Qualys Real-Time CSPM Cuts Posture Lag; Azure Foundational CSPM Changes Default Billing
Qualys launched real-time drift detection for multi-cloud environments with asset-based pricing. Microsoft changed Azure Foundational CSPM to opt-in, affecting default security coverage.
Qualys ships real-time posture detection with asset-based pricing
Qualys released Real-Time CSPM on August 12, integrated into its TotalCloud platform and priced per cloud asset scanned. The product detects configuration drift—exposed S3 buckets, new IAM policies, Kubernetes changes—immediately rather than waiting for periodic scans. Existing TotalCloud CSPM subscribers get the feature included; new buyers need to model costs based on cloud asset count, which matters for ephemeral workload environments where asset counts fluctuate.
The technical shift is from scheduled scans (daily, weekly) to continuous monitoring via cloud provider event streams. TotalCloud 2.27.0, released August 18, adds native Azure EventGrid integration that triggers inventory updates when Azure resources are created, modified, or deleted, while maintaining a recommended 48-hour full sync cycle. Oracle Cloud Infrastructure perimeter scanning now auto-discovers internet-facing compute with public IPs and feeds them into vulnerability assessment.
Qualys scores each drift event dynamically and recalibrates as the environment changes. Remediation guidance integrates with Jira and ServiceNow, pushing misconfig findings into existing ticketing workflows. Automated fixes are available for NIST, CIS Benchmarks, and PCI-DSS controls where policy allows. The risk scoring ties into the broader TruRisk platform, which aggregates vulnerability, posture, and patch data into a unified view.
For buyers already running Qualys VMDR, this creates a consolidation path. Instead of paying for standalone CSPM from Wiz, Orca, or Palo Alto Prisma Cloud, you can collapse posture management into the same platform handling vulnerability scanning. The trade-off is vendor lock-in and the need to verify that Qualys' real-time detection matches the speed and coverage of graph-based agentless platforms. Qualys positions this against "traditional periodic scans," which suggests the target is lagging incumbents rather than the fastest agentless competitors.
The August 18 release also added action-level RBAC for CSPM policies. Sub-users now get create, edit, delete, and view permissions at the policy and control level, scoped to specific connector tags. This matters for regulated industries that need strict separation of duties between cloud infrastructure teams and security operations. Previously, broad permissions made it difficult to delegate posture tasks without granting excessive access.
Microsoft shifts Azure Foundational CSPM to opt-in model
Microsoft changed the default behavior of Azure Foundational CSPM, moving from automatic enablement to an opt-in model. The timing aligns with broader changes to Defender for Cloud's plan structure, though exact dates were not disclosed in available documentation. This affects how Azure subscriptions are secured by default and has budget implications for organizations that assumed baseline posture management was included without explicit action.
Foundational CSPM previously activated automatically on new Azure subscriptions, providing basic misconfiguration detection, secure score, and compliance dashboards at no additional charge beyond the Azure subscription itself. The change means new subscriptions will not receive these features unless explicitly enabled, and existing subscriptions may require policy adjustments to maintain coverage. Microsoft has not published the commercial rationale, but the shift suggests a move toward clearer plan segmentation between free baseline features and paid Defender CSPM capabilities.
For enterprise buyers, this creates a gap-check moment. If your Azure landing zone automation assumes Foundational CSPM is active by default, new subscriptions or projects may deploy without posture monitoring until someone notices. Cloud platform teams need to update infrastructure-as-code templates and policy-as-code frameworks to explicitly enable Foundational CSPM or upgrade to Defender CSPM, which adds agentless scanning, attack path analysis, and deeper multi-cloud coverage for AWS and GCP.
The financial impact depends on your Azure footprint. Foundational CSPM remains free, so enabling it has no direct cost—but the operational cost of missing it is higher. Organizations with decentralized cloud provisioning and weak guardrails face the most risk. The change also raises questions about Microsoft's long-term strategy: whether this is a step toward deprecating Foundational CSPM entirely in favor of paid Defender plans, or simply a cleaner separation between basic and advanced posture capabilities.
What this means for CSPM buying decisions
The Qualys launch and Microsoft policy change both tighten the link between posture management and platform economics. Qualys is betting that buyers want CSPM bundled with vulnerability management under asset-based pricing, which favors organizations with stable cloud footprints and existing Qualys deployments. Microsoft is forcing explicit choices about baseline security coverage, which favors buyers with strong governance automation and penalizes those relying on default enablement.
If you are evaluating CSPM vendors, model Qualys pricing against your actual cloud asset count—VMs, containers, serverless functions—and compare it to per-account or per-workload pricing from Wiz, Orca, and Prisma Cloud. If you run Azure, audit your landing zone automation to confirm Foundational CSPM is explicitly enabled or decide whether Defender CSPM's paid features justify the upgrade. Both changes reward proactive governance and punish assumption-driven security postures.
What to watch
Qualys will need to prove that real-time detection delivers measurably faster remediation than existing agentless platforms. Look for customer case studies with specific MTTR improvements and coverage comparisons across AWS, Azure, GCP, and OCI. Microsoft's Foundational CSPM change may signal further segmentation in Defender for Cloud's pricing structure; watch for announcements about features moving from free to paid tiers. Both vendors are consolidating posture management into broader platforms, which means CSPM is increasingly a feature decision rather than a standalone product category.
Technology decisions, clearly explained.
Weekly analysis of the tools, platforms, and strategies that matter to B2B technology buyers. No fluff, no vendor spin.
