Tag: Cloud Security Posture Management (CSPM)

Enable and configure Defender for Cloud workload protection plans (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Enable and configure Defender for Cloud workload protection plans


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Microsoft Defender for Cloud provides security capabilities for cloud environments from security posture management through active workload protection.

For the SC-500 exam, an important distinction is between:

  • Cloud Security Posture Management (CSPM) — identifies security weaknesses, misconfigurations, exposure, and compliance gaps.
  • Cloud Workload Protection Platform (CWPP) — provides workload-specific threat protection and security capabilities for resources such as servers, containers, databases, storage, applications, APIs, and AI services.

Defender for Cloud’s workload protection plans are enabled according to the types of workloads an organization needs to protect. These plans provide capabilities such as threat detection, vulnerability assessment, runtime protection, malware scanning, and other workload-specific security controls.

For the SC-500 exam, you should understand which Defender plan protects which workload, how to enable the plan, how to configure important plan-specific settings, how to deploy plans at scale, and how to verify coverage.


1. What Is Cloud Workload Protection?

Cloud workload protection focuses on protecting workloads while they are running, rather than simply identifying whether their configuration is secure.

For example:

WorkloadPotential Security ConcernRelevant Defender Capability
Virtual machinesMalware, vulnerabilities, suspicious activityDefender for Servers
KubernetesVulnerable containers, runtime attacksDefender for Containers
Azure StorageMalicious uploads, data threatsDefender for Storage
Azure SQLDatabase attacks and vulnerabilitiesDefender for Databases
App ServiceAttacks against web applicationsDefender for App Service
APIsAPI vulnerabilities and attacksDefender for APIs
Key VaultSuspicious access to secrets and keysDefender for Key Vault
AI servicesThreats against generative AI applicationsDefender for AI Services
Azure resource managementSuspicious resource-management operationsDefender for Resource Manager
DNSDNS-layer threatsDefender for DNS

The important SC-500 concept is that you select protection plans based on the workloads that exist in your environment.

Defender for Cloud currently provides a broad catalog of workload-specific protection plans, including servers, containers, storage, databases, Key Vault, App Service, APIs, AI Services, DNS, and Resource Manager.


2. CSPM vs. CWPP

One of the most important distinctions for the exam is the difference between CSPM and workload protection.

Cloud Security Posture Management

CSPM answers questions such as:

“Is this environment configured securely?”

Examples include:

  • Is a storage account publicly accessible?
  • Is encryption configured?
  • Is a network security control missing?
  • Does a resource violate a security policy?
  • Does the environment have excessive risk?

Defender for Cloud’s foundational CSPM capabilities include recommendations, asset inventory, workbooks, Secure Score, and Microsoft cloud security benchmark capabilities.

Cloud Workload Protection

CWPP answers questions such as:

“Is this workload currently protected against threats?”

Examples include:

  • Is a VM protected against malware and endpoint threats?
  • Is a Kubernetes cluster receiving runtime threat detection?
  • Is malicious content being detected when uploaded to storage?
  • Are suspicious database activities being detected?
  • Are API attacks being detected?
  • Are AI workloads receiving threat protection?

Exam tip:

CSPM focuses primarily on improving security posture.
CWPP focuses primarily on protecting workloads from active threats.

In real environments, the two capabilities complement each other rather than replacing one another.


3. Defender for Cloud Workload Protection Plans

Defender for Cloud contains multiple workload-specific plans.

Some of the important plans for SC-500 include:

Defender for Servers

Protects physical and virtual machines across Azure and supported multicloud environments.

Defender for Servers provides capabilities such as:

  • Threat detection
  • Endpoint protection integration
  • Vulnerability assessment
  • Security recommendations
  • Agentless scanning
  • Additional Plan 2 capabilities

Defender for Servers is available as Plan 1 (P1) and Plan 2 (P2).


Defender for Containers

Protects Kubernetes environments, including supported Azure Kubernetes Service, Amazon EKS, Google GKE, and Azure Arc-enabled Kubernetes environments.

Depending on the environment and configuration, capabilities can include:

  • Vulnerability scanning
  • Runtime threat protection
  • Security posture assessments
  • Agentless scanning
  • Defender sensor
  • Kubernetes API access
  • Registry access

The exact components available depend on the Kubernetes environment and configuration.


Defender for Storage

Defender for Storage provides security monitoring and threat detection for Azure Storage.

The current plan includes capabilities such as:

  • Activity monitoring
  • On-upload malware scanning
  • Sensitive-data threat detection

Malware scanning can also be configured with options such as scanning limits, filtering, scan-result storage, and automated integration through Event Grid or Log Analytics.


Defender for Databases

Defender for Databases protects supported database workloads.

For example, Defender for Azure SQL Databases provides attack detection and threat-response capabilities for Azure SQL databases.

The broader database protection capabilities also include support for other database workloads, depending on the specific Defender plan and supported environment.

For SQL Server running on machines, the SQL Servers on Machines protection is selected within the Defender for Databases plan.


Defender for App Service

Defender for App Service provides protection for applications running on Azure App Service.

It is designed to identify attacks targeting App Service web applications and APIs.


Defender for APIs

Defender for APIs provides security visibility and protection for APIs managed through Azure API Management.

Capabilities include:

  • API discovery
  • Security posture assessment
  • Vulnerability prioritization
  • Threat detection
  • Runtime protection

Defender for APIs is enabled at the subscription level, and the appropriate plan should be selected based on API traffic requirements.

Important exam consideration: enabling Defender for APIs does not automatically mean that every API in existence is protected. The APIs must be onboarded appropriately, and the APIs you want to protect must be published through Azure API Management.


Defender for Key Vault

Defender for Key Vault detects unusual and potentially harmful attempts to access or exploit Key Vault accounts.

This is particularly important because Key Vault can contain highly sensitive:

  • Secrets
  • Encryption keys
  • Certificates

The purpose is not simply to encrypt the vault. Defender for Key Vault adds threat-detection capabilities around access and usage.


Defender for AI Services

AI workloads introduce threats that traditional infrastructure security controls may not completely address.

Defender for AI Services provides threat protection for generative AI applications and can detect suspicious activity involving supported AI services.

For SC-500, remember:

AI workloads are now explicitly part of the Defender for Cloud workload-protection model.

This is especially relevant because the SC-500 certification focuses on cloud and AI workloads, rather than traditional cloud infrastructure alone.


Defender for Resource Manager

Defender for Resource Manager monitors Azure resource-management operations and can detect suspicious activity involving management operations.

This protects an important control plane:

The Azure Resource Manager layer through which resources are created, modified, and managed.

It is different from protecting a VM’s operating system or a storage account’s data plane.


Defender for DNS

Defender for DNS provides DNS-layer threat detection for Azure resources.

This illustrates another important Defender for Cloud concept:

Defender plans are specialized according to the attack surface being protected.


4. Choosing the Appropriate Defender Plan

A common SC-500 scenario is:

“An organization has identified a particular workload and wants to enable the appropriate Defender protection.”

The first step is to identify the workload.

For example:

RequirementAppropriate plan
Protect Azure VMsDefender for Servers
Protect AKS/KubernetesDefender for Containers
Detect malicious files uploaded to StorageDefender for Storage
Protect Azure SQL databasesDefender for Databases
Protect App Service applicationsDefender for App Service
Protect APIs managed through API ManagementDefender for APIs
Detect suspicious Key Vault accessDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure resource-management operationsDefender for Resource Manager
Detect DNS-based threatsDefender for DNS

The exam may deliberately include several plausible answers.

The key is to identify the workload, not simply the type of security problem.


5. Enabling Defender for Cloud

Before configuring individual workload protection plans, Defender for Cloud must be enabled for the relevant environment.

For Azure, Defender for Cloud can be accessed through the Azure portal.

Once the environment is available, the administrator can use:

Microsoft Defender for Cloud → Environment settings

From there, the administrator selects the relevant:

  • Azure subscription
  • AWS account
  • GCP project
  • Other supported environment/connector

The available Defender plans can then be configured for that environment.


6. Environment Settings

The Environment settings area is particularly important for SC-500.

It provides a centralized location for configuring Defender plans for the selected environment.

A typical workflow is:

  1. Open Microsoft Defender for Cloud.
  2. Select Environment settings.
  3. Select the target environment.
  4. Locate the desired Defender plan.
  5. Turn the plan On.
  6. Configure plan-specific settings.
  7. Save the configuration.
  8. Verify coverage.

For example, to enable Defender for Servers, you select the appropriate environment, turn on the Servers plan, choose the appropriate plan tier, and save the configuration.


7. Defender for Servers Plan 1 vs. Plan 2

Defender for Servers is especially important for the SC-500 exam because it contains two plan levels:

  • Plan 1
  • Plan 2

When enabling Defender for Servers, Plan 2 is selected by default in the current Azure portal workflow, but the administrator can change the selection to Plan 1.

The plans provide different levels of capability.

For example:

CapabilityPlan 1Plan 2
Defender for Endpoint integrationYesYes
Vulnerability assessmentYesYes
Agentless scanning—Yes
File integrity monitoring—Available
Additional advanced capabilitiesLimitedMore extensive

Current configuration guidance indicates that vulnerability assessment is enabled by default when either P1 or P2 is enabled, Defender for Endpoint integration is available with both, and agentless scanning is associated with Plan 2. File integrity monitoring is a Plan 2 capability that is not enabled by default.

Exam strategy

If a question specifically requires a Plan 2-only capability, Plan 1 is not sufficient.

Do not assume:

“Servers enabled = every Defender for Servers capability is enabled.”

Instead, identify the required capability and determine which plan provides it.


8. Configuring Defender for Servers

After enabling Defender for Servers, plan-specific settings can be configured.

Examples include:

Vulnerability assessment

Helps identify vulnerable software and applications on protected machines.

Endpoint protection

Defender for Endpoint integration provides endpoint detection and response capabilities.

Agentless scanning

Agentless scanning can provide additional visibility without requiring a traditional security agent for certain scanning scenarios.

File integrity monitoring

File integrity monitoring can identify changes to important files and registries.

The availability and default state of these capabilities depend on the selected plan.


9. Defender for Storage Configuration

Defender for Storage provides several important configurable capabilities.

The current Defender for Storage plan includes:

  • Activity monitoring
  • Malware scanning
  • Sensitive-data threat detection

Malware scanning can be configured with options such as:

  • Monthly scanning caps
  • Scan filtering
  • Blob index tags for scan results
  • Soft deletion of malicious blobs
  • Event Grid integration
  • Log Analytics integration

Example

Suppose an organization uploads customer documents to Azure Blob Storage.

The security team wants to:

  1. Detect malicious files immediately after upload.
  2. Record scan results.
  3. Automatically initiate downstream processing when malware is discovered.

Defender for Storage can provide the malware scanning capability, while Event Grid can be used to integrate scan results into automated response workflows.


10. Defender for Storage: Important Exam Distinction

Do not confuse:

Activity monitoring

with:

Malware scanning

Activity monitoring provides security analysis of activity involving storage.

Malware scanning specifically detects malicious files, including files uploaded to storage.

Similarly, sensitive-data threat detection addresses suspicious activity involving resources containing sensitive data.

Therefore, if an exam question says:

“Detect malicious files as they are uploaded to Blob Storage.”

The relevant capability is:

Defender for Storage with on-upload malware scanning.


11. Defender for Databases

Defender for Databases protects database workloads against threats and vulnerabilities.

For Azure SQL databases, Defender for Azure SQL Databases can be enabled through the Databases plan.

The administrator:

  1. Opens Defender for Cloud.
  2. Selects Environment settings.
  3. Selects the relevant environment.
  4. Locates Databases.
  5. Selects Select types.
  6. Enables Azure SQL Databases.
  7. Selects Continue.
  8. Saves the configuration.

This illustrates an important Defender for Cloud design:

A single high-level plan may contain multiple workload-specific resource types.

For example, Defender for Databases contains multiple database protection capabilities rather than representing only one specific database engine.


12. SQL Servers on Machines

SQL Server workloads may run on:

  • Azure virtual machines
  • Azure Arc-enabled servers

For SQL Servers on Machines, the protection is configured under the Defender for Databases plan.

The administrator can select the SQL Servers on Machines resource type within the Databases plan.

This is a useful exam distinction.

If a question describes:

“SQL Server installed on an Azure VM”

do not automatically treat it as the same configuration scenario as an Azure SQL Database.

The underlying workload type matters.


13. Defender for Containers

Defender for Containers protects Kubernetes environments.

Depending on the environment, administrators can configure components such as:

  • Agentless scanning
  • Defender sensor
  • Azure Policy
  • Kubernetes API access
  • Registry access

These capabilities support different aspects of container security.

For example:

Defender sensor

is associated with collecting runtime security telemetry used for threat detection.

Registry access

supports vulnerability assessment for container images in connected registries.

Azure Policy

supports Kubernetes security posture assessment and related recommendations.

Kubernetes API access

allows Defender for Cloud to obtain Kubernetes metadata required for inventory, configuration analysis, and related capabilities.


14. Defender for APIs

Defender for APIs provides protection for APIs managed through Azure API Management.

Its capabilities include:

  • Discovery
  • Security posture visibility
  • Vulnerability prioritization
  • Runtime threat detection
  • Response capabilities

One important configuration consideration is selecting the appropriate plan based on API traffic.

The current deployment guidance indicates that subscriptions are opted into Plan 1 by default and that organizations should select a plan appropriate for their API traffic volume to avoid unexpected overages.

Exam scenario

A company has a high-volume API platform.

The question asks what should be considered before selecting the Defender for APIs plan.

The best answer is likely to focus on:

API traffic volume and the plan entitlement associated with that traffic.


15. Defender for AI Services

AI workloads require specialized protection because they introduce risks beyond conventional infrastructure.

Defender for Cloud’s AI threat protection can provide:

  • AI workload discovery
  • Security posture capabilities
  • Runtime threat detection
  • Security alerts
  • Investigation capabilities

Microsoft’s current Defender for Cloud training specifically includes enabling and configuring the AI workloads plan and reviewing AI resource insights, posture, and runtime threats.

This is particularly important for SC-500 because AI security is integrated directly into the certification’s scope.


16. AI Threat Detection and Application Context

AI security can involve applications that sit between an end user and an AI service.

For example:

User → Web application → Azure OpenAI → Model

The AI service may see a request, but security investigators may need to understand:

  • Which user initiated it?
  • Which application generated it?
  • What source IP was involved?

Defender for Cloud’s AI threat protection can use additional security context to improve alert investigation. Microsoft documents the use of fields such as end-user identity, source IP, and application name for supported Azure OpenAI scenarios.

The important SC-500 concept is:

AI workload protection is not limited to infrastructure configuration; it can also provide runtime threat detection and investigation context.


17. Azure-Only vs. Multicloud Defender Plans

Not every Defender for Cloud workload plan applies to every cloud.

Some plans support Azure, AWS, and GCP workloads, while others are Azure-specific.

For example, current support information identifies these as Azure-only plans:

  • Defender for Storage
  • Defender for Key Vault
  • Defender for Resource Manager
  • Defender for DNS
  • Defender for App Service
  • Defender for APIs
  • Defender for AI Services

Defender for Servers and Defender for Containers, by contrast, have significant multicloud support.

Exam tip

If a question says:

“An organization wants to protect an AWS EC2 instance.”

Think about plans that support multicloud workloads, such as:

Defender for Servers

rather than Azure-only plans such as Defender for Storage.


18. Subscription-Level vs. Resource-Level Configuration

Defender for Cloud supports different deployment scopes depending on the plan.

A common approach is to enable a workload protection plan at the subscription level.

This is generally easier to manage and provides broader coverage.

Some scenarios also support resource-level configuration.

For example, Defender for Servers can be configured at different scopes, although Microsoft recommends subscription-level deployment for many scenarios.

However, resource-level configuration can be useful when:

  • Different workloads require different protection levels.
  • Specific resources need to be excluded.
  • An organization is transitioning workloads.
  • Different security requirements exist within the same subscription.

Important exam concept

Do not assume every Defender plan supports the same resource-level configuration options.

Always evaluate the specific plan.


19. Management Group Deployment

Large organizations often have many subscriptions.

Enabling every Defender plan manually on every subscription can be inefficient.

Defender for Cloud can be managed at larger scopes, including management groups, where supported.

This enables organizations to establish consistent protection across a portfolio of subscriptions.

The basic enterprise pattern is:

Management Group

↓

Subscriptions

↓

Workloads

The objective is centralized governance combined with consistent security coverage.


20. Deploying Defender Plans at Scale

Azure Policy can be used to help configure Defender for Cloud plans at scale.

Microsoft provides built-in policy initiatives for configuring Defender plans.

For example, there are built-in policies for:

  • Defender for Servers
  • Defender for Containers
  • Defender for Storage
  • Defender for Databases
  • Defender for APIs
  • Defender for AI Services
  • Defender CSPM
  • Other Defender capabilities

This is especially valuable when an organization wants to enforce security requirements consistently.

Example

An organization has 50 Azure subscriptions and wants Defender for Storage enabled consistently.

Instead of manually configuring each subscription, the organization can use an appropriate Azure Policy assignment to configure the plan at scale.


21. Azure Policy and Defender Plans

An important distinction is:

Azure Policy

can be used to enforce or deploy configurations.

Defender for Cloud

provides the security-management and workload-protection capabilities.

They work together.

For example, a policy can require that Defender for Storage be enabled.

The policy can evaluate the environment and deploy the appropriate configuration where applicable. Microsoft provides a built-in policy specifically for configuring Defender for Storage with its available capabilities.


22. Verifying Protection Coverage

Enabling a Defender plan is not the final step.

Security administrators should verify that the intended resources are actually covered.

Defender for Cloud provides a Coverage workbook that shows which plans are enabled and provides insight into coverage across subscriptions and resources.

A good operational workflow is:

Select plan

↓

Enable plan

↓

Configure plan-specific settings

↓

Deploy required components

↓

Verify coverage

↓

Review alerts/recommendations

↓

Remediate gaps


23. Why Verification Matters

Consider this scenario:

An administrator enables Defender for Servers at the subscription level.

They assume every VM is protected.

However:

  • Some resources may have different configuration.
  • Some resources may be excluded.
  • Required components may not be deployed.
  • Resource-level settings may override broader settings.
  • Multicloud resources may require appropriate onboarding.

Therefore:

Turning a Defender plan on is not the same thing as proving that every intended workload is protected.

The Coverage workbook is designed to help validate the actual deployment state.


24. Monitoring Workload Protection

Defender for Cloud provides workload protection insights and security alerts.

The Workload protections area can show the status of advanced protection for workloads such as:

  • Virtual machines
  • SQL databases
  • Containers
  • Web applications
  • Other supported workload types

Security alerts can provide:

  • Affected resource
  • Threat information
  • Suggested remediation
  • Additional investigation information
  • In some cases, automated response options

This allows security teams to move from:

Protection configuration

to:

Threat detection and response


25. Important Licensing and Cost Considerations

Many workload protection plans are paid capabilities.

Before enabling a plan broadly, an organization should understand:

  • Which workloads will be protected
  • Which features will be enabled
  • Which resources are in scope
  • Whether the plan has multiple tiers
  • Whether optional features incur additional costs
  • Expected usage
  • How long the plan will remain enabled

For example, Defender for Storage includes configurable malware-scanning capabilities, and Defender for APIs has plan selection considerations based on API traffic.

Exam strategy

If a scenario asks for the best security configuration, do not automatically choose the least expensive option.

First satisfy the security requirement.

If the question specifically introduces cost as a constraint, then cost becomes part of the decision.


26. Common SC-500 Workload Protection Scenarios

Scenario 1 — Virtual machines

Requirement: Detect vulnerabilities and protect Azure VMs.

Solution: Defender for Servers.


Scenario 2 — Kubernetes

Requirement: Detect container vulnerabilities and runtime threats in AKS.

Solution: Defender for Containers.


Scenario 3 — Malicious file uploads

Requirement: Detect malicious files uploaded to Blob Storage.

Solution: Defender for Storage with malware scanning.


Scenario 4 — Azure SQL

Requirement: Detect suspicious activity against Azure SQL databases.

Solution: Defender for Databases with Azure SQL Database protection enabled.


Scenario 5 — SQL Server on VM

Requirement: Protect SQL Server running on an Azure VM.

Solution: Configure the SQL Servers on Machines capability within Defender for Databases.


Scenario 6 — API attacks

Requirement: Discover and detect threats against APIs hosted through Azure API Management.

Solution: Defender for APIs.


Scenario 7 — AI threats

Requirement: Detect runtime threats targeting generative AI services.

Solution: Defender for AI Services.


Scenario 8 — Suspicious Azure management activity

Requirement: Detect suspicious Azure resource-management operations.

Solution: Defender for Resource Manager.


27. Common Mistakes to Avoid

Mistake 1: Confusing CSPM with workload protection

CSPM identifies posture weaknesses.

CWPP provides workload-specific protection.


Mistake 2: Enabling the wrong plan

A plan should be selected based on the workload being protected.


Mistake 3: Assuming one Defender plan protects everything

Defender for Cloud uses specialized plans for different workload categories.


Mistake 4: Assuming “On” means every feature is enabled

Some plans contain configurable components and tiers.


Mistake 5: Ignoring plan tiers

Defender for Servers has P1 and P2.

If a scenario requires a Plan 2 capability, enabling P1 is insufficient.


Mistake 6: Forgetting multicloud scope

Some Defender plans support AWS and GCP while others are Azure-only.


Mistake 7: Ignoring API traffic

Defender for APIs plan selection should take API traffic volume into account.


Mistake 8: Forgetting Storage malware scanning

Enabling Defender for Storage and enabling/configuring malware scanning are related but distinct considerations.


Mistake 9: Failing to verify coverage

Always verify that intended workloads are actually protected.


Mistake 10: Treating recommendations as runtime protection

A security recommendation identifies a security weakness.

A workload protection plan provides additional protection against threats.

They complement one another.


28. SC-500 Exam Comparison Table

RequirementThink About
Improve overall cloud security postureCSPM
Improve Secure ScoreCSPM
Identify misconfigurationsCSPM
Protect Azure VMsDefender for Servers
Protect KubernetesDefender for Containers
Detect malicious files in StorageDefender for Storage
Protect Azure SQLDefender for Databases
Protect SQL Server on machinesDefender for Databases → SQL Servers on Machines
Protect App ServiceDefender for App Service
Protect APIsDefender for APIs
Protect Key VaultDefender for Key Vault
Protect generative AI servicesDefender for AI Services
Detect suspicious Azure management activityDefender for Resource Manager
Detect DNS threatsDefender for DNS
Apply configuration consistently at scaleAzure Policy
Verify plan/resource coverageCoverage workbook

29. Recommended Deployment Method

For an enterprise environment, a strong implementation approach is:

Step 1 — Inventory workloads

Identify:

  • VMs
  • Containers
  • Storage
  • Databases
  • APIs
  • App Services
  • Key Vaults
  • AI services
  • Other cloud workloads

Step 2 — Map workloads to Defender plans

Determine which workload protection plan applies to each workload.

Step 3 — Determine scope

Decide whether protection should apply at:

  • Management group
  • Subscription
  • Resource
  • Connected multicloud environment

Step 4 — Select appropriate tiers

For plans with multiple tiers, select the tier that satisfies the security requirement.

Step 5 — Configure plan-specific features

Examples include:

  • Server vulnerability assessment
  • Server agentless scanning
  • Storage malware scanning
  • Storage sensitive-data detection
  • Container runtime protection
  • Container registry scanning
  • API plan selection
  • AI threat protection

Step 6 — Automate deployment

Use Azure Policy where appropriate to establish consistent deployment at scale.

Step 7 — Verify coverage

Use Defender for Cloud’s Coverage workbook.

Step 8 — Monitor

Review:

  • Security alerts
  • Recommendations
  • Coverage
  • Workload protection status

Step 9 — Remediate

Address identified vulnerabilities and configuration gaps.


30. Key Takeaways

For the SC-500 exam, remember these principles:

  1. Defender for Cloud combines CSPM and workload protection capabilities.
  2. CWPP plans are workload-specific.
  3. Choose the Defender plan based on the workload that needs protection.
  4. Defender for Servers has Plan 1 and Plan 2.
  5. Plan 2 provides additional advanced server protection capabilities.
  6. Defender for Storage can provide malware scanning and sensitive-data threat detection.
  7. Defender for Databases protects supported database workloads.
  8. Defender for Containers protects Kubernetes environments.
  9. Defender for APIs protects APIs managed through Azure API Management.
  10. Defender for AI Services provides specialized protection for supported AI workloads.
  11. Not every Defender plan supports AWS and GCP.
  12. Azure Policy can help deploy Defender plans consistently at scale.
  13. Enabling a plan is not the same as verifying coverage.
  14. Use the Coverage workbook to validate deployment coverage.
  15. Always distinguish posture management from active workload protection.

The central exam concept is simple:

Identify the workload → select the appropriate Defender plan → choose the required tier/features → deploy at the appropriate scope → verify coverage → monitor and remediate.


Practice Exam Questions

Question 1

An organization has several Azure virtual machines. The security team wants to detect vulnerabilities, integrate endpoint protection, and provide additional threat protection for the machines.

Which Microsoft Defender for Cloud plan should the organization enable?

A. Defender for Servers

B. Defender for Storage

C. Defender for APIs

D. Defender for Key Vault

Answer: A. Defender for Servers

Explanation: Defender for Servers is the workload protection plan designed for server and machine workloads. It provides capabilities such as vulnerability assessment and Defender for Endpoint integration. Defender for Storage protects storage accounts, Defender for APIs protects APIs, and Defender for Key Vault protects Key Vault resources.


Question 2

A security administrator needs to protect an AKS environment against container vulnerabilities and runtime threats.

Which Defender for Cloud plan should be configured?

A. Defender for App Service

B. Defender for Resource Manager

C. Defender for Servers

D. Defender for Containers

Answer: D. Defender for Containers

Explanation: Defender for Containers is designed to protect Kubernetes environments such as AKS. Depending on the configuration, it can provide vulnerability assessment, runtime threat protection, posture assessment, agentless scanning, registry assessment, and other Kubernetes security capabilities. Defender for Servers is intended primarily for machine workloads.


Question 3

A company uploads documents to Azure Blob Storage. The security team wants Defender for Cloud to identify malicious files when they are uploaded.

Which capability should be configured?

A. Defender for Storage malware scanning

B. Defender for Databases

C. Defender for Key Vault

D. Defender for APIs

Answer: A. Defender for Storage malware scanning

Explanation: Defender for Storage provides on-upload malware scanning for supported storage workloads. The capability is specifically intended to detect malicious files uploaded to storage. Defender for Key Vault, Databases, and APIs address different workload types.


Question 4

An organization enables Defender for Servers and needs a capability that is associated with Plan 2 rather than Plan 1.

Which plan should the organization select?

A. Foundational CSPM

B. Defender for Servers Plan 1

C. Defender CSPM

D. Defender for Servers Plan 2

Answer: D. Defender for Servers Plan 2

Explanation: Defender for Servers has Plan 1 and Plan 2. Plan 2 provides additional advanced capabilities, including agentless scanning. File integrity monitoring is also available as a Plan 2 capability, although it isn’t enabled by default.


Question 5

A company uses Azure API Management and wants to discover APIs, assess their security posture, prioritize API vulnerabilities, and detect active API threats.

Which Defender for Cloud plan should be used?

A. Defender for APIs

B. Defender for App Service

C. Defender for Containers

D. Defender for Resource Manager

Answer: A. Defender for APIs

Explanation: Defender for APIs provides discovery, security posture visibility, vulnerability prioritization, and runtime threat detection for APIs managed through Azure API Management. The APIs must be appropriately onboarded, and plan selection should account for API traffic requirements.


Question 6

An organization wants to apply Microsoft Defender for Cloud workload protection configurations consistently across a large number of Azure subscriptions.

Which service is most appropriate for enforcing configuration at scale?

A. Azure Bastion

B. Azure Policy

C. Azure Monitor

D. Azure DNS

Answer: B. Azure Policy

Explanation: Azure Policy can be used to enforce and deploy security configurations consistently across Azure resources and subscriptions. Microsoft provides built-in policy definitions and initiatives for configuring various Defender for Cloud plans, including Defender for Servers, Storage, Containers, APIs, AI Services, and others.


Question 7

A security engineer wants to verify which subscriptions and resources are actually covered by the Defender for Cloud plans that have been enabled.

Which capability should the engineer use?

A. Secure Score

B. Regulatory Compliance dashboard

C. Coverage workbook

D. Azure Service Health

Answer: C. Coverage workbook

Explanation: The Defender for Cloud Coverage workbook provides visibility into which Defender plans are enabled and the resulting coverage across subscriptions and resources. This is particularly important because simply enabling a plan does not necessarily mean that every intended workload has been successfully protected.


Question 8

A company is deploying a generative AI application and wants specialized Defender for Cloud protection that can identify threats targeting supported AI services.

Which plan should the security team consider?

A. Defender for DNS

B. Defender for Key Vault

C. Defender for Storage

D. Defender for AI Services

Answer: D. Defender for AI Services

Explanation: Defender for AI Services provides specialized threat protection for supported generative AI services and applications. Defender for Cloud’s AI protection capabilities can provide discovery, posture assessment, runtime threat detection, and investigation capabilities for AI workloads.


Question 9

An organization has an Azure SQL Database and wants to enable Defender for Cloud’s attack detection and threat-response capabilities for that database.

Which configuration should the administrator use?

A. Defender for Databases with Azure SQL Databases enabled

B. Defender for Servers Plan 2

C. Defender for Storage

D. Defender for Containers

Answer: A. Defender for Databases with Azure SQL Databases enabled

Explanation: Azure SQL Database protection is configured through the Defender for Databases plan. The administrator selects the Databases plan and enables the Azure SQL Databases resource type. Defender for Servers is intended for machine workloads, while Storage and Containers address different workload categories.


Question 10

An organization has connected its AWS environment to Microsoft Defender for Cloud. The security team wants to protect Windows and Linux EC2 instances against threats.

Which Defender for Cloud plan is the best fit?

A. Defender for Storage

B. Defender for Servers

C. Defender for APIs

D. Defender for AI Services

Answer: B. Defender for Servers

Explanation: Defender for Servers supports multicloud machine workloads, including supported AWS and GCP machines. AWS and GCP machines use the appropriate Defender for Cloud onboarding mechanisms, including Azure Arc for supported server scenarios. Azure-only plans such as Defender for Storage, APIs, and AI Services are not the appropriate choice for protecting EC2 machines.


Final SC-500 Exam Reminder

When you see a Defender for Cloud workload-protection question, first ask:

“What workload am I protecting?”

Then map it to the appropriate plan:

Servers → Defender for Servers

Containers/Kubernetes → Defender for Containers

Storage → Defender for Storage

Databases → Defender for Databases

App Service → Defender for App Service

APIs → Defender for APIs

Key Vault → Defender for Key Vault

AI Services → Defender for AI Services

Resource management → Defender for Resource Manager

DNS → Defender for DNS

Then determine whether the question requires a particular plan tier, feature, deployment scope, or configuration option.

Finally, remember to verify actual coverage rather than assuming that enabling the plan means the deployment is complete.

This topic is important for SC-500 because Microsoft is increasingly treating AI workloads as a first-class security workload, so I would expect questions to test not only the traditional Servers/Storage/Databases/Containers plans but also Defender for AI Services, Defender for APIs, plan-specific configuration, and coverage verification.


Go to the SC-500 Exam Prep Hub main page

Connect hybrid cloud and multicloud environments to Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP) (SC-500 Exam Prep)

This post is a part of the "SC-500: Implementing End-to-End Security Controls for Cloud and AI Workloads" Exam Prep Hub.
This topic falls under these sections:
Manage and monitor security posture (20–25%)
   --> Manage security posture by using Defender for Cloud
      --> Connect hybrid cloud and multicloud environments to Defender for Cloud, including Amazon Web Services (AWS) and Google Cloud Platform (GCP)


Note that there are 10 practice questions (with answers) at the end of each section to help you solidify your knowledge of the material. Also, there are 4 practice tests with 30 questions each available from the hub's main page below the exam topics section.

Introduction

Modern organizations rarely operate entirely within a single cloud provider.

An enterprise might have:

  • Azure virtual machines
  • Amazon EC2 instances
  • Google Compute Engine virtual machines
  • Amazon EKS clusters
  • Google Kubernetes Engine (GKE) clusters
  • On-premises servers
  • SQL Server databases running outside Azure
  • Applications distributed across multiple cloud platforms

Managing security independently in each environment can create visibility gaps and inconsistent security controls.

Microsoft Defender for Cloud helps address this problem by providing a centralized security platform for Azure, AWS, GCP, on-premises, and other supported environments.

For the SC-500 exam, an especially important concept is that Defender for Cloud can extend both:

  • Cloud Security Posture Management (CSPM) capabilities to multicloud environments
  • Cloud Workload Protection Platform (CWPP) capabilities to supported multicloud workloads

These two capabilities use different mechanisms.

CSPM is primarily agentless, while many CWPP scenarios use Azure Arc to connect non-Azure workloads to Azure and enable additional protection capabilities.


1. What Does “Multicloud” Mean?

A multicloud environment uses services from more than one public cloud provider.

For example:

Azure

  • Azure Virtual Machines
  • Azure SQL
  • Azure Storage
  • Azure Kubernetes Service

AWS

  • EC2
  • S3
  • RDS
  • EKS

GCP

  • Compute Engine
  • Cloud Storage
  • Cloud SQL
  • GKE

An organization may intentionally use multiple providers because of:

  • Existing investments
  • Business acquisitions
  • Application requirements
  • Geographic considerations
  • Vendor strategy
  • Specialized cloud services
  • Regulatory requirements
  • Avoidance of excessive vendor dependency

From a security perspective, however, multicloud environments introduce complexity.

Security teams need to answer questions such as:

  • What resources exist?
  • Where are they located?
  • Which resources are exposed?
  • Which resources have vulnerabilities?
  • Which security standards apply?
  • Which workloads are protected?
  • Which accounts or projects have excessive permissions?
  • Where are active threats occurring?

Defender for Cloud can provide a unified view across these environments.


2. What Does “Hybrid Cloud” Mean?

A hybrid environment combines cloud resources with infrastructure outside the public cloud.

A typical example is:

On-premises data center

↓

Azure

↓

AWS

↓

GCP

Defender for Cloud can incorporate on-premises servers by using Azure Arc-enabled servers.

An Azure Arc-enabled server becomes an Azure resource, allowing Azure services and Defender for Cloud capabilities to interact with that server.

For the SC-500 exam, remember:

Azure Arc is the key technology for extending Azure management and many Defender for Cloud workload-protection capabilities to servers outside Azure.


3. The Defender for Cloud Multicloud Model

The multicloud architecture can be viewed conceptually as:

                       Microsoft Defender for Cloud
                                  |
             +--------------------+--------------------+
             |                    |                    |
           Azure                 AWS                  GCP
             |                    |                    |
        Azure resources      AWS resources        GCP resources
             |                    |                    |
             +--------------------+--------------------+
                                  |
                           Unified security
                                  |
              +-----------------+----------------+
              |                                  |
             CSPM                               CWPP
       Posture management                  Workload protection
       Primarily agentless                Often uses Azure Arc

The key idea is that Defender for Cloud doesn’t require an organization to move its workloads into Azure.

Instead, it connects to the other environments and provides security visibility and, where supported, workload protection.


4. CSPM vs. CWPP in Multicloud Environments

This is one of the most important concepts for SC-500.

Cloud Security Posture Management

CSPM focuses on answering:

“Is my environment configured securely?”

Examples include identifying:

  • Misconfigured resources
  • Excessive exposure
  • Weak security configurations
  • Compliance issues
  • Vulnerable configurations
  • Excessive permissions
  • Security recommendations

Defender for Cloud provides CSPM capabilities for AWS and GCP after their environments are connected.

Importantly, multicloud CSPM is agentless. The CSPM assessment does not require installing agents on every AWS or GCP resource.


5. Cloud Workload Protection Platform

CWPP focuses more directly on protecting workloads from threats.

Examples include:

  • Endpoint threat detection
  • Runtime protection
  • Vulnerability assessment
  • Malware detection
  • Container runtime protection
  • Database threat detection

For multicloud environments, many of these capabilities require additional components.

For example, Defender for Servers can use:

  • Azure Arc
  • Microsoft Defender for Endpoint
  • Vulnerability assessment capabilities
  • Agentless scanning

The exact dependencies vary by Defender plan.

Exam distinction

Remember:

CapabilityPrimary purposeMulticloud approach
CSPMIdentify security posture issuesPrimarily agentless
CWPPProtect workloads against threatsOften requires Azure Arc/agents/extensions
Azure ArcConnect/manage supported non-Azure resourcesAzure management plane
Defender plansAdd workload-specific protectionDepends on workload

6. Connecting AWS to Defender for Cloud

AWS accounts can be connected directly to Defender for Cloud through a native AWS connector.

The connection creates a security relationship between Microsoft Defender for Cloud and the AWS environment.

The high-level process is:

  1. Open Microsoft Defender for Cloud.
  2. Navigate to the environment settings.
  3. Select the option to connect an AWS account.
  4. Specify the AWS account and Azure subscription information.
  5. Select the Defender plans to enable.
  6. Configure the required AWS permissions.
  7. Deploy the required AWS resources.
  8. Complete the connector configuration.
  9. Validate connector health.
  10. Review coverage.

Microsoft’s current AWS onboarding process supports configuring the connector through the Azure portal and deploying the required AWS resources using AWS CloudFormation or Terraform, depending on the configuration.


7. AWS Authentication: Federated Authentication

A critical security feature is that Defender for Cloud does not require storing long-lived AWS credentials.

Instead, Defender for Cloud uses federated authentication.

The current AWS architecture uses:

  • Microsoft-managed Microsoft Entra application
  • OpenID Connect (OIDC)
  • AWS IAM roles
  • AWS Security Token Service (STS)
  • Short-lived credentials

The CloudFormation deployment establishes the required trust relationship.

Conceptually:

Microsoft Defender for Cloud
|
| Federated authentication
v
Microsoft Entra identity
|
| OIDC / web identity federation
v
AWS IAM Role
|
| Assume role
v
AWS Security Token Service
|
| Short-lived credentials
v
AWS Resources

The important security principle is:

Defender for Cloud obtains short-lived credentials through federation instead of requiring long-lived AWS access keys to be stored.

SC-500 exam tip

If an answer says:

“Store an AWS access key and secret key in Defender for Cloud.”

that should immediately raise a red flag.

The preferred architecture uses federated trust and temporary credentials.


8. AWS IAM Permissions

The AWS connector requires appropriate permissions to discover and protect AWS resources.

The permissions depend on the Defender plans that are enabled.

For example, the CSPM connector requires permissions to discover AWS resources.

Additional permissions may be required for:

  • Defender for Servers
  • Defender for Containers
  • Other workload protection capabilities
  • Agentless scanning
  • Azure Arc autoprovisioning

Defender for Cloud creates the required roles and permissions in AWS as part of connector configuration.


9. Default Access vs. Least-Privilege Access

When configuring an AWS connector, Defender for Cloud provides options for configuring access.

Two important concepts are:

Default access

Provides the permissions required for the selected Defender capabilities and allows Defender for Cloud to incorporate future capabilities.

Least-privilege access

Grants only the permissions currently required by the selected plans.

The trade-off is important.

If new capabilities require additional permissions later, the connector may need to be updated.

Microsoft documents that changes to Defender plans or plan options can require rerunning the appropriate deployment artifact, such as the CloudFormation template or Terraform configuration.

Exam concept

If a question emphasizes:

“Grant only the minimum permissions required.”

think:

Least-privilege access.

If the question emphasizes:

“Automatically include future Defender capabilities.”

think:

Default access.


10. Connecting GCP to Defender for Cloud

GCP projects and organizations can also be connected to Defender for Cloud.

The high-level workflow is similar to AWS:

  1. Open Defender for Cloud.
  2. Navigate to Environment settings.
  3. Select the GCP connection option.
  4. Select the Azure subscription.
  5. Specify the GCP project or organization.
  6. Configure the required GCP permissions.
  7. Deploy the required GCP configuration.
  8. Complete the connector configuration.
  9. Validate connector health.
  10. Review coverage.

The current GCP connector uses federated authentication, allowing Defender for Cloud to access GCP APIs without storing long-lived credentials.


11. GCP Authentication

The GCP authentication architecture is designed to establish trust between Defender for Cloud and GCP.

The goal is similar to AWS:

Provide Defender for Cloud with the permissions required to inspect and protect resources without relying on permanently stored cloud credentials.

This is an important Zero Trust-oriented principle.

The security solution should have:

  • Appropriate identity
  • Appropriate permissions
  • Appropriate scope
  • No unnecessary long-lived secrets

12. GCP IAM Permissions

The GCP connector creates the required roles and permissions based on the selected Defender plans.

For example, Defender CSPM requires permissions that allow Defender for Cloud to:

  • Discover projects
  • Inspect organizations
  • Inspect folders
  • Review resource configurations
  • Discover resources
  • Analyze IAM-related information
  • Discover supported AI platform resources

Additional permissions may be required for workload protection plans.

Important principle

The permissions required for a GCP connector are not necessarily the same as the permissions required for an AWS connector.

Each cloud provider has its own identity and authorization model.


13. AWS vs. GCP Connector Comparison

CharacteristicAWSGCP
Connected to Defender for CloudYesYes
CSPM supportYesYes
CWPP supportYesYes
AuthenticationFederatedFederated
Long-lived cloud credentials requiredNoNo
Connector creates cloud-side security configurationYesYes
Infrastructure deploymentCloudFormation/TerraformCloud Shell/Terraform
Servers can use Azure ArcYesYes
Containers/Kubernetes supportedEKSGKE
CSPM is primarily agentlessYesYes

The exact permissions and deployment artifacts differ between AWS and GCP.


14. Azure Arc and Multicloud Servers

Azure Arc is particularly important when protecting servers outside Azure.

For example:

AWS EC2
|
| Azure Arc
v
Azure
|
v
Microsoft Defender for Cloud

and:

GCP Compute Engine
|
| Azure Arc
v
Azure
|
v
Microsoft Defender for Cloud

The Azure Arc Connected Machine agent enables the non-Azure server to participate in Azure management.

Microsoft recommends onboarding AWS and GCP machines as Azure Arc-enabled VMs to obtain the full Defender for Servers functionality.


15. Azure Arc Does Not Mean the Workload Moves to Azure

This is an important conceptual distinction.

When an AWS EC2 instance is connected through Azure Arc:

The EC2 instance remains in AWS.

When a GCP Compute Engine VM is connected through Azure Arc:

The VM remains in GCP.

Azure Arc provides a management and identity bridge.

Conceptually:

AWS EC2
|
+---- remains in AWS
|
+---- Azure Arc connection
|
v
Defender for Cloud

The same principle applies to GCP.


16. Defender for Servers on AWS and GCP

Defender for Servers can protect:

  • AWS EC2 instances
  • GCP Compute Engine VMs
  • Azure VMs
  • Azure Arc-enabled servers
  • Supported on-premises machines

When AWS or GCP machines are connected through the multicloud connector, Azure Arc can be automatically deployed as part of the connection process.

The Azure Arc agent is important because it allows Defender for Cloud to:

  • Read host-level security information
  • Deploy required extensions
  • Connect the machine to Azure
  • Extend Defender capabilities to the machine

For AWS, the AWS Systems Manager (SSM) agent is used as part of the Azure Arc autoprovisioning process.

For GCP, the OS Config agent is used for the corresponding process.


17. Defender for Containers in AWS and GCP

Defender for Containers can extend protection to:

  • Amazon EKS
  • Google GKE
  • Other supported Kubernetes environments through Azure Arc-enabled Kubernetes

The multicloud container protection architecture can include:

  • Azure Arc agent
  • Defender sensor
  • Azure Policy for Kubernetes
  • Kubernetes audit logs
  • Agentless scanning

These components have different purposes.

Defender sensor

Provides runtime threat protection.

Azure Policy for Kubernetes

Helps assess and enforce Kubernetes security configuration.

Kubernetes audit logs

Provide activity information that Defender for Cloud can use for suspicious-activity detection and investigation.

Agentless capabilities

Provide visibility into Kubernetes inventory and other security information without requiring the same sensor-based deployment model.


18. EKS and GKE

For the SC-500 exam, remember this mapping:

CloudKubernetes serviceDefender for Containers
AzureAKSYes
AWSEKSYes
GCPGKEYes

This is an easy area for scenario-based questions.

If the question describes:

“A Kubernetes cluster running in AWS”

think:

Amazon EKS → Defender for Containers

If it describes:

“A Kubernetes cluster running in GCP”

think:

GKE → Defender for Containers


19. Defender for SQL in Multicloud Environments

Defender for SQL can provide threat protection for supported SQL workloads running on AWS and GCP.

For multicloud SQL Server scenarios, Azure Arc is important.

The SQL Server can be running on:

  • AWS EC2
  • GCP Compute Engine
  • Other supported machines

The machine is connected to Azure through Azure Arc, and the appropriate Defender for SQL configuration is enabled in the Azure subscription containing the Arc-enabled machine.


20. Multicloud Dependency Model

Different Defender plans have different dependencies.

A simplified view is:

Defender capabilityAzure ArcAgent/extensionAgentless capabilities
CSPMNoNoYes
Defender for ServersYesMDE/other componentsYes
Defender for ContainersYes for sensor-based capabilitiesDefender sensor/PolicyYes
Defender for SQL on MachinesYesSQL-related componentsLimited

The exact dependencies depend on the selected features and workload.

The key exam lesson is:

Do not assume that connecting an AWS or GCP account automatically installs every Defender component required for every workload.

Different plans have different requirements.


21. On-Premises Servers

Hybrid security also includes on-premises environments.

An on-premises server can be connected to Azure using Azure Arc-enabled servers.

Once connected:

  • The server becomes an Azure resource.
  • Azure services can interact with the server.
  • Defender for Cloud can assess and protect the server when the appropriate plans are enabled.

Microsoft recommends Azure Arc onboarding for on-premises servers when full Defender for Servers functionality is desired.


22. Why Azure Arc Is Important

Azure Arc creates a common management model.

Without Arc:

Azure → Azure security model
AWS → AWS security model
GCP → GCP security model
On-premises → Local management

With Arc:

                     Azure
                       |
             Microsoft Defender for Cloud
                       |
       +---------------+---------------+
       |               |               |
    Azure            AWS             GCP
                       |               |
                    Arc               Arc
                       |               |
                    Servers           Servers

This makes it easier to apply centralized security management.


23. Connecting an AWS Account: Conceptual Process

The exact portal experience can change, but the conceptual process is important for the exam.

Step 1 — Prepare Azure

Ensure Defender for Cloud is available in the Azure subscription.

Step 2 — Prepare AWS

Ensure the AWS account can deploy the required IAM roles and resources.

Step 3 — Create the connector

Create the AWS security connector in Defender for Cloud.

Step 4 — Select Defender plans

Select the plans required for the AWS environment.

For example:

  • Defender CSPM
  • Defender for Servers
  • Defender for Containers
  • Defender for SQL

Step 5 — Configure AWS access

Choose the appropriate access model and deploy the required CloudFormation or Terraform configuration.

Step 6 — Complete federation

The AWS-side IAM roles establish the trust relationship.

Step 7 — Validate

Confirm connector health.

Step 8 — Verify coverage

Use Defender for Cloud coverage information to confirm that the expected workloads are being protected.


24. Connecting a GCP Project: Conceptual Process

The process is similar.

Step 1 — Prepare Azure

Ensure Defender for Cloud is available.

Step 2 — Prepare GCP

Ensure the required permissions are available.

Step 3 — Create the GCP connector

Create the connector in Defender for Cloud.

Step 4 — Select Defender plans

Select the appropriate protection capabilities.

Step 5 — Configure GCP access

Deploy the required GCP configuration using the supported deployment method.

Step 6 — Establish federated authentication

The connector establishes the required trust relationship.

Step 7 — Validate connector health

Confirm that Defender for Cloud can communicate with GCP.

Step 8 — Verify coverage

Confirm that the expected GCP resources are visible and protected.


25. Connector Health

Connecting an AWS account or GCP project is not the end of the implementation.

Administrators should verify:

  • Connector status
  • Authentication
  • Permissions
  • Resource discovery
  • Defender plan configuration
  • Azure Arc status where applicable
  • Agent/extension deployment where applicable
  • Security recommendations
  • Security alerts
  • Workload coverage

Both the AWS and GCP connector experiences provide mechanisms to validate connector health and review coverage.


26. Coverage Verification

A very important operational step is determining:

“What is actually protected?”

Defender for Cloud provides coverage information through workbooks, including a Coverage workbook.

This can help administrators understand:

  • Which plans are enabled
  • Which subscriptions are involved
  • Which resources are covered
  • Where protection gaps exist

The GCP connector documentation specifically identifies the Coverage workbook as a way to understand current coverage.

Exam lesson

If the question asks:

“How can an administrator verify whether multicloud resources are covered?”

look for an answer involving:

Defender for Cloud coverage information/workbooks

rather than simply checking whether the connector exists.


27. Security Connector

When AWS or GCP environments are onboarded, Defender for Cloud creates a security connector as an Azure resource.

The connector represents the relationship between the external cloud environment and Defender for Cloud.

It also serves as an important scope for access management.

For example, organizations can assign access to workload owners based on the AWS account or GCP project represented by the security connector.


28. RBAC for Multicloud Security

Azure RBAC controls access to Defender for Cloud resources and security information.

For example, users may need access to:

  • Recommendations
  • Alerts
  • Security posture
  • Connector configuration
  • Workload information

Defender for Cloud includes roles such as:

  • Owner
  • Contributor
  • Reader
  • Security Reader

The Security Reader role provides read-only access to Defender for Cloud security information such as recommendations, alerts, policies, and security states.


29. Resource Group Scope

Multicloud security connectors are Azure resources.

Therefore, Azure RBAC can be used to control access to those connectors.

Permissions assigned at the resource-group level can also be inherited for multicloud recommendations and security alerts associated with the connectors.

This is useful in large organizations where:

  • Different teams own different cloud accounts.
  • Security operations is centralized.
  • Workload owners need visibility into only their environments.

30. Cloud Account vs. Subscription vs. Project

The terminology differs by cloud.

Azure

Subscription

AWS

Account

GCP

Project

A common SC-500 scenario might say:

“Connect an AWS environment.”

Think:

AWS account → Defender for Cloud connector → Azure subscription

Or:

“Connect a GCP environment.”

Think:

GCP project/organization → Defender for Cloud connector → Azure subscription

Understanding this terminology can prevent confusion on the exam.


31. AWS Organizations and GCP Organizations

Large cloud environments may contain many AWS accounts or GCP projects.

Organizations can design their connector strategy around the scale of their environment.

The goal is to avoid creating unnecessary management complexity while maintaining appropriate isolation and access control.

For particularly large AWS environments, Microsoft recommends considering how connectors are distributed across Azure subscriptions to manage portal scale effectively.


32. CloudTrail and Cloud Logging

Multicloud security can also incorporate activity information from the source cloud.

For AWS, Defender for Cloud supports AWS CloudTrail log ingestion in supported scenarios.

For GCP, GCP Cloud Logging ingestion is available in preview for certain enhanced identity and permission insights.

This is important because:

Resource configuration tells you what exists, while activity logs can provide additional context about what happened.


33. Agentless vs. Agent-Based Security

This distinction is extremely important.

Agentless

The security service obtains information without installing an agent on the workload.

Benefits can include:

  • Lower operational overhead
  • Faster deployment
  • Broad visibility
  • No workload agent lifecycle to maintain

Multicloud CSPM is primarily agentless.

Agent-based

An agent or extension runs on or alongside the workload.

This may provide:

  • Runtime telemetry
  • Host-level information
  • Endpoint detection
  • Runtime threat detection
  • Configuration enforcement

For example, Defender for Servers can use the Azure Arc agent and Defender for Endpoint capabilities.


34. Why CSPM Doesn’t Require Azure Arc

Suppose an organization connects an AWS account to Defender for Cloud.

The security team wants only:

“Identify AWS resources with security misconfigurations.”

Azure Arc isn’t required for the core CSPM assessment.

Why?

Because CSPM can assess the AWS environment through the multicloud connector using agentless techniques.

However, if the organization wants deeper workload protection for EC2 machines, Azure Arc may become important.

Exam distinction

Posture assessment:

Connector + agentless CSPM

Full server workload protection:

Connector + Azure Arc + appropriate Defender components


35. Defender for Servers and Azure Arc

For AWS and GCP machines, Azure Arc provides the bridge needed for full Defender for Servers functionality.

The current Microsoft guidance recommends Azure Arc onboarding because it enables the broader Defender for Servers feature set.

For example:

AWS EC2
↓
AWS SSM
↓
Azure Arc
↓
Defender for Cloud
↓
Defender for Servers
↓
Security monitoring/protection

A corresponding GCP model uses the GCP OS Config agent for Azure Arc autoprovisioning.


36. Networking Requirements

Multicloud protection requires appropriate outbound network connectivity.

For example, AWS and GCP machines that are being protected through Azure Arc need access to the endpoints required by the relevant Azure Arc and Defender components.

For GCP Defender for Servers deployments, required outbound HTTPS access includes endpoints such as:

  • osconfig.googleapis.com
  • compute.googleapis.com
  • containeranalysis.googleapis.com
  • agentonboarding.defenderforservers.security.azure.com
  • gbl.his.arc.azure.com

AWS deployments require access to appropriate AWS Systems Manager endpoints and Azure Arc endpoints.

Exam lesson

If an Arc-enabled machine cannot connect to Defender for Cloud, check:

  1. Agent status
  2. IAM permissions
  3. Outbound network connectivity
  4. Required endpoints
  5. Connector health

37. Data Residency Considerations

Multicloud security introduces data residency considerations.

Organizations should understand:

  • Where security data is collected
  • Where it is processed
  • Where it is stored
  • Which agents are involved
  • Which source-cloud logging services are involved

CSPM is primarily agentless, whereas CWPP capabilities can involve agents and extensions.

For Kubernetes, for example, source-cloud logging services such as Amazon CloudWatch or GCP Cloud Logging may be involved in audit-log collection.

Therefore, organizations with strict data residency requirements should evaluate the complete architecture rather than considering only the location of the protected workload.


38. Multicloud Security and Least Privilege

A strong multicloud architecture follows least privilege.

Defender for Cloud should receive only the permissions required for the selected capabilities.

At the same time, administrators should avoid granting so little access that required security functionality cannot operate.

The balance is:

Too many permissions
↓
Unnecessary risk
Too few permissions
↓
Incomplete security visibility/protection
Appropriate permissions
↓
Required security capabilities
+
Least privilege

This is an important security-design principle and an important SC-500 exam concept.


39. Common Multicloud Security Scenario

Consider an organization with:

  • 500 Azure VMs
  • 200 AWS EC2 instances
  • 100 GCP Compute Engine VMs
  • 10 AKS clusters
  • 5 EKS clusters
  • 4 GKE clusters

The organization wants centralized security.

A reasonable architecture is:

Azure

Use Defender for Cloud directly.

AWS

Connect the AWS account and use:

  • Defender CSPM for posture management
  • Defender for Servers for EC2 protection
  • Defender for Containers for EKS

GCP

Connect the GCP project and use:

  • Defender CSPM
  • Defender for Servers
  • Defender for Containers for GKE

On-premises

Use:

  • Azure Arc-enabled servers
  • Appropriate Defender plans

This provides a unified security-management model without moving workloads between clouds.


40. Common Mistakes to Avoid

Mistake 1: Thinking Azure Arc is required for CSPM

It isn’t.

Multicloud CSPM is primarily agentless.


Mistake 2: Thinking connecting AWS automatically protects every EC2 instance

The connector provides the connection and discovery foundation.

The appropriate Defender workload protection plan and required components must also be configured.


Mistake 3: Confusing an AWS account with an Azure subscription

AWS uses accounts.

Azure uses subscriptions.

The AWS account is connected to Defender for Cloud through an Azure subscription.


Mistake 4: Confusing a GCP project with an Azure subscription

GCP uses projects.

Azure uses subscriptions.

The GCP project is connected to Defender for Cloud through an Azure subscription.


Mistake 5: Assuming long-lived AWS credentials are required

Defender for Cloud uses federated authentication and short-lived credentials for AWS.


Mistake 6: Assuming every Defender plan is multicloud

Some Defender plans are designed for Azure-specific workloads.

Always verify plan support for the cloud and workload in question.


Mistake 7: Ignoring Azure Arc

For many CWPP scenarios involving AWS/GCP servers, Azure Arc is an important dependency.


Mistake 8: Forgetting connector permissions

A connector can exist but still have insufficient permissions to perform all configured security functions.


Mistake 9: Forgetting network requirements

Agents and extensions must be able to communicate with the required services.


Mistake 10: Not verifying coverage

A healthy connector does not necessarily mean every intended workload is protected.

Always validate coverage.


41. SC-500 Decision Matrix

ScenarioPrimary consideration
Assess AWS security postureAWS connector + CSPM
Assess GCP security postureGCP connector + CSPM
Protect AWS EC2AWS connector + Defender for Servers
Protect GCP Compute EngineGCP connector + Defender for Servers
Protect AWS EKSDefender for Containers
Protect GCP GKEDefender for Containers
Protect SQL Server on AWS/GCPDefender for SQL + Azure Arc
Connect on-premises serverAzure Arc
Avoid long-lived AWS credentialsFederated authentication
Deploy AWS connectorCloudFormation or Terraform
Deploy GCP connectorCloud Shell or Terraform
Verify connector statusConnector health
Verify resource coverageCoverage workbook
Minimize cloud permissionsLeast-privilege access
Centralize multicloud securityDefender for Cloud
Runtime protection for non-Azure serverCWPP + appropriate agents/Arc

42. A Complete Multicloud Deployment Workflow

A strong enterprise implementation can follow this sequence.

Step 1 — Identify environments

Inventory:

  • Azure subscriptions
  • AWS accounts
  • GCP projects
  • On-premises servers
  • Kubernetes clusters
  • Database workloads

Step 2 — Identify security requirements

Determine whether the organization needs:

  • CSPM
  • CWPP
  • Vulnerability assessment
  • Runtime protection
  • Container security
  • SQL protection
  • Compliance assessment
  • Identity analysis

Step 3 — Establish connectors

Connect:

  • AWS accounts
  • GCP projects
  • Other supported environments

Step 4 — Configure authentication

Use federated authentication rather than long-lived cloud credentials.

Step 5 — Configure permissions

Use the minimum permissions required for the selected plans.

Step 6 — Enable Defender plans

Select appropriate workload protection plans.

Step 7 — Deploy Azure Arc where required

For supported CWPP scenarios, onboard machines or Kubernetes clusters through Azure Arc.

Step 8 — Configure agents and extensions

Deploy required:

  • Defender for Endpoint components
  • Defender sensor
  • Azure Policy for Kubernetes
  • Other required extensions

Step 9 — Verify networking

Confirm required outbound connectivity.

Step 10 — Validate connectors

Check connector health.

Step 11 — Validate coverage

Review the Coverage workbook and resource inventory.

Step 12 — Monitor

Review:

  • Recommendations
  • Alerts
  • Security posture
  • Workload protection
  • Compliance

Step 13 — Remediate

Address security findings and protection gaps.


43. SC-500 Key Concepts to Memorize

The following concepts are especially likely to be useful when answering scenario-based questions.

Concept 1

CSPM = posture management

Concept 2

CWPP = workload protection

Concept 3

CSPM for AWS/GCP = primarily agentless

Concept 4

AWS/GCP server protection = Azure Arc is important

Concept 5

AWS authentication = federated authentication + short-lived credentials

Concept 6

AWS deployment = CloudFormation or Terraform

Concept 7

GCP deployment = Cloud Shell or Terraform

Concept 8

AWS EC2 = Defender for Servers

Concept 9

GCP Compute Engine = Defender for Servers

Concept 10

AWS EKS = Defender for Containers

Concept 11

GCP GKE = Defender for Containers

Concept 12

On-premises servers = Azure Arc

Concept 13

Connector ≠ complete workload protection

Concept 14

Coverage must be verified after onboarding


44. Key Takeaways

Microsoft Defender for Cloud provides a unified security model across Azure, AWS, GCP, and hybrid environments.

The most important SC-500 concepts are:

  1. AWS accounts and GCP projects can be connected directly to Defender for Cloud.
  2. Defender for Cloud provides CSPM capabilities across AWS and GCP.
  3. Multicloud CSPM is primarily agentless.
  4. CWPP provides deeper workload protection.
  5. Azure Arc is important for many non-Azure CWPP scenarios.
  6. AWS authentication uses federated trust and short-lived credentials.
  7. GCP also uses federated authentication for its connector.
  8. AWS connector deployment can use CloudFormation or Terraform.
  9. GCP connector deployment can use Cloud Shell or Terraform.
  10. Defender for Servers can protect supported AWS EC2 and GCP Compute Engine machines.
  11. Defender for Containers can protect supported EKS and GKE environments.
  12. Different Defender plans have different dependencies.
  13. Connector permissions must be sufficient for the enabled plans.
  14. Least-privilege access reduces unnecessary permissions.
  15. Azure Arc does not move a workload into Azure.
  16. Connecting an environment does not automatically mean every workload is protected.
  17. Connector health should be validated.
  18. Coverage should be verified after onboarding.
  19. Networking requirements must be satisfied for agents and extensions.
  20. The goal is unified security management without requiring workloads to migrate to Azure.

The most useful mental model for the exam is:

Connect → Authenticate → Authorize → Assess → Protect → Verify

Or, more specifically:

AWS/GCP connector → federated identity → appropriate permissions → CSPM → Azure Arc/CWPP where required → verify coverage


Practice Exam Questions

Question 1

A company has several AWS accounts and wants Microsoft Defender for Cloud to identify security misconfigurations and assess its AWS environment. The company does not want to install agents on its AWS resources.

What should the security engineer implement?

A. Azure Arc on every AWS resource

B. Defender for Servers Plan 2 on every EC2 instance

C. An AWS connector with Defender CSPM

D. Microsoft Defender for Endpoint on every AWS resource

Answer: C. An AWS connector with Defender CSPM

Explanation: Defender for Cloud provides CSPM capabilities for AWS through the AWS connector, and multicloud CSPM is primarily agentless. Azure Arc and endpoint agents are relevant to deeper workload-protection scenarios, but they aren’t required simply to perform the core CSPM assessment.


Question 2

A security engineer needs to protect EC2 instances in an AWS account using Microsoft Defender for Servers. The organization wants to take advantage of the full Defender for Servers functionality available for its multicloud machines.

Which technology should the engineer use to onboard the machines?

A. Azure Arc-enabled servers

B. Azure Bastion

C. Azure VPN Gateway

D. Microsoft Sentinel agents

Answer: A. Azure Arc-enabled servers

Explanation: Microsoft recommends onboarding AWS and GCP machines as Azure Arc-enabled machines to take full advantage of Defender for Servers. The multicloud connector can automatically onboard the Azure Arc agent as part of the connection process.


Question 3

An organization is connecting an AWS account to Defender for Cloud. The security team has a requirement that Defender for Cloud must not store long-lived AWS access credentials.

Which authentication mechanism should be used?

A. A permanent AWS access key stored in Azure Key Vault

B. Federated authentication using OIDC and short-lived AWS credentials

C. A shared IAM user account with a permanent password

D. An Azure Storage account containing AWS credentials

Answer: B. Federated authentication using OIDC and short-lived AWS credentials

Explanation: Defender for Cloud uses federated authentication when connecting to AWS. The architecture establishes a trust relationship involving Microsoft Entra ID, OIDC, AWS IAM roles, and AWS STS so that Defender for Cloud can obtain short-lived credentials rather than relying on long-lived secrets.


Question 4

A company has deployed several workloads in Google Cloud Platform. The security team wants Defender for Cloud to discover GCP resources and assess their security posture without deploying agents to each resource.

What should the security team configure?

A. Defender for Servers on every GCP VM

B. Azure Arc on every GCP resource

C. Microsoft Defender for Endpoint on every GCP resource

D. A GCP connector with the appropriate CSPM configuration

Answer: D. A GCP connector with the appropriate CSPM configuration

Explanation: Defender for Cloud can perform CSPM for GCP through the GCP connector using primarily agentless techniques. Azure Arc and workload agents become relevant when deeper workload protection is required.


Question 5

An organization has connected an AWS account to Defender for Cloud. The security team wants to protect Amazon EKS clusters against vulnerabilities and runtime threats.

Which Defender for Cloud capability should be enabled?

A. Defender for Containers

B. Defender for Storage

C. Defender for Key Vault

D. Defender for App Service

Answer: A. Defender for Containers

Explanation: Defender for Containers provides protection for supported Kubernetes environments, including Amazon EKS. Multicloud container protection can include Azure Arc, the Defender sensor, Azure Policy for Kubernetes, audit logs, and agentless capabilities depending on the selected configuration.


Question 6

An organization is onboarding a large AWS environment to Defender for Cloud. The security team wants the connector to grant only the permissions currently required by the selected Defender plans.

Which access model should the team select?

A. Default access

B. Owner access

C. Least-privilege access

D. Contributor access

Answer: C. Least-privilege access

Explanation: Least-privilege access grants Defender for Cloud only the permissions required for the currently selected capabilities. This reduces unnecessary permissions. One trade-off is that when new Defender capabilities or permissions are required, the deployment artifact may need to be updated and redeployed.


Question 7

An organization connects a GCP project to Defender for Cloud. It wants to protect GCP Compute Engine virtual machines using Defender for Servers.

Which combination is most appropriate for obtaining the full Defender for Servers functionality?

A. GCP connector only

B. GCP connector plus Azure Arc onboarding

C. Azure Bastion plus VPN Gateway

D. Microsoft Sentinel plus Azure Firewall

Answer: B. GCP connector plus Azure Arc onboarding

Explanation: Connecting the GCP project provides the multicloud integration, while Azure Arc provides the bridge needed for full Defender for Servers functionality on supported GCP machines. Microsoft recommends Azure Arc onboarding for GCP and AWS machines protected by Defender for Servers.


Question 8

A security administrator has successfully connected an AWS account to Defender for Cloud. The connector reports as healthy, but the administrator wants to determine whether the expected AWS resources are actually covered by the enabled Defender plans.

What should the administrator do?

A. Review the Coverage workbook

B. Create a new Azure Policy initiative

C. Enable Azure Bastion

D. Review Azure Service Health

Answer: A. Review the Coverage workbook

Explanation: Connector health confirms that the connection is functioning, but coverage verification determines whether the expected resources are actually protected by the appropriate plans. Defender for Cloud provides coverage workbooks for this purpose.


Question 9

A company has SQL Server databases running on virtual machines in AWS and GCP. The security team wants to use Microsoft Defender for Cloud to provide SQL threat protection for these workloads.

Which approach is appropriate?

A. Enable Defender for Storage on the AWS and GCP accounts

B. Enable Defender for APIs on the Azure subscription

C. Use Defender for SQL with Azure Arc-enabled machines

D. Deploy Azure Firewall to both cloud environments

Answer: C. Use Defender for SQL with Azure Arc-enabled machines

Explanation: Defender for SQL supports SQL workloads running on supported AWS and GCP machines. For multicloud SQL Server scenarios, Azure Arc connects the machines to Azure, allowing Defender for Cloud to provide the required SQL protection capabilities.


Question 10

A company wants to connect its GCP environment to Defender for Cloud. The security team wants to avoid storing long-lived GCP credentials for Defender for Cloud to use when accessing GCP APIs.

Which approach is most appropriate?

A. Create a permanent GCP service-account password

B. Store a GCP private key in an Azure VM

C. Create an AWS IAM role and use it for GCP authentication

D. Use the federated authentication architecture provided by the GCP connector

Answer: D. Use the federated authentication architecture provided by the GCP connector

Explanation: The Defender for Cloud GCP connector uses federated authentication to access GCP APIs without storing long-lived credentials. This provides a more secure cross-cloud trust model while allowing Defender for Cloud to perform the required discovery and security operations.


Final SC-500 Exam Reminder

When you encounter a hybrid or multicloud Defender for Cloud question, work through these questions in order:

1. What cloud is involved?

  • Azure
  • AWS
  • GCP
  • On-premises

2. What is being requested?

  • CSPM?
  • Compliance?
  • Vulnerability assessment?
  • Server protection?
  • Container protection?
  • SQL protection?

3. Is the capability agentless?

If the question is primarily about CSPM, think:

Connector + agentless assessment

4. Does the scenario require workload protection?

If so, think:

Appropriate Defender plan + required components

5. Is Azure Arc required?

For many non-Azure server and Kubernetes CWPP scenarios:

Yes, Azure Arc is an important dependency.

6. How is authentication performed?

For AWS and GCP:

Federated authentication

Avoid answers based on permanently stored cloud credentials.

7. What scope is involved?

Remember:

Azure = Subscription

AWS = Account

GCP = Project

8. How do you know it is working?

Look for:

Connector health + resource inventory + coverage verification

The core SC-500 mental model is:

Connect → Federate → Authorize → Assess → Protect → Verify

That sequence captures much of what Microsoft is testing in this portion of the exam.

This topic is important because the current SC-500 material treats multicloud security as more than simply “connecting AWS and GCP.” The exam can test the distinction between agentless CSPM and Arc-enabled CWPP, the authentication model, cloud-specific permissions, workload-specific Defender plans, and the process of verifying that protection is actually in place.


Go to the SC-500 Exam Prep Hub main page