Defender for Cloud Plan Selection and Cost Checklist
Retrospective: this article looks back at events from November 2021, written in 2026 with the benefit of hindsight.
Defender for Cloud includes a free foundational tier and several paid plans. Use this checklist to decide which to enable and keep costs predictable.
Foundational (free)
- Enabled on all subscriptions.
- AWS and GCP connectors configured for posture assessment.
- Microsoft cloud security benchmark assigned.
Defender CSPM (paid)
Consider if you need:
- Attack path analysis and cloud security explorer.
- Agentless vulnerability and secrets scanning for VMs.
- Sensitive data discovery in storage.
- Governance rules with owners and due dates.
Workload protection plans
- Defender for Servers — Plan 1 (Defender for Endpoint integration) or Plan 2 (adds vulnerability assessment, JIT, file integrity monitoring and more). Required for most server protection.
- Defender for Storage — malware scanning and anomaly detection for storage accounts with sensitive data.
- Defender for Databases (SQL, open-source, Cosmos DB) — for production data stores.
- Defender for Containers — for AKS, EKS and GKE clusters.
- Defender for Key Vault and Resource Manager — low cost, high value for detecting control plane abuse.
- Defender for App Service and APIs — for internet-facing applications.
- Defender for AI services — if you run Azure AI workloads.
Cost controls
- Enable plans at subscription level only where workloads justify it.
- Use the Defender for Cloud cost estimation tools and Azure Cost Management alerts.
- Review per-resource pricing for Storage (transaction-based options).
- Revisit plan coverage quarterly.
Operations
- Alerts flow to Defender XDR and/or Sentinel.
- Someone owns recommendations and alerts for each subscription.