurement reassessment. Teams should decide whether Microsoft's paid tier is sufficient or whether they need a specialist CNAPP platform for multicloud attack-path analysis and remediation. Independent benchmark reporting from 2026 evaluated Wiz, Prisma Cloud, Microsoft Defender for Cloud, and Lacework across more than 180 enterprises and a 280-rule misconfiguration benchmark. Wiz achieved 95% coverage and a median remediation time of 4.1 days.
OX Security Expands Into CNAPP
OX Security launched OX Cloud on September 16, 2026, expanding beyond application security into a broader CNAPP. The platform combines CSPM with Kubernetes security posture management, data security posture management, runtime vulnerability detection, cloud inventory, and graph-based attack-path analysis. OX positioned the product for environments where AI agents access data and take autonomous actions.
This places OX more directly against integrated CNAPP vendors such as Wiz, Palo Alto Networks, Microsoft, CrowdStrike, Orca, and Sysdig. The competitive shift is toward consolidating infrastructure posture, workload, data, identity, and AI-agent risk in one platform.
Buyers should not treat the launch as evidence of market leadership. The announcement does not disclose customer counts, pricing, detection rates, remediation benchmarks, or independent validation. Enterprises evaluating OX should demand proof of cloud-provider coverage, rule counts, false-positive rates, attack-path precision, integrations, and incremental cost relative to an existing CSPM or CNAPP contract.
Market Forecasts Show Category Confusion
Two market forecasts published this week illustrate the difficulty of sizing the CSPM category. Dimension Market Research estimated the CSPM market at $6.8 billion in 2026, reaching $24.5 billion by 2035 at a 15.2% CAGR. Fortune Business Insights gave a lower 2026 estimate of $3.77 billion and projected $21.31 billion by 2034, with a 24.2% CAGR.
The $3 billion gap for 2026 shows that market-size figures depend heavily on whether vendors and analysts include adjacent CNAPP, DSPM, KSPM, exposure-management, and compliance functionality. Buyers should avoid using headline market size as a business case without defining the included categories.
What to Watch
Azure customers have 13 months to update subscription provisioning before Microsoft's change takes effect. The opt-in model creates risk for decentralized organizations where individual teams spin up Azure subscriptions without central IT oversight. Procurement teams should audit landing-zone templates and Azure Policy configurations now rather than after the cutover date.
The OX Cloud launch is strategically relevant but lacks the data buyers need to compare it against established CNAPP platforms. Watch for independent benchmarks, customer case studies with specific metrics, and pricing transparency. The broader trend—CSPM vendors expanding into CNAPP—continues. Enterprises with standalone CSPM contracts should expect vendor pressure to consolidate posture, workload, data, and identity monitoring into a single platform and cost structure.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
