Adrie B.
AB
Chairman of the foundation
Small-Business (50 or fewer emp.)
"Attack Path Analysis That Makes Cloud Risk Actionable"
4.5/5
What do you like best about Microsoft Defender for Cloud?

It’s not just a scanner—it’s a control plane that connects posture findings to real remediation, and it’s become genuinely strong at doing that.

A few things that stand out for me:

Attack path analysis. This is the feature that changed how I run client conversations. Instead of handing someone a spreadsheet with 400 “high severity” findings, I can show an actual graph: “this exposed VM connects to this database with this over-permissioned identity, and here’s the three-hop path an attacker would take.” It turns abstract risk into a story leadership can actually follow, and it pushes prioritization instead of the usual whack-a-mole.

Unifying CSPM and CWPP in one place. Before this was consolidated, I was stitching together posture data from one tool and runtime threat detection from another for every client. Now I can see recommendations and active threat alerts in the same console, often tied to the same resource. That correlation—“this resource is misconfigured and is also showing suspicious activity right now”—is where the real value shows up.

Multi-cloud without needing a separate product. Being able to onboard an AWS account and evaluate it against the same posture framework as an Azure subscription, all in the same portal, still feels like a genuine win. A lot of clients end up with hybrid environments almost by accident (for example, shadow IT AWS accounts spun up by a dev team), and having one pane of glass to catch that is worth a lot.

Native reporting. I’ve mentioned this earlier, but it deserves its own callout: being able to build a CNAPP Executive Summary report inside the product and export it for a board deck—rather than exporting raw data into Power BI every quarter—has saved me hours per client.

If I had to pick just one highlight, though, it’s the attack path graph. It’s what turns “here’s a wall of alerts” into “here’s what actually matters and why,” and that’s basically the whole job of a security consultant. Review collected by and hosted on G2.com.

What do you dislike about Microsoft Defender for Cloud?

The recommendation-noise problem never fully goes away. Even with the shift to individual, per-finding recommendations, the practical effect for a lot of shops is more line items, not fewer. Grouped recommendations were easier to triage at a glance; now I’m explaining to a client why they have 40 near-identical “update this package” entries instead of one grouped item. Granularity is great for engineers doing the actual remediation, but it’s a rougher experience for anyone trying to get a quick posture read.

Licensing and plan boundaries are genuinely confusing. Walking someone through which Defender plan covers which capability—and which sub-features are metered separately (looking at you, per-resource billing on things like Defender for Open-Source Relational Databases)—eats up real time in every engagement. It’s not that the pricing is unreasonable; it’s that it stays opaque until you’re already three tabs deep in the Azure pricing calculator.

The pace of change is exhausting to keep up with. New GA features, new deprecations, new permission requests (like the GitHub connector’s new artifact_metadata:write scope), and new default-behavior changes all land more or less monthly. That’s good for the product, but rough on a consultant who has to read every release note or risk a client asking, “Why did this alert disappear?” and not having an answer. Nobody has time to be a full-time Defender for Cloud news-tracker.

Defaults also quietly shift under you. Foundational CSPM moving to opt-in for new subscriptions this October is the current example—sensible from Microsoft’s cost perspective, but it means immature orgs that relied on “it just works out of the box” are going to lose baseline visibility without realizing it. I’ve seen this pattern before with other default changes, and it always turns into a wave of “Wait, why isn’t this showing up anymore?” support tickets.

Cross-cloud parity isn’t quite there yet. AWS and GCP support has improved a lot, but the depth of coverage—especially on workload protection, not just posture—still lags what you get natively in Azure. If a client is AWS-heavy with just a toe in Azure, I’m upfront that this won’t feel as first-class as it does for an Azure-native shop.

There’s also alert fatigue on the identity/OAuth side. As Defender for Cloud Apps keeps absorbing more governance surface (AI agent protection, unused app insights, etc.), the volume of identity-related findings has grown fast. It’s good coverage, but without dedicated headcount to triage it, a lot of clients just let it pile up—which defeats the purpose.

None of this is a dealbreaker—I still recommend it to nearly every Azure client—but it’s not a “set it and forget it” tool. Anyone selling it to leadership as one is setting expectations wrong. Review collected by and hosted on G2.com.

See what 423 reviewers think of Microsoft Defender for Cloud

4.4 out of 5 · Verified reviews from real users

Read all reviews