AzureHow-To & HardeningRetrospectives

Exposure Management Quick-Start Checklist

By OnCloudSec Research Team · Published Oct 6, 2026 · 1 min read

Retrospective: this article looks back at events from November 2024, written in 2026 with the benefit of hindsight.

Use this checklist to start an exposure management program with Microsoft Defender tools.

Setup

  • Defender for Cloud with Defender CSPM enabled for production subscriptions and AWS/GCP connectors.
  • Defender for Endpoint, Defender for Identity and Defender for Office 365 data feeding Exposure Management.
  • Roles assigned for Exposure Management viewers and contributors.

Critical assets

  • Predefined critical asset classifications reviewed.
  • Custom critical assets added (crown-jewel databases, storage, apps).
  • Owners recorded for each critical asset.

Attack paths

  • Top 20 attack paths reviewed.
  • Choke points identified.
  • Remediation tickets created with owners and due dates.

Initiatives

  • Exposure initiatives reviewed (for example, ransomware, BEC, cloud security).
  • Two or three initiatives chosen as priorities for the quarter.

Integration

  • Findings linked to your ticketing system.
  • Vulnerability management and cloud posture processes use attack path context for prioritization.

Reporting

  • Monthly report: attack paths to critical assets, choke points fixed, initiative scores.
  • Quarterly review with leadership.

Ongoing

  • New critical assets added as they're created.
  • Exposure review included in change management for major projects.
exposure management quick start checklistIgnite 2024 Exposure Management2024

More on this story