Costa Rica
Last updated: 2026-07-27
Microsoft Defender is a family of security products, not a single switch. This repository explains where each product applies, what it protects, how it is onboarded, and where its alerts and recommendations appear.
Important
Start with What is Microsoft Defender?. It separates Defender for Cloud, Defender XDR, Microsoft Sentinel, and enforcement tools.
| I need to protect | Microsoft product or plan | Guide |
|---|---|---|
| Overall cloud posture | Foundational CSPM or Defender CSPM | CSPM |
| Windows and Linux servers | Defender for Servers | Servers |
| Kubernetes and container images | Defender for Containers | Containers |
| Blob, Files, and Data Lake storage | Defender for Storage | Storage |
| Azure App Service | Defender for App Service | App Service |
| SQL, Cosmos DB, and open-source databases | Defender for Databases | Databases |
| Azure Key Vault | Defender for Key Vault | Key Vault |
| Azure control-plane operations | Defender for Resource Manager | Resource Manager |
| APIs published in Azure API Management | Defender for APIs | APIs |
| Generative AI workloads | Defender for AI and AI security posture | AI workloads |
| Source code and pipelines | Defender for Cloud DevOps security | DevOps |
| AWS accounts | Defender for Cloud multicloud connector | AWS |
| Google Cloud projects | Defender for Cloud multicloud connector | GCP |
| On-premises or other-cloud workloads | Azure Arc plus Defender for Cloud | Hybrid and other clouds |
| PCs, servers, phones, and tablets | Defender for Endpoint | Endpoints |
| Exchange Online, Teams, SharePoint, and OneDrive | Defender for Office 365 | Microsoft 365 |
| Active Directory identities | Defender for Identity | Identity |
| SaaS applications and shadow IT | Defender for Cloud Apps | Cloud Apps |
| Vulnerability prioritization and remediation | Defender Vulnerability Management | Vulnerability Management |
| Small and medium business endpoints | Microsoft Defender for Business | Defender for Business |
| Operational technology and enterprise IoT | Microsoft Defender for IoT | IoT and OT |
| Entra user and sign-in risk | Microsoft Entra ID Protection | Entra ID Protection |
| Cross-domain incidents and hunting | Microsoft Defender XDR | Defender XDR |
| SIEM, SOAR, and long-term correlation | Microsoft Sentinel | Sentinel |
| Environment | Native connection | Typical protection path |
|---|---|---|
| Azure | Azure subscription | Enable Defender plans at management group or subscription scope |
| AWS | Defender for Cloud AWS connector | Connect accounts, deploy required AWS resources, and select plans |
| Google Cloud | Defender for Cloud GCP connector | Connect projects or organizations, grant roles, and select plans |
| On-premises and other clouds | Azure Arc | Arc-enable servers or Kubernetes, then enable the relevant plan |
| Microsoft 365 and SaaS | Defender portal connectors and licensing | Configure the relevant Defender XDR workload |
Note
Coverage and billing differ by plan, resource type, region, and cloud. Validate the current support matrix and pricing before production rollout.
- Inventory subscriptions, cloud accounts, tenants, workloads, and data owners.
- Confirm licensing, supported regions, permissions, data residency, and cost.
- Assign security contacts and centralize plan configuration at scale.
- Pilot one non-production scope and verify recommendations and test alerts.
- Connect incident workflows to Defender XDR, Sentinel, ITSM, or automation.
- Measure coverage, agent health, recommendation age, and response outcomes.
Use the deployment checklist and automation guide for rollout. Estimate and govern spend with the licensing and cost guide.