Most of what an Azure security audit needs is already free in your subscription.
Secure score, the Microsoft cloud security benchmark and multicloud connection all sit in the free Foundational CSPM tier of Defender for Cloud. Very few UAE organisations have switched them on. We audit what your estate actually looks like, and tell you what genuinely needs paying for.

- Foundational CSPMFree, and usually not enabled
- Subscription-wideIdentity, network, data, workloads
- Free firstWe use what you already have
- AWS and GCP tooMulticloud connection is free
Eight areas, starting with the tooling you already own.
Turn on what is free before buying anything
Microsoft states that Defender for Cloud includes free Foundational CSPM capabilities, and the free tier explicitly covers secure score, centralised policy management with the Microsoft cloud security benchmark as a built-in standard, the CSPM dashboard, and connecting AWS and GCP environments. In most UAE estates we assess, none of this is enabled. That is a genuine finding and it costs nothing to fix.
Who can do what, across subscriptions
Role assignments at management group, subscription and resource group level, how many people hold Owner or Contributor, whether those assignments are permanent or activated when needed, and which service principals and managed identities hold significant rights. Service principals are the ones organisations lose track of, because they were created during a deployment and nobody owns them afterwards.
What is reachable from the internet
Public IP addresses, exposed management ports, storage accounts and databases with public network access, application endpoints, and anything left listening from a project that finished. This is the section that most often produces something urgent, and the cause is almost always a temporary arrangement that was never reversed rather than a deliberate decision.
Where the data is and how it is protected
Storage accounts, databases and their access model: network restrictions, shared access signatures and how they are issued, encryption and key management, and whether anything holding personal or regulated data is reachable more broadly than anybody intended. Shared access tokens are a recurring finding because they are easy to issue, long-lived by default and hard to revoke individually.
Key Vault, secrets and what is sitting in plain text
Whether secrets are in Key Vault or in application settings, pipeline variables and configuration files, who can read them, whether access is logged, and whether anything has an expiry nobody is tracking. The common pattern is a Key Vault that exists, is used properly by the newest workload, and is bypassed by everything older.
Policy, and whether anything is actually enforced
Azure Policy assignments, what they audit rather than enforce, and whether exemptions were granted temporarily and never reviewed. Centralised policy management sits in the free tier, so an estate with no policy assignments is not a licensing problem, it is an unconfigured one. Effective policy is what stops the estate drifting back after you fix it.
Logging, retention and whether an investigation is possible
Which resources send diagnostic logs, where those logs go, how long they are kept, and whether anybody would notice an alert. As with any cloud platform, the retention you have is a configuration decision rather than a default that suits you, and organisations discover the limit during an investigation rather than before one.
Which paid plans are actually worth it for you
Defender CSPM adds attack path analysis, cloud security explorer, regulatory compliance and governance. The workload plans cover servers, containers, storage, databases, Key Vault, App Service, APIs and Resource Manager separately. Which of these earns its place depends entirely on what you run, and the honest answer for a small estate is often fewer of them than a vendor would propose.
Switch on the free tier and look at the score.
This is the single most useful thing on this page and you can do it yourself this afternoon. Microsoft publishes what is included at no cost, and it is more than most people assume.
- Microsoft states that Defender for Cloud includes free Foundational CSPM capabilities. Explicitly listed in that free tier: secure score, centralised policy management including the Microsoft cloud security benchmark as a built-in standard, the CSPM dashboard, and multicloud coverage so you can connect AWS and GCP environments as well.
- That gives you a prioritised list of misconfigurations across your Azure estate without spending anything. It will not give you attack path analysis, the cloud security explorer, regulatory compliance reporting or governance rules, which sit in the paid Defender CSPM plan, and it will not give you the workload protection plans. But it will tell you whether you have a problem worth investigating.
- What the score is not is a security rating you should optimise. It is calculated against a Microsoft baseline that does not know your business, so it will award points for controls you do not need and stay silent on the specific thing that would actually hurt you. Use it as a starting index and a trend line, not as an answer.
- The reason this matters commercially is that plenty of proposals in this market start with buying Defender plans. Sometimes that is right. But an estate that has never enabled the free tier has no idea what its actual problems are, and buying advanced tooling before knowing that is a poor sequence.
Four things that keep this from becoming a licensing proposal.
We use the free tier before recommending a paid one
Foundational CSPM gives you secure score, policy management, the Microsoft cloud security benchmark and multicloud connection at no cost. We enable and read that first, because it establishes what your actual problems are. Recommending Defender CSPM or workload plans before knowing that is selling before diagnosing, and it produces spend that does not match the risk.
We separate what is urgent from what is untidy
An Azure estate will generate a long list of recommendations, most of which are housekeeping. A management port open to the internet, an over-permissioned service principal and a storage account holding personal data with public access are a different category entirely. The report leads with the second group, because a hundred-item list gets filed and a five-item list gets fixed.
We connect findings to the obligations you actually carry
Where you are subject to UAE data protection obligations, sector requirements or client commitments, the findings that matter are the ones touching those. We map them rather than reporting generically, which also makes the remediation easier to fund because the justification is concrete rather than a security preference.
We cover the estate you have, including the parts outside Azure
Multicloud connection for AWS and GCP is in the free tier, so if you run workloads across more than one provider we can bring them into the same view rather than assessing Azure in isolation. Plenty of UAE organisations have a primary platform and a second one that arrived through an acquisition or a single project, and the second one is invariably the less governed.
Six situations that bring UAE organisations to an Azure audit.
A client or insurer has asked specific questions
Questions about cloud access control, encryption, logging and network exposure, which somebody has to answer accurately and in writing. An audit produces the answers and, more usefully, identifies which ones you should fix before answering. This is the most common trigger and the one with the clearest finish line.
Azure grew from one project into an estate
It started with a single workload, it worked, and five years later there are several subscriptions, resources nobody claims and access granted for reasons nobody remembers. Nothing is wrong exactly, and nobody has ever looked at it as a whole. These audits reliably find things worth fixing and rarely find a crisis, which is the right time to look.
A regulated firm in DIFC, ADGM or under CBUAE supervision
Cloud governance, access control and the ability to evidence both come up in supervisory conversations, and for a firm running material workloads in Azure that evidence lives in the subscription. Where the Central Bank requirements applying to you set the UAE Information Assurance Standards as a floor, the mapping between those and your Azure configuration is work worth doing deliberately.
An organisation holding personal or regulated data in Azure
The federal data protection law and, for free zone entities, their own regimes apply to data wherever it sits. The practical questions are where that data actually is in your estate, who can reach it, whether it is reachable from outside, and whether you could evidence access. Those are audit questions before they are legal ones.
A business that inherited an estate from a departed engineer
One person built it, understood it and has left. What remains is infrastructure nobody can fully explain, with service principals, automation and access whose purpose is undocumented. The first value of an audit here is simply an accurate picture, before any question of improving it arises.
After a cost review raised uncomfortable questions
A finance-driven look at Azure spend often surfaces resources nobody can account for, which is a security question as much as a cost one. Anything running that nobody owns is also anything running that nobody is patching, monitoring or securing. The two exercises overlap more than people expect and are worth doing together.
What we find when we audit an Azure estate in the UAE.
| Feature | Governed | Grown by accretion | Unexamined |
|---|---|---|---|
Complete inventory of subscriptions and owners | Partial | ||
Defender for Cloud enabled at least on the free tier | Sometimes | ||
Secure score tracked as a trend | |||
Privileged role assignments reviewed | Rarely | ||
Service principals owned and understood | |||
Internet exposure known and intentional | Partly | ||
Secrets held in Key Vault | Newer workloads only | In config files | |
Policy enforces rather than only audits | Audit only | None | |
Diagnostic logging with deliberate retention | Default or absent | ||
Resources from finished projects removed |
Defender for Cloud capabilities by plan.
| Capability | Plan | |
|---|---|---|
| Secure score | Foundational CSPM, free | |
| Centralised policy management | Foundational CSPM, free | |
| Microsoft cloud security benchmark as a built-in standard | Foundational CSPM, free | |
| CSPM dashboard | Foundational CSPM, free | |
| Connect AWS and GCP environments | Foundational CSPM, free | |
| Code pipeline insights | Foundational CSPM and Defender CSPM | |
| Attack path analysis | Defender CSPM | |
| Cloud security explorer | Defender CSPM | |
| Regulatory compliance reporting | Defender CSPM | |
| Security governance rules | Defender CSPM | |
| Data security posture management | Defender CSPM or Defender for Storage | |
| Server, container, storage, database and other workload protection | Separate CWPP plans, per workload type |
Five stages, typically one to two weeks.
- 1
Inventory the estate and enable what is free
Every subscription, who owns it, what runs in it, and Defender for Cloud enabled at least on Foundational CSPM so the secure score and benchmark recommendations are available. For many organisations this stage alone produces the first useful output, because the complete subscription list does not currently exist anywhere.
- 2
Identity and access review
Role assignments across management groups, subscriptions and resource groups, privileged role holders, whether access is standing or activated when needed, and the service principals and managed identities that hold meaningful rights. This is where the highest-severity findings usually sit, and it is the part most often missing from automated reports.
- 3
Exposure and data review
What is reachable from the internet, what network restrictions exist on storage and databases, how shared access tokens are issued and whether they can be revoked, encryption and key management, and where regulated data actually lives. We work from what is configured now rather than from what the policy intends.
- 4
Logging, policy and detection review
Diagnostic settings across resource types, where logs go and for how long, whether alerts reach anybody, Azure Policy assignments and whether they enforce or merely audit, and which exemptions were granted temporarily and never revisited.
- 5
Report, prioritise, and decide what to buy
Findings ranked by exploitability rather than by tool severity, separated into what costs configuration effort and what would cost licensing. Where a paid Defender plan genuinely earns its place for your workloads we say which and why. Where it does not, we say that too, and the free tier plus configuration is the recommendation.
What organisations ask about Azure security audits.
Fifteen questions about your own subscriptions.
What actually exists
- How many Azure subscriptions do you have, and who owns each?Shadow subscriptions on a departmental card are common.
- Is Defender for Cloud enabled, even on the free tier?Free, and usually not switched on.
- What is your secure score, and has anyone looked at it?A starting index, not a target to optimise.
- Are there resources from projects that finished?They keep running, keep costing and keep being exposed.
- Do you know which resources hold personal or regulated data?Needed for both security and data protection obligations.
Exposure
- How many resources have a public IP address?Count them. The number is usually a surprise.
- Are any management ports reachable from the internet?The most common route into a cloud estate.
- Do storage accounts or databases allow public network access?Check per resource, not per policy intention.
- How many people hold Owner or Contributor at subscription level?And is that access permanent or activated when needed.
- Which service principals hold significant permissions?Created during deployments, rarely owned afterwards.
Could you investigate
- Are diagnostic logs enabled on resources that matter?Off by default on many resource types.
- Where do those logs go, and how long are they kept?Retention is a configuration decision, not a sensible default.
- Would an alert reach a human who would act on it?Collection without response is not detection.
- Are secrets in Key Vault, or in app settings and pipelines?The older the workload, the more likely the latter.
- Do any Azure Policy assignments actually enforce, or only audit?Audit-only policy documents drift, it does not stop it.
The pages around this one.
Microsoft 365 security audit
The tenant half of the same Microsoft estate: identity, mail, sharing, devices, and how far back your audit evidence actually reaches.
IT audit services in Dubai
The wider audit practice, and how to tell which kind of engagement your situation actually calls for before anybody quotes for one.
NIST CSF 2.0 assessment
If you want a picture across the whole security function rather than one platform, this is the broader framework a cloud audit feeds into.
Enable the free tier and count your public IP addresses.
Those two things cost nothing, take an afternoon, and between them tell you whether you have a problem. If you would like help interpreting what you find, or a proper look at the estate behind it, that is a short conversation and we will tell you what we would examine first.
Related Services
Explore more solutions that work great with this service
Microsoft 365 Security Audit
Tenant review, and how far back your evidence really goes
IT Audit Services Dubai
Assessment, technical test or certification, scoped properly
NIST CSF 2.0 Assessment
Know where you stand, without committing to certification
Microsoft Entra
Identity and access management solutions
Microsoft Security Dubai
Entra, Defender, Purview, Sentinel, and what you already own
Azure Cloud Solutions
Azure landing zone, migration, FinOps, managed
UAE PDPL Compliance
Federal Decree-Law 45 of 2021 readiness and operations
Managed Security Services
MSS on Microsoft Defender XDR and Sentinel