"Single-Pane Cloud Protection with Great Value and Microsoft Support"
Defender for Cloud helps you protect your cloud estate using a single pane approach. All the metrics you need at a glance are right there in the UI. When we factor in that many devices and identities are protected using a license they already have (cost-effective), then it really is a no-brainer. There is good support from Microsoft for any queries we had when setting it up, and there are AI integrations and improvements that really enhance performance. In some but not all cases, especially ones where Windows/Microsoft is not the main OS or identity provider, you might need add-ons to get your device onboarded. It's helping us protect our cloud estate and ensuring that any integrations we undertake are safe.
I
Information Technology Support Engineer
"Seamless CNAPP Monitoring and Compliance Across Azure"
As a CNAPP, it allows us to continuously monitor and secure users and assets, and it's compliance-friendly as it works smoothly with all other Azure resources and objects. Like many other Microsoft solutions, it's sometimes difficult to account for scalable prices and costs. Risk management can be somewhat challenging to implement, and configuration seems complex. It's not unified with some interfaces, so we need to dive into other niche areas. Defender is helping us implement policies and secure our cloud resources. It binds perfectly for users and RBAC roles, and it also works as a general cloud anti-malware, preventing intrusions and logging every event that could pose a risk to our organization.
"Customized, Best-Practice Security Settings for Enterprise Needs"
Defender allows individual businesses to configure security settings that are not only aligned with industry best practices but also tailored to their enterprise needs, with specific tabs that fit their requirements. It's hard to identify any real downsides with Microsoft Defender. Our IT SecOps practices and overall experience with the admin interface have been consistently positive. The biggest ROI for us is the centralized console. Microsoft Defender has allowed our team to stop relying on 3 to 5 different vendors and trying to pull data from each one just to make informed decisions for employees and endpoints. Everything we need is right there in one place, with robust controls.
"Powerful Cloud Security Dashboard but Cost and Alert Tuning Need Work"
Microsoft Defender for Cloud excels at consolidating all security management into one dashboard. The automated security posture recommendations and native integration with Azure services save us considerable time on manual auditing. Threat protection and continuous compliance assessment across our multi-cloud infrastructure give our team full confidence in our cloud posture. The main downside is the cost tiering for advanced features, which escalates quickly with increasing multi-cloud workloads. Navigating security plans through the UI can feel fragmented, and it takes some initial tuning to manage alert fatigue. If licensing were simplified and default alert thresholds were better refined, the overall experience would improve. Microsoft Defender for Cloud addresses the challenge of maintaining consistent security posture and compliance across cloud workloads. Automated risk prioritization and actionable remediation steps enable our team to fix vulnerabilities before they become critical threats. This proactive monitoring has improved our auditing workflows and overall system resilience without placing an undue burden on our technical team.
"Unified Security Dashboard with Strong XDR and Secure Score"
It offers a single dashboard to oversee security recommendations, compliance status, vulnerabilities, and threats across the entire environment. The secure score is also a useful feature that aids in remediating risks and improving our score. The XDR feature is very powerful when integrated with Microsoft Sentinel. I don't have major dislikes about Microsoft Defender, but there are a few points to highlight. Some features require an additional subscription and should be included in the Business Premium Plan. Also, I've noticed that multi-cloud capabilities are not as seamless as native Azure integrations. For our organization, the biggest benefit is centralized visibility. Instead of manually reviewing multiple systems and cloud services, Defender for Cloud provides a single dashboard that highlights security posture, compliance status, vulnerabilities, and active threats.
"Centralized, Real-Time Cloud Security with Actionable Recommendations"
What I appreciate most about Microsoft Defender for Cloud is its ability to centralize security monitoring across various cloud environments. It continuously assesses security risks, provides clear and actionable recommendations, and helps detect threats in real time. Its integration with Microsoft Azure and other cloud services also streamlines security management, making the overall process much more efficient. One downside is that the platform can be complex for new users due to the sheer number of security features and configuration options to navigate. Some advanced capabilities can also increase costs, and understanding all the alerts and recommendations takes time and has a learning curve. Microsoft Defender for Cloud assists me in managing and securing cloud resources across complex environments. It simplifies identifying vulnerabilities, monitoring compliance, detecting threats, and receiving recommendations that enhance my overall security posture. For me, this leads to reduced security risk, better visibility into my cloud infrastructure, and greater confidence that my applications and data are protected against cyber threats.
"Multi-Cloud Security Alerts and Compliance Audits Unified in One Dashboard"
The best part is definitely the multi-cloud support. It lets you view all security alerts for Azure, AWS, and GCP in a single dashboard. This saves a lot of time because you don't have to switch between different consoles to check if everything is secure. Also, the regulatory compliance dashboard is extremely useful for audits. It shows exactly where you have gaps and offers clear recommendations to address them quickly. The biggest issue is definitely the cost; it can escalate quickly when you enable advanced protection features for multiple environments. If you don't monitor it, the monthly bill can be a nasty surprise. Another issue is that the alerts can be overwhelming at times. There are many false positives, which becomes annoying because you spend time investigating things that aren't real threats. Also, the UI can feel slow or cluttered when navigating through deep policy settings. The main problem it solves is the lack of visibility across different cloud platforms. Before using it, keeping track of security posture across AWS and Azure was a huge headache because everything was scattered. Now, it centralizes all security recommendations and compliance checks, which addresses the issue of 'alert fatigue' and missed vulnerabilities. The benefit for me is mostly peace of mind and time savings. It automatically scans for misconfigurations, so we can fix security gaps before they become actual problems. This is especially helpful during audits because compliance reports are already generated, so we don't have to scramble for evidence.
I
IBM IIS Server Upgrade – Bank Mandiri
"Effortless Azure Integration with Strong Real-Time Threat Detection"
The smooth integration with the Azure ecosystem and native Microsoft tools is a significant advantage. It provides solid real-time threat detection and advanced protection for workloads like EKS/AKS containers, VMs, and databases without requiring complicated agent installations. The security alerts are very detailed and help our team respond swiftly to incidents. Although it supports AWS and GCP, the integration and feature parity are not as smooth or comprehensive as with native Azure resources. Setting up connectors can sometimes be awkward, and navigating the sub-menus within Microsoft Purview or the wider security center can feel overwhelming due to frequent UI layout changes. The primary problem it solves is fragmented visibility. Managing separate security tools for different cloud infrastructures can lead to blind spots. Defender for Cloud consolidates our security posture into a single pane of glass. The benefit is a streamlined workflow for our security team, enabling us to detect and remediate vulnerabilities much faster.
I
Information Technology Specialist
"Comprehensive Security Visibility and Robust Threat Protection Across Hybrid and Multi-Cloud"
The thing I value most about Microsoft Defender for Cloud is that it unifies security visibility, recommendations, and threat protection into a single solution. It enables me to quickly grasp the security status of servers, cloud resources, and workloads without juggling multiple tools. The straightforward recommendations, ongoing monitoring, and alerts make it simpler to spot risks and address them before they escalate. I also like that it works across hybrid and multi-cloud setups, which is highly beneficial for organizations managing both on-premises and cloud infrastructure. On the downside, the initial setup and configuration can feel overwhelming, especially for those new to cloud security. Some recommendations and alerts may also require deeper investigation to figure out their true priority, which can be time-consuming. The pricing for advanced features can be tricky to predict as the environment scales. However, once properly configured and managed, the platform delivers strong security visibility and valuable protection. Microsoft Defender for Cloud is helping us address the challenge of maintaining consistent security across cloud and hybrid environments. It continuously monitors servers, applications, and cloud resources, identifies vulnerabilities, and provides clear recommendations to reduce risk. This improves our visibility, speeds up threat response, and cuts down on manual security checks. It also enhances compliance and gives the team greater confidence that critical workloads are protected through a single, centralized security platform.
C
Chairman of the foundation
"Attack Path Analysis Turns Cloud Risk Into Actionable Steps"
It's more than just a scanner—it functions as a control plane linking posture findings to actual fixes, and it's become really effective at that. Several aspects really impress me: Attack path analysis. This capability transformed how I run client discussions. Instead of giving someone a list of 400 'high severity' issues, I can display a visual graph: 'this exposed VM connects to this database with this over-permissioned identity, and here's the three-hop route an attacker could take.' It changes vague risk into a narrative that leadership can grasp, and it promotes prioritization rather than the usual reactive approach. Merging CSPM and CWPP into one platform. Before this consolidation, I was manually combining posture data from one tool and runtime threat detection from another for each client. Now I can view recommendations and live threat alerts in the same console, often linked to the same resource. That correlation—'this resource is misconfigured and also showing suspicious activity right now'—is where the real value emerges. Multi-cloud without a separate product. Being able to connect an AWS account and assess it against the same posture framework as an Azure subscription, all in the same portal, still seems like a major advantage. Many clients end up with hybrid environments unintentionally (like a dev team spinning up shadow IT AWS accounts), and having a single pane to identify that is very valuable. Native reporting. I've noted this before, but it deserves its own mention: creating a CNAPP Executive Summary report within the product and exporting it for a board deck—instead of pulling raw data into Power BI every quarter—has saved me hours per client. If I had to choose just one standout, it's the attack path graph. It converts 'here's a wall of alerts' into 'here's what truly matters and why,' which is essentially the core of a security consultant's job. The problem of noisy recommendations never completely disappears. Even with the move to individual, per-finding recommendations, the practical result for many organizations is more line items, not fewer. Grouped recommendations were easier to review at a glance; now I'm explaining to a client why they have 40 nearly identical 'update this package' entries instead of one grouped item. Granularity is great for engineers doing the actual remediation, but it's a tougher experience for anyone trying to get a quick posture overview. Licensing and plan boundaries are genuinely confusing. Walking someone through which Defender plan covers which capability—and which sub-features are metered separately (like per-resource billing on Defender for Open-Source Relational Databases)—takes up significant time in every engagement. It's not that the pricing is unreasonable; it's that it remains unclear until you're deep into the Azure pricing calculator. The pace of change is exhausting to keep up with. New GA features, new deprecations, new permission requests (like the GitHub connector's new artifact_metadata:write scope), and new default-behavior changes all come roughly monthly. That's good for the product, but tough on a consultant who has to read every release note or risk a client asking, 'Why did this alert disappear?' and not having an answer. No one has time to be a full-time Defender for Cloud news-tracker. Defaults also quietly shift under you. Foundational CSPM moving to opt-in for new subscriptions this October is the current example—sensible from Microsoft's cost perspective, but it means immature organizations that relied on 'it just works out of the box' will lose baseline visibility without realizing it. I've seen this pattern before with other default changes, and it always turns into a wave of 'Wait, why isn't this showing up anymore?' support tickets. Cross-cloud parity isn't quite there yet. AWS and GCP support have improved significantly, but the depth of coverage—especially for workload protection, not just posture—still lags what you get natively in Azure. If a client is AWS-heavy with just a toe in Azure, I'm upfront that this won't feel as first-class as it does for an Azure-native shop. There's also alert fatigue on the identity/OAuth side. As Defender for Cloud Apps absorbs more governance surface (AI agent protection, unused app insights, etc.), the volume of identity-related findings has grown quickly. It's good coverage, but without dedicated headcount to triage it, many clients just let it pile up—which defeats the purpose. None of this is a dealbreaker—I still recommend it to nearly every Azure client—but it's not a 'set it and forget it' tool. Anyone selling it to leadership as one is setting expectations wrong. The problems it's solving: 1. Fragmented visibility across cloud sprawl. Before a tool like this, answering 'what's our security posture?' meant pulling data from five different places—Azure Policy, native AWS Security Hub, some Kubernetes dashboard, and even manual spreadsheets. Defender for Cloud brings that into a single view of resources, misconfigurations, and identities across Azure/AWS/GCP. That's the foundational issue: you can't secure what you can't see. 2. The alert-to-action gap. Traditional security tooling is great at generating alerts and terrible at telling you which ones actually matter. Attack path analysis and exposure-based prioritization directly tackle alert fatigue by linking findings to real exploitability—whether an exposed resource is reachable and whether it leads anywhere valuable. 3. Compliance as an ongoing state instead of a point-in-time audit. Frameworks like ISO, NIST, and CIS benchmarks used to mean a consultant doing a manual audit once or twice a year. The built-in regulatory compliance dashboards shift that into a continuously updated posture, which changes the cadence of how compliance work gets done. 4. The DevSecOps handoff problem. The GitHub connector and the artifact attestation work address a real gap: security findings used to live entirely in ops-land, disconnected from the developers who actually write the vulnerable code. Pushing findings back into the CI/CD pipeline closes that loop. Benefits: 1. It shortens my time-to-value on every new engagement. When I onboard a new client, I'm not building a bespoke inventory-and-risk process from scratch. I plug them in, wait for the initial scan, and I have a defensible baseline in days instead of weeks. That's billable time I'm not burning on plumbing. 2. It gives me a credible artifact for client conversations. Secure Score and the attack path graphs aren't perfect, but they're legible to non-technical stakeholders. I spend less time translating technical risk into business risk because the tool does part of that translation for me. 3. It makes my recommendations more defensible. When I tell a client, 'Fix this first,' I can point to Microsoft's own risk-prioritization logic backing that call, rather than it being just 'my opinion as a consultant.' That matters when you're pushing back against a dev team that doesn't want to reprioritize their sprint. 4. The native reporting has quietly become part of my deliverable. I used to build custom PowerBI decks for quarterly reviews; now a meaningful chunk of that is generated in-portal and exportable to PDF. That's real time back in my week that I can spend on remediation work instead of report formatting. The honest caveat: it solves the visibility and prioritization problems well. It doesn't solve the organizational problem. A client still needs a human with the authority to act on what it surfaces. I've seen plenty of tenants with beautiful Secure Scores and dashboards that nobody ever looks at because there's no clear owner. The tool gives me leverage; it doesn't replace the part of the job where I have to convince a room full of people to care.