Microsoft Merges Defender CSPM Into XDR Portal, Adds Risk-Based Cloud Secure Score
Microsoft unified Defender for Cloud CSPM into Defender XDR with a new Cloud Secure Score that weighs asset criticality and exposure, enabling enterprises to consolidate posture dashboards and prioritize remediation by business risk.
Microsoft consolidates cloud posture management into XDR workflow
Microsoft moved Defender for Cloud's CSPM capabilities into the Defender XDR portal in public preview, giving customers a single dashboard for posture across Azure, AWS, GCP, on-premises, and DevOps environments including Azure DevOps, GitHub, GitLab, DockerHub, and JFrog. The integration introduces a new Cloud Secure Score that factors asset criticality, internet exposure, and data sensitivity into posture calculations—a shift from counting misconfigurations to ranking them by business risk.
This matters for enterprises already licensing Defender XDR because it eliminates the need to toggle between separate consoles for endpoint exposure and cloud posture. The consolidated view extends CSPM coverage to serverless workloads across Azure Web Apps and AWS Lambda in public preview, addressing a gap in posture visibility for environments running serverless functions at scale.
Risk-based scoring changes how CISOs allocate remediation budget
The Cloud Secure Score's risk weighting gives security teams a defensible way to prioritize remediation spend. Instead of treating all misconfigurations equally, the score surfaces internet-exposed critical workloads handling sensitive data first. This shifts the conversation from "we have 2,400 misconfigurations" to "these 180 issues pose the highest business risk."
Microsoft deprecated separate AWS and GCP CSPM standards, consolidating posture policies into unified baselines. For regulated enterprises managing compliance across multiple clouds, this reduces policy sprawl and the overhead of maintaining disparate security baselines per cloud provider.
Defender CSPM is sold as a per-resource, per-month paid plan above the foundational CSPM included with basic Defender for Cloud onboarding. Enterprises already paying for Defender XDR gain the integrated exposure-management experience without adding a separate CSPM tool, creating a vendor-consolidation argument for budget reallocation.
Competitive positioning against Wiz, Palo Alto, and CrowdStrike
The integration positions Microsoft against Palo Alto Networks Prisma Cloud, Wiz, and CrowdStrike Falcon Cloud Security—all of which already offer unified cloud posture and risk views. Wiz's agentless CNAPP and CrowdStrike's recent AI Security Posture Management launch both emphasize integrated exposure management, but Microsoft's differentiator is tight coupling with the M365 and Entra ecosystem plus built-in telemetry from Azure.
Microsoft also introduced AI Security Posture Management in Defender for Cloud (preview), extending CSPM principles to AI models, datasets, and AI infrastructure on Azure and AWS. This follows similar announcements from Wiz and CrowdStrike, making AI-SPM a new competitive front within CSPM. The AI-SPM capability is part of the premium Defender CSPM plan, not the foundational tier.
For enterprises standardized on Microsoft security, the unified portal reduces operational friction. The question is whether Defender CSPM's feature set matches the depth of standalone CNAPP platforms—particularly for organizations with complex multicloud estates or those requiring agentless discovery and attack path analysis across clouds.
What to watch
Public preview status for the unified dashboard and serverless coverage means most enterprises will restrict deployment to non-production or limited pilots until general availability. Buyers migrating from incumbent CSPM tools should map the new Cloud Secure Score methodology to existing compliance controls and internal KPIs before committing to a full transition—scoring changes can disrupt SLA reporting.
Validate how the risk-based score handles edge cases: serverless functions with dynamic exposure, ephemeral containers, and workloads with fluctuating criticality. The shift from misconfiguration counts to risk-weighted posture is directionally correct, but scoring accuracy determines whether the feature drives better decisions or just different dashboards.
Enterprises evaluating CSPM platforms should benchmark Microsoft's serverless coverage (Azure Web Apps and AWS Lambda in preview) against Wiz, CrowdStrike, and Prisma Cloud's support for Lambda, Cloud Functions, and containerized workloads. If your serverless footprint includes GCP Cloud Functions or runs on niche runtimes, confirm whether Defender CSPM's preview scope meets your visibility requirements before consolidating tools.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
