Cloud Workload Protection

Defender for Cloud & Defender for Containers & Defender for Servers — Product Overview

Microsoft Defender for Cloud is Microsoft's cloud-native application protection platform, giving organizations visibility into their security posture and protection for their workloads across Azure, other clouds, and on-premises environments. Defender for Servers and Defender for Containers are two of the workload-specific protection plans available within Defender for Cloud, purpose-built for two of the most common workload types. Below is an overview of what each offers and the value it delivers.


Microsoft Defender for Cloud

Designed for: Every organization that wants ongoing visibility into its cloud security posture, across Azure, other cloud providers, and on-premises infrastructure.

What's Included

  • Foundational cloud security posture management (CSPM), included at no cost, providing baseline visibility into misconfigurations and security recommendations
  • Advanced CSPM capabilities, including attack path analysis, an intelligent security graph, and agentless vulnerability scanning
  • DevOps security, helping development teams identify and fix misconfigurations earlier, before code reaches production
  • A unified view across Azure, AWS, Google Cloud, and on-premises resources connected through Azure Arc
  • A library of workload-specific protection plans that can be enabled individually based on what an organization needs to protect

Why It Matters for Your Business

Defender for Cloud gives an organization a single, central view of its security posture, regardless of where its infrastructure actually runs. Because foundational visibility is included at no cost, every organization has a baseline understanding of its security posture the moment it starts using Azure. Attack path analysis is particularly valuable for security teams, since it doesn't just list individual misconfigurations — it shows how several smaller issues could be chained together by an attacker to reach a critical resource, helping teams prioritize the fixes that matter most rather than treating every recommendation as equally urgent.


Microsoft Defender for Servers

Designed for: Organizations that want active threat protection for their virtual machines and physical servers, whether in Azure, another cloud, or on-premises.

What's Included

  • Threat detection and behavioral analytics for virtual machines and servers
  • Two protection tiers: a foundational plan focused on core threat detection, and an advanced plan adding endpoint detection and response, vulnerability management, and additional security controls
  • Coverage extending to on-premises and other-cloud servers connected through Azure Arc
  • Integration with Microsoft Defender for Endpoint for unified detection and response

Why It Matters for Your Business

Defender for Servers extends active threat protection to the workloads running an organization's core applications and databases, not just the endpoints its employees use day to day. Because coverage extends to servers outside of Azure through Azure Arc, an organization doesn't need every server to be hosted in Azure to benefit from the same consistent protection and visibility — a meaningful advantage for organizations with a mixed or hybrid infrastructure footprint.


Microsoft Defender for Containers

Designed for: Organizations running containerized applications on Kubernetes, whether in Azure, another cloud, or on-premises.

What's Included

  • Kubernetes-native deployment and protection, purpose-built for containerized environments
  • Threat detection with Kubernetes-aware behavioral analytics and anomaly detection
  • Vulnerability scanning for container images, both in registries and at runtime
  • Runtime visibility into vulnerabilities actually in use, helping prioritize which issues pose real risk
  • Support across Azure Kubernetes Service, and Kubernetes clusters running in other clouds or on-premises

Why It Matters for Your Business

Containers introduce a different set of security challenges than traditional servers — they're created and destroyed constantly, often built from images pulled from external sources, and can be harder to monitor with conventional tools. Defender for Containers is purpose-built to understand this environment, applying Kubernetes-specific context to threat detection rather than treating containers like traditional servers. Runtime vulnerability visibility is especially valuable, since it helps security teams focus on the vulnerabilities that are actually running in production, rather than trying to remediate every vulnerability found in every image regardless of whether it's ever deployed.

Please Note

Microsoft Defender for Cloud, Servers, and Containers are billed based on actual resource usage — such as the number of servers protected or the compute capacity of a Kubernetes environment — rather than a fixed license per user. Because of this, actual cost depends heavily on the size and shape of an organization's specific environment. Our team is happy to provide guidance tailored to your infrastructure.


Summary

  • Defender for Cloud — unified security posture visibility across Azure, other clouds, and on-premises environments, with foundational capabilities included at no cost.
  • Defender for Servers — active threat protection for virtual machines and physical servers.
  • Defender for Containers — Kubernetes-native protection for containerized applications and workloads.

Defender for Servers and Defender for Containers are two of several workload-specific protection plans available within Defender for Cloud, allowing an organization to build coverage around the specific types of workloads it actually runs.


Have Questions? We're Here to Help.

Our team can help you identify the plan that best matches your organization's needs and guide you through setup.

Contact Us