Microsoft Turns Off Auto-Enabled CSPM for New Azure Accounts on October 27
Microsoft will disable Foundational CSPM by default for new Azure subscriptions starting October 27, 2026, forcing security teams to explicitly opt in or fund paid Defender CSPM.
Microsoft shifts CSPM from default to opt-in
Microsoft will stop enabling Foundational CSPM by default for new Azure subscriptions on October 27, 2026. The free cloud security posture management plan will remain active on existing subscriptions unless manually disabled, but new Azure tenants will launch without posture monitoring unless security teams explicitly turn it on.
The change removes a layer of baseline protection that has been automatic since Defender for Cloud launched. New Azure projects will no longer receive misconfiguration detection, security recommendations, or compliance mapping out of the box. The paid Defender CSPM plan—which adds attack path analysis, AI-driven risk prioritization, and DevOps security features—remains unchanged, billed per resource onboarded across Azure, AWS, GCP, and on-premises infrastructure via Azure Arc.
Microsoft updated the Defender for Cloud documentation on September 11, 2026, clarifying the scope and availability of both CSPM plans. Foundational CSPM covers basic posture monitoring across Azure, AWS, and GCP at no cost. Defender CSPM extends that with advanced features including pull request annotations, code-to-cloud mapping, and expanded Azure DevOps recommendations. The paid plan is available in commercial Azure regions, Azure Government, Azure Government Secret, multi-cloud environments, and integrates with GitHub and Azure DevOps.
What this means for enterprise buyers
Security teams must now treat CSPM activation as a manual governance control rather than an inherited default. Organizations that provision Azure subscriptions through infrastructure-as-code templates, landing zones, or automated account vending will need to update those workflows to explicitly enable Foundational CSPM or fund Defender CSPM licenses. Without that change, new cloud projects will go live with no posture monitoring.
The shift creates budget pressure in two directions. Teams satisfied with free baseline posture management must now allocate engineering time to embed CSPM activation into provisioning runbooks. Teams that want advanced features—attack path analysis, AI-driven posture, DevOps security—must budget for Defender CSPM on a per-resource basis. The billing model ties cost directly to resource counts across all onboarded clouds, including AWS and GCP workloads, which can multiply the line item quickly in multi-cloud estates.
For government and regulated industries, the change complicates consolidation strategies. Defender CSPM's availability in Azure Government and Azure Government Secret clouds positions Microsoft as a single-pane option for posture management across Azure, AWS, and GCP in classified and public sector environments. Agencies must now decide whether to pay for that consolidation or maintain neutral third-party CSPM tools to avoid platform lock-in, especially where non-Microsoft infrastructure and DevOps pipelines dominate.
DevOps security posture becomes an explicit upsell. Advanced capabilities such as pull request annotations, code-to-cloud mapping, and security explorer features are only available in paid Defender CSPM. Enterprises investing in GitHub, Azure DevOps, and cloud-native pipelines must decide whether to fund those features through Defender CSPM licenses or use third-party tools for pipeline security and treat CSPM purely as runtime posture.
Third-party CSPM vendors gain an opening
The policy change creates more room for Wiz, Palo Alto Networks Prisma Cloud, Check Point CloudGuard, CrowdStrike Falcon Cloud Security, and Trend Micro to insert themselves early in new cloud projects. When CSPM was auto-enabled, Microsoft held the default position in Azure tenants. Now, new Azure accounts launch with no posture management, and vendors can compete on equal footing for initial deployment.
This matters most in brownfield environments where Azure is not the dominant cloud. Organizations running multi-cloud infrastructure often prefer cloud-agnostic CSPM tools to avoid dependencies on a single hyperscaler's security stack. The shift from auto-enabled to opt-in makes that preference easier to act on during initial Azure deployment.
What to watch
Security teams should audit provisioning workflows before October 27, 2026, to ensure new Azure subscriptions do not launch without posture monitoring. Organizations using Azure landing zones, Terraform, or automated account vending must update those templates to explicitly enable Foundational CSPM or allocate budget for Defender CSPM licenses.
For multi-cloud buyers, the decision point is whether to consolidate posture management into Defender CSPM across Azure, AWS, and GCP or maintain neutral third-party tools. The answer depends on the relative weight of Azure in the infrastructure mix and the value placed on avoiding platform lock-in. Microsoft's resource-based billing model makes cost forecasting straightforward but requires accurate resource counts across all clouds to avoid budget overruns.
DevOps-heavy organizations should compare the cost of Defender CSPM's advanced DevOps features against third-party pipeline security tools. The feature set—pull request annotations, code-to-cloud mapping, attack path analysis—is only available in the paid plan, and the decision to fund it should align with the organization's investment in GitHub and Azure DevOps as primary pipeline platforms.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
