
For Microsoft Defender for Cloud, the thing I like best is continuous Cloud Security Posture Management + attack path analysis.
*Why it stands out:*
1. It finds the "blast radius" before attackers do -
Instead of just flagging "VM has open port 22", it maps how that misconfig + weak identity + exposed storage = full path to your crown jewels. The attack path visualization saves tons of time triaging.
2. One pane for AWS, Azure, GCP :
Most teams are multi-cloud now. Defender lets you see secure score, recommendations, and alerts across all 3 clouds without jumping dashboards. That’s rare.
3. DevSecOps shift-left :
The code-to-cloud integration means it scans IaC templates, containers, and CI/CD pipelines before you even deploy. Fixing a bad ARM/Bicep/Terraform template in PR is way cheaper than fixing it in prod.
4. Agentless scanning for VMs + databases -
No agents needed for vulnerability assessment on Azure VMs and SQL. Less overhead, less "please install this agent" friction with infra teams.
The secure score is gamified but actually useful too - it gives CISOs something to track quarter-over-quarter. Review collected by and hosted on G2.com.
Pricing can be confusing, and it’s easy to end up with surprise charges from “Defender plans” when you thought you were just using the free CSPM features. The alerts can also be very noisy at first, with lots of false positives and brute-force warnings until you spend time tuning the settings. Overall it feels Azure-first, with AWS and GCP getting weaker features compared with Azure. Finally, Secure Score doesn’t always reflect real risk in practice—teams can end up chasing the score instead of focusing on fixing the actual attack paths. Review collected by and hosted on G2.com.