TechSignal.news
Cybersecurity

Microsoft Makes Azure CSPM Opt-In Starting October 2026

Microsoft will stop enabling Foundational CSPM by default for new Azure subscriptions. Organizations relying on default settings risk creating unmonitored cloud environments.

TechSignal.news AI4 min read

Microsoft Changes Azure Security Defaults

Microsoft will stop automatically enabling Foundational CSPM in Microsoft Defender for Cloud for new Azure subscriptions starting October 27, 2026. The capability remains free, and existing subscriptions keep their current settings. The change affects only new Azure environments—AWS and GCP onboarding is unchanged.

The financial impact is zero. The operational cost shifts to governance. Azure administrators now need subscription-creation controls, policy automation, or deployment checklists to ensure CSPM is turned on. Organizations that rely on Microsoft's defaults could create new subscriptions without posture monitoring, increasing configuration and compliance risk.

This matters most to enterprises managing dozens or hundreds of subscriptions. Buyers should verify whether their Azure landing-zone templates explicitly enable CSPM rather than assuming it is present. The change does not remove the free capability—it removes the assumption that it will be there.

Qualys Adds Real-Time Posture Detection

Qualys launched Real-Time Cloud Security Posture Management on October 5. The product is integrated into the Qualys Enterprise TruRisk Platform and is designed to detect posture changes as they occur rather than relying on periodic scans.

Qualys reports the product covers more than 200 cloud services, including serverless functions and containers, without agents. It correlates posture findings with vulnerability data, asset criticality, and exploitability. Remediation workflows connect to Jira and ServiceNow, and automated fixes map to NIST, CIS Benchmarks, and PCI-DSS controls.

The positioning is against Wiz, Orca Security, Palo Alto Networks Prisma Cloud, Microsoft Defender for Cloud, and Rapid7. Qualys's claimed differentiator is integration with its existing vulnerability, endpoint, compliance, and risk-prioritization data rather than posture findings as a standalone queue.

The practical purchasing question is whether Qualys can replace separate CSPM, vulnerability-prioritization, and compliance workflows—or merely add another module to an existing security stack. Buyers should test whether real-time detection materially reduces mean time to detect configuration drift and whether the platform's existing Qualys footprint lowers tool-sprawl costs. The announcement provides no public pricing, customer count, or independent detection-latency benchmark. The performance claim remains vendor-reported rather than independently validated.

CSPM Merges with Data Security and Exposure Management

Two recent developments indicate continued convergence between CSPM, DSPM, and broader exposure management. Upwind and Matters.AI announced an integration connecting Upwind's real-time cloud-infrastructure exposure data with Matters.AI's sensitive-data discovery, classification, and database-activity intelligence.

Earlier in September, SecureSky acquired Soveren, whose DSPM technology uses eBPF-based network analysis and machine-learning classification. Soveren reported 98% accuracy and had raised $10 million before the acquisition.

These moves broaden competition beyond traditional CSPM vendors toward DSPM, CNAPP, CTEM, and cloud-exposure-management providers. Security teams may increasingly evaluate CSPM based on whether it can identify not only an exposed resource, but also the sensitivity and activity of the data behind it. That can affect budget ownership between cloud security, data security, vulnerability management, and SOC teams.

Buyers should demand independent validation of accuracy and false-positive rates. The 98% figure is a vendor-reported claim, not an independently established benchmark.

What to Watch

Microsoft's opt-in change creates an immediate Azure governance requirement. Organizations should audit their subscription-creation processes and landing-zone templates now, not in late 2026. The risk is creating unmonitored environments during mergers, acquisitions, or rapid expansion.

For Qualys, the question is whether real-time detection justifies adding another security module or whether it can consolidate existing tools. Procurement teams should require trials with measured detection latency, coverage by cloud service, false-positive rates, remediation success, and total cost against existing CNAPP or CSPM licenses.

The DSPM integrations reinforce a broader buying shift toward continuous, context-aware cloud exposure management. The market is moving from "what is misconfigured" to "what is misconfigured, what data is behind it, and who can reach it." Pricing and independent performance data remain sparse, so trials with your own cloud environments are the only reliable way to evaluate these claims.

CSPMMicrosoft AzureQualysCloud SecurityDSPM

Technology decisions, clearly explained.

Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.

More in Cybersecurity