Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Secure compute (20–25%)
   --> Implement security for AI
      --> Enable Defender for AI Service in Cloud Workload Protection in Defender for Cloud


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Overview

Artificial intelligence workloads can introduce security risks that are different from those associated with traditional applications. Examples include unauthorized access to AI services, suspicious model usage, abuse of AI endpoints, anomalous activity, and attacks against applications that consume Azure AI services.

Microsoft Defender for AI Services is a workload protection capability in Microsoft Defender for Cloud designed to detect threats targeting Azure AI services workloads. It complements identity controls, network security, data protection, AI guardrails, and security posture management.

This topic is part of the Secure compute → Implement security for AI area of the SC-500 exam.


What Is Defender for AI Services?

Defender for AI Services provides security monitoring and threat protection for supported Azure AI services workloads. It is part of the broader Cloud Workload Protection Platform capabilities in Microsoft Defender for Cloud.

Its purpose is to help security teams:

  • Detect suspicious activity involving Azure AI services.
  • Identify potential threats targeting AI service resources.
  • Investigate security alerts in the Microsoft Defender portal.
  • Review AI security posture and coverage.
  • Combine AI workload protection with broader Defender for Cloud capabilities.
  • Correlate AI-related security information with other incidents and alerts.

Defender for AI Services is not a replacement for Microsoft Foundry guardrails, Azure AI Content Safety, Microsoft Entra ID, Azure Policy, or network controls. Instead, it adds a security monitoring and threat-detection layer to the AI workload.


AI Workload Security: Posture Versus Runtime Protection

A key exam concept is the difference between security posture management and runtime threat protection.

Cloud Security Posture Management

Cloud Security Posture Management, or CSPM, focuses on identifying and reducing configuration risks before they result in an incident.

Examples include:

  • An AI service that permits unnecessary public network access.
  • Local authentication being enabled when Microsoft Entra authentication should be used.
  • Excessive permissions assigned to an application or identity.
  • Missing security configuration or governance controls.
  • Resources that do not comply with organizational policies.

Cloud Workload Protection

Cloud Workload Protection, or CWP, focuses on detecting threats and suspicious behavior while workloads are operating.

Examples include:

  • Suspicious activity targeting an AI service.
  • Abnormal usage patterns.
  • Potential attempts to exploit an AI workload.
  • Threat indicators associated with an AI service resource.
  • Runtime activity that requires investigation.

Microsoft Defender for Cloud combines discovery, posture management, and runtime protection to provide broader visibility into AI environments.

Exam distinction

If a question asks which capability identifies a misconfiguration, think primarily of CSPM.

If it asks which capability detects a threat or suspicious activity during operation, think primarily of CWP, including Defender for AI Services.


Supported AI Workload Context

The learning material specifically associates this capability with Azure AI services workloads, including services such as:

  • Azure OpenAI-related workloads.
  • Microsoft Foundry and AI service resources.
  • AI model deployments and related service endpoints.
  • Applications that consume Azure AI services.

The exact supported resource types and detections can change as Microsoft expands the service. Therefore, organizations should verify current service coverage and supported regions before designing a production deployment.

Defender for AI Services should be considered part of a layered security architecture rather than a single control that secures every component of an AI solution.


Prerequisites

Before enabling Defender for AI Services, administrators should have:

  • An Azure subscription containing the AI workloads to protect.
  • Microsoft Defender for Cloud enabled for the subscription.
  • Appropriate permissions to configure Defender for Cloud plans.
  • Familiarity with Azure AI services and model deployments.
  • Familiarity with the Azure portal and Microsoft Defender portal.

The associated Microsoft Learn module identifies an Owner or Contributor role on the target subscription as a prerequisite for the configuration exercise. In production environments, organizations should use the least-privileged role that provides the required administrative capability.


Enable Defender for AI Services

The plan is enabled from the Defender for Cloud environment settings.

Step 1: Open Microsoft Defender for Cloud

  1. Sign in to the Azure portal.
  2. Search for and open Microsoft Defender for Cloud.
  3. Select Environment settings.

Step 2: Select the subscription

  1. Select the Azure subscription that contains the AI workloads.
  2. Review the available Defender for Cloud plans.

Defender for Cloud plans can be enabled at the subscription level. Enabling a plan at subscription scope generally applies the protection to applicable resources within that subscription.

Step 3: Enable the AI Services plan

  1. Locate the plan for Defender for AI Services.
  2. Turn the plan on.
  3. Review any available plan-specific configuration options.
  4. Select Save.

The exact portal labels and available configuration options may change as the service evolves. The important exam concept is that Defender for AI Services is enabled as a Defender for Cloud workload protection plan, rather than by installing a traditional agent on each AI service resource.


Configure Plan Components

After enabling the plan, review its available components and configuration settings.

Depending on the current service capabilities, configuration may include:

  • Selecting which AI workloads are covered.
  • Reviewing supported AI service resource types.
  • Enabling or disabling available protection components.
  • Configuring notification and monitoring integrations.
  • Reviewing the subscription’s protection status.
  • Confirming that the required security data is available.

Microsoft continuously adds capabilities to Defender for Cloud plans. Azure Policy includes a built-in initiative named Configure Microsoft Defender threat protection for AI Services to be enabled, which can help ensure that newly created or existing subscriptions remain configured according to organizational requirements.

Important distinction

The Defender for AI Services plan provides the protection capability. Azure Policy can help enforce or audit the desired configuration.

These are different functions:

CapabilityPrimary purpose
Defender for AI ServicesDetect threats targeting AI services workloads
Azure PolicyAudit or enforce resource configuration
Microsoft Defender for Cloud CSPMIdentify security posture weaknesses
Microsoft Foundry guardrailsApply controls to AI inputs, outputs, and model behavior
Microsoft Entra IDAuthenticate and authorize users, applications, and identities
Private Link and network controlsReduce network exposure

Monitor AI Security with the Data and AI Security Dashboard

After the plan is enabled, use the Data and AI security dashboard in Microsoft Defender for Cloud to review AI security information.

The dashboard is intended to provide visibility into areas such as:

  • AI resources discovered in the environment.
  • Security posture information.
  • Protection coverage.
  • Security recommendations.
  • AI-related alerts and findings.
  • Potential risks affecting AI workloads.

The dashboard helps security teams understand whether AI resources are being protected and where additional action may be required.

Recommended monitoring process

  1. Review the AI resource inventory.
  2. Confirm that expected subscriptions and resources are represented.
  3. Review recommendations and unresolved security issues.
  4. Investigate active alerts.
  5. Determine whether the issue is a configuration problem, an identity problem, a network problem, or a runtime threat.
  6. Remediate the issue.
  7. Confirm that the resource returns to the expected protection state.

Investigate AI Threat Protection Alerts

Defender for AI Services can generate security alerts when suspicious activity associated with supported AI workloads is detected.

When investigating an alert, review:

  • The affected subscription.
  • The affected AI service or resource.
  • The alert severity.
  • The detection time.
  • The activity associated with the alert.
  • The identity or application involved, when available.
  • Related resources and incidents.
  • Recommended remediation actions.

AI-related alerts can be investigated through the Microsoft Defender portal. Defender for Cloud alerts can also integrate with Microsoft Defender XDR, allowing security operations teams to correlate cloud alerts with identity, endpoint, email, and other security signals.

Example investigation workflow

A security analyst notices suspicious activity associated with an AI service.

  1. Open the alert in the Defender portal.
  2. Review the affected AI resource.
  3. Examine the evidence and activity timeline.
  4. Identify the application, identity, or network source involved.
  5. Determine whether the activity is expected.
  6. Disable or restrict a compromised identity if necessary.
  7. Rotate exposed credentials.
  8. Review network access and authentication configuration.
  9. Investigate related resources and incidents.
  10. Document the remediation and verify that the threat is no longer present.

Relationship to Other AI Security Controls

Defender for AI Services should be deployed as part of defense in depth.

Microsoft Entra ID

Use Microsoft Entra ID to control who or what can access AI services.

Recommended controls include:

  • Microsoft Entra authentication.
  • Managed identities.
  • Role-based access control.
  • Conditional Access where applicable.
  • Least-privilege permissions.
  • Removal of unnecessary credentials.

Defender for AI Services may detect suspicious activity, but it does not replace proper identity configuration.

Azure AI Content Safety and Foundry Guardrails

Guardrails help control unsafe or undesirable AI inputs and outputs. They address risks such as:

  • Harmful content.
  • Prompt-based abuse.
  • Inappropriate model responses.
  • Content filtering requirements.
  • Certain application-level AI risks.

Runtime threat protection and AI guardrails address different security concerns. A workload can have guardrails configured and still require threat monitoring.

Azure Policy

Azure Policy can audit or enforce requirements such as:

  • AI services should have local authentication disabled.
  • AI services should restrict network access.
  • Defender for AI Services should be enabled.

For example, Microsoft provides policy definitions related to disabling key-based access and restricting network access for Azure AI Services resources.

Network security

Network controls can reduce exposure by using:

  • Private endpoints.
  • Virtual network integration where supported.
  • Network access restrictions.
  • Firewall rules.
  • Private DNS configuration.
  • Restricted administrative access.

Network restrictions reduce the attack surface, while Defender for AI Services helps detect threats against the workload.

Microsoft Defender XDR

Defender XDR can provide a broader incident investigation experience by correlating AI workload alerts with other security signals.


Subscription-Level Enablement and Scale

Defender for Cloud plans are commonly configured at subscription scope. Organizations with many subscriptions should consider centralized governance.

Possible approaches include:

  • Enabling the plan on individual subscriptions.
  • Using management groups to organize subscriptions.
  • Applying Azure Policy initiatives.
  • Auditing plan coverage.
  • Reviewing coverage workbooks.
  • Establishing a standard for newly created subscriptions.

The Defender for Cloud coverage workbook helps administrators understand which plans are enabled across subscriptions and resources.

Why centralized governance matters

Without centralized governance, an organization may have:

  • AI resources deployed in subscriptions without protection.
  • Inconsistent security configurations.
  • Newly created resources that are not covered.
  • Different teams using different security standards.
  • Gaps between development, test, and production environments.

Azure Policy can help maintain consistency, but policy compliance should be verified rather than assumed.


Common Troubleshooting Issues

The plan is not visible

Possible causes include:

  • The wrong subscription or environment was selected.
  • The user lacks sufficient permissions.
  • The capability is not available in the selected region.
  • The service or plan name has changed.
  • The feature is subject to preview or availability limitations.

AI resources are not appearing in the dashboard

Check:

  • Whether the correct subscription is selected.
  • Whether the plan is enabled.
  • Whether the resource type is supported.
  • Whether the resource is in a supported region.
  • Whether sufficient time has passed for discovery and data collection.
  • Whether the resource is excluded by configuration or policy.

Alerts are not appearing

Check:

  • Whether the plan is enabled for the correct subscription.
  • Whether the activity matches a supported detection.
  • Whether the resource is covered.
  • Whether the alert is being viewed in the correct portal.
  • Whether filters are hiding the alert.
  • Whether the issue is a posture recommendation rather than a runtime alert.

A resource is secure but still has recommendations

This may occur because:

  • The recommendation has not refreshed.
  • The resource has another unresolved configuration issue.
  • A policy assignment requires a different setting.
  • The resource is evaluated against a broader security standard.
  • The recommendation applies to a different component of the workload.

Best Practices

Enable protection before production deployment

Do not wait until an AI service is compromised before enabling monitoring and threat protection.

Use least privilege

Assign only the permissions required to configure Defender for Cloud and manage AI resources.

Combine CSPM and CWP

Use CSPM to reduce misconfigurations and CWP to detect suspicious runtime activity.

Restrict network exposure

Use private endpoints and network restrictions where supported and appropriate.

Prefer Microsoft Entra authentication

Avoid unnecessary use of static keys. Use managed identities or Microsoft Entra authentication when supported.

Enforce configuration with Azure Policy

Use policy to audit or enforce requirements such as:

  • Defender for AI Services being enabled.
  • Local authentication being disabled.
  • Network access being restricted.

Monitor the Data and AI dashboard

Review coverage, recommendations, and alerts regularly.

Integrate with incident response

Ensure that AI security alerts are routed to the appropriate security operations team and correlated with other incidents.

Do not assume that one control solves every AI risk

AI security requires multiple layers, including:

  • Identity.
  • Network security.
  • Data protection.
  • Application security.
  • Guardrails.
  • Runtime threat detection.
  • Logging and monitoring.
  • Governance and compliance.

Exam-Focused Comparisons

Exam conceptCorrect interpretation
Defender for AI ServicesRuntime threat protection for supported Azure AI services workloads
AI workloads planDefender for Cloud plan used to protect AI workloads
Data and AI security dashboardView AI security posture, resources, and protection information
CSPMIdentifies configuration and posture weaknesses
CWPDetects threats and suspicious runtime activity
Azure PolicyAudits or enforces Azure resource configuration
Foundry guardrailsControls AI behavior, inputs, and outputs
Microsoft Entra IDProvides authentication and authorization
Defender XDRCorrelates and investigates security signals across workloads
Coverage workbookHelps verify Defender for Cloud plan coverage

Practice Exam Questions

Question 1

An organization uses Azure AI services for a customer-support application. The security team wants to detect suspicious activity targeting the AI service while the application is running. Which capability should the team enable?

A. Azure Policy
B. Microsoft Defender for AI Services
C. Microsoft Entra Privileged Identity Management
D. Azure Resource Manager locks

Answer: B

Explanation: Microsoft Defender for AI Services is designed to detect threats targeting supported Azure AI services workloads. Azure Policy governs configuration, PIM manages privileged access, and resource locks help prevent accidental deletion or modification.


Question 2

Where should an administrator go to enable Defender for AI Services for an Azure subscription?

A. Microsoft Foundry project settings
B. Azure Monitor Workbooks
C. Microsoft Defender portal Incidents page
D. Microsoft Defender for Cloud Environment settings

Answer: D

Explanation: Defender for Cloud workload protection plans are enabled through Microsoft Defender for Cloud → Environment settings, where the administrator selects the appropriate subscription and enables the required plan.


Question 3

A security engineer wants to identify an AI service that has an insecure configuration, such as unnecessary public network access. Which Defender for Cloud capability is most directly relevant?

A. Cloud Security Posture Management
B. Cloud Workload Protection
C. Microsoft Defender XDR incident correlation
D. Azure Bastion

Answer: A

Explanation: CSPM identifies configuration weaknesses and security posture risks. CWP focuses on runtime threats, Defender XDR supports investigation and correlation, and Azure Bastion provides secure administrative access to virtual machines.


Question 4

After enabling Defender for AI Services, which feature should an administrator use to review AI resource insights, security posture, and protection information?

A. Azure Service Health
B. Azure Advisor only
C. Data and AI security dashboard
D. Azure Cost Management

Answer: C

Explanation: The Data and AI security dashboard in Defender for Cloud provides visibility into AI resources, security posture, and related protection information.


Question 5

An organization wants to ensure that Defender for AI Services remains enabled across newly created subscriptions. Which approach is most appropriate?

A. Configure a resource lock on every AI service
B. Create a custom Microsoft Entra authentication method
C. Enable Azure Bastion
D. Use Azure Policy to audit or deploy the required Defender for AI Services configuration

Answer: D

Explanation: Azure Policy can help audit or enforce the desired Defender for Cloud plan configuration across a defined scope. Resource locks, authentication methods, and Bastion do not ensure that the Defender for AI Services plan is enabled.


Question 6

Which statement best describes the relationship between Defender for AI Services and Microsoft Foundry guardrails?

A. Defender for AI Services replaces all Foundry guardrails
B. Defender for AI Services detects workload threats, while guardrails help control AI inputs, outputs, and behavior
C. Foundry guardrails are used only to enable Azure subscriptions
D. Defender for AI Services is required only for virtual machines

Answer: B

Explanation: These controls address different risks. Defender for AI Services provides workload threat protection, while Foundry guardrails help manage AI behavior and content-related risks.


Question 7

A security analyst receives an alert involving suspicious activity against an Azure AI service. Where should the analyst investigate the alert?

A. Microsoft Defender portal
B. Azure Storage Explorer
C. Azure Resource Graph only
D. Microsoft Entra Domain Services

Answer: A

Explanation: Defender for AI Services alerts can be investigated in the Microsoft Defender portal. Defender for Cloud alerts can also integrate with Microsoft Defender XDR for broader correlation and investigation.


Question 8

Which statement about Defender for AI Services is correct?

A. It eliminates the need for identity and network controls
B. It encrypts every prompt and model response automatically
C. It provides runtime threat protection for supported Azure AI services workloads
D. It is an Azure resource lock mechanism

Answer: C

Explanation: Defender for AI Services is a workload protection capability. It does not replace authentication, authorization, encryption, network restrictions, or other defense-in-depth controls.


Question 9

An administrator enables Defender for AI Services but does not see a particular AI resource in the dashboard. What should the administrator check first?

A. Whether the resource is supported, in the correct subscription, and in a supported region
B. Whether the resource has an Azure Bastion host
C. Whether the resource has a resource lock
D. Whether the application uses a virtual machine scale set

Answer: A

Explanation: Missing resource visibility can result from unsupported resource types, incorrect subscription selection, regional availability, or discovery delays. Bastion, resource locks, and VM scale sets are not prerequisites for discovering an AI service resource.


Question 10

Which combination provides the most complete defense-in-depth approach for an Azure AI workload?

A. Resource locks and Azure Cost Management
B. Azure Bastion and storage replication
C. Azure Policy only
D. Microsoft Entra authentication, network restrictions, AI guardrails, Defender for Cloud posture management, and Defender for AI Services runtime protection

Answer: D

Explanation: AI workloads require multiple complementary controls. Identity protects access, network restrictions reduce exposure, guardrails address AI behavior, CSPM identifies configuration weaknesses, and Defender for AI Services detects runtime threats.


Key Takeaways

For the SC-500 exam, remember the following:

  1. Defender for AI Services is a Defender for Cloud workload protection capability.
  2. It focuses on detecting threats targeting supported Azure AI services workloads.
  3. Enable it through Microsoft Defender for Cloud → Environment settings.
  4. Use the Data and AI security dashboard to monitor AI security information.
  5. Investigate alerts in the Microsoft Defender portal.
  6. Use CSPM for configuration and posture risks.
  7. Use CWP for runtime threat detection.
  8. Use Azure Policy to audit or enforce plan configuration.
  9. Defender for AI Services complements—not replaces—identity, network, guardrail, and data security controls.
  10. Treat AI security as a defense-in-depth responsibility rather than a single-product task.

Go to the SC-500 Exam Prep Hub main page

Leave a Reply