We value your privacy

We use cookies to analyse site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft security
  2. Defender for Cloud
Microsoft Defender for Cloud, UAE

The posture management tier is free, and most Azure subscriptions in this market have never switched it on.

Defender for Cloud scores your cloud security posture, checks it against a built-in benchmark that also covers AWS and GCP, and defends servers, containers, storage, databases and APIs through separate plans you enable only where they earn their place. The first part costs nothing and almost nobody uses it.

Book a cloud posture reviewSee what is free and what is not
Microsoft Defender for Cloud for UAE organisations
  • Free tierFoundational CSPM, including secure score
  • AWS and GCPMulticloud, agentless
  • Attack pathsHow an attacker would actually get in
  • Ten plansEnabled selectively, not all at once
Start with what costs nothing

Four capabilities are in the free foundational tier.

Microsoft states plainly that Defender for Cloud includes free foundational CSPM capabilities. In our experience most UAE Azure estates have never enabled them, which makes this the cheapest security improvement available to them.

  • Secure score, which summarises your posture from the security recommendations and improves as you remediate them. It gives you a number to report and a ranked list to work through, on subscriptions you already pay for.
  • Centralised policy management, translating your security conditions into recommendations that flag resources violating them, with the Microsoft cloud security benchmark available as a built-in standard covering Azure, AWS and GCP.
  • Multicloud coverage, connecting AWS and GCP environments agentlessly for posture insight, so a mixed estate can be assessed against one benchmark rather than three separate conversations.
  • Code pipeline insights, connecting GitHub, Azure DevOps and GitLab to surface infrastructure as code misconfigurations and exposed secrets. Paid Defender CSPM then adds attack path analysis, the cloud security explorer, regulatory compliance, governance and data security posture management, and those are the capabilities worth a budget conversation once the free tier has told you where you stand.
Ask us to enable and interpret the free tier first
What it covers

Eight capabilities, and the line between free and paid.

Microsoft describes Defender for Cloud as a cloud native application protection platform with three core components: cloud security posture management, development security operations, and cloud workload protection. The first has a free tier that most organisations have never enabled.

Secure score, in the free foundational tier

Microsoft states that Defender for Cloud includes free foundational CSPM capabilities, and secure score is one of them. It summarises your posture based on the security recommendations, and improves as you remediate them. For an organisation with Azure subscriptions and no posture management at all, this is a genuine and immediate improvement that costs nothing but the effort of acting on it.

AWS and GCP in the same view, also free

Multicloud coverage sits in the foundational tier too, connecting AWS and GCP environments using agentless methods for posture insight. For UAE organisations that ended up multicloud through acquisition, a specific workload requirement or a developer decision nobody reviewed, having one posture view across all three providers is usually the first time anybody has seen the whole picture.

The Microsoft cloud security benchmark, applied across providers

Centralised policy management, also in the free tier, translates security conditions into recommendations that identify resources violating your policy. The Microsoft cloud security benchmark is a built-in standard applying security principles with detailed technical implementation guidance for Azure and, notably, for other providers including AWS and GCP. That gives a mixed estate one consistent yardstick rather than three.

Attack path analysis, which is the paid capability worth paying for

Attack path analysis models traffic across your environment to identify potential risks before you make changes, and the cloud security explorer lets you query a map of your environment to find risks. This is the capability that converts a list of eight hundred recommendations into the handful that actually chain together into a route somebody could use, which is a completely different conversation with a board.

Workload plans you enable selectively

Separate plans cover servers, containers, storage, databases, App Service, Key Vault, Resource Manager, APIs and AI services. The design intent is that you enable what your estate actually contains rather than everything, and the plan-by-plan decision is where the cost conversation happens. Most organisations need two or three, not ten.

Storage protection, including SAS token misuse

Defender for Storage protects against malware, storage-specific threats, sensitive data leakage and Shared Access Signature token misuse. That last one is worth calling out because SAS tokens are handed around freely during projects, rarely revoked, frequently over-scoped and almost never monitored, which makes them a recurring finding in the Azure estates we assess.

DevOps security, from code rather than after deployment

Code pipeline insights connect GitHub, Azure DevOps and GitLab repositories, surfacing infrastructure as code misconfigurations and exposed secrets, and correlating those findings with cloud security context so remediation can be prioritised in code. Microsoft lists this under the foundational free tier as well as Defender CSPM, which makes it an unusually cheap place to start.

AI workload security, which is newly relevant

AI security posture management helps discover generative AI applications and identify vulnerabilities, producing what Microsoft calls an AI bill of materials, and AI threat protection detects threats targeting generative AI workloads. For organisations building on Azure OpenAI, this is the mechanism for knowing what AI workloads exist at all, which is frequently more than the security team was told about.

How we approach it

Four things that keep this from becoming a very expensive dashboard.

Defender for Cloud is easy to enable everywhere and easy to leave producing hundreds of recommendations nobody owns. The value is in what gets fixed, not in what gets flagged.

We enable the free tier and interpret it before proposing anything paid

Foundational CSPM gives you a secure score, policy-driven recommendations, multicloud posture and code pipeline insights at no cost. Working that first tells you the shape of the problem, gives you a baseline to measure against, and means any subsequent plan decision is based on your own findings rather than a sales conversation.

We prioritise by attack path, not by recommendation count

A large estate produces hundreds of recommendations and remediating them by severity alone is slow and demoralising. Attack path analysis identifies the chains that actually lead somewhere, which is usually a much shorter list. Fixing one link in a chain removes the whole path, and that is a far better use of a limited engineering budget.

We enable plans selectively and say so

There are ten plans and most estates warrant two or three. We map what you actually run to the plans that cover it and tell you which ones we would not enable, because a recommendation to buy everything is not advice. Where the free tier is sufficient for a workload, we say that too.

We settle ownership before turning on alerting

Workload protection plans generate security alerts that need a responder. Before enabling them we establish who receives an alert, who owns remediation of a misconfiguration in a given subscription, and what happens outside working hours. In multi-subscription estates ownership is the genuinely hard question, and it is the one that determines whether anything improves.

Where this matters most

Six UAE situations where cloud posture is the actual gap.

The common factor is an Azure estate that grew through projects rather than through a plan, which describes most of the ones we assess.

An estate with subscriptions nobody can fully account for

Created for projects, inherited from an acquisition, or spun up by a developer with a credit card and later formalised. The free posture tier across all subscriptions is the fastest way to see what actually exists and how exposed it is, and the inventory alone is usually worth the exercise.

A regulated firm needing cloud compliance evidence

Where a regulator, an auditor or a client asks how cloud workloads are secured and against what standard, the regulatory compliance capability in Defender CSPM maps your posture to recognised standards and produces the evidence. For firms under Central Bank, DFSA or FSRA supervision this is directly usable in the examination pack.

A development team shipping infrastructure as code

Code pipeline insights connect GitHub, Azure DevOps and GitLab and surface infrastructure as code misconfigurations and exposed secrets before they become deployed resources. Catching a misconfiguration in a pull request costs minutes. Catching it in production, after an auditor finds it, costs considerably more.

An organisation that ended up multicloud without deciding to

A workload on AWS because a supplier required it, something on GCP from an acquisition, the rest on Azure. Agentless connection of AWS and GCP for posture insight is in the free tier, and assessing all three against the Microsoft cloud security benchmark is usually the first consistent view anybody has had.

A business running production databases and storage in Azure

Defender for Databases covers Azure SQL, SQL on machines, open-source relational databases and Cosmos DB, and Defender for Storage covers malware, sensitive data leakage and SAS token misuse. Where the data is the business, these are the two plans that usually justify themselves fastest.

An organisation building on Azure OpenAI

AI security posture management discovers generative AI applications and identifies vulnerabilities, producing an AI bill of materials, while AI threat protection detects threats targeting those workloads. For most organisations the first value is simply knowing which AI workloads exist, because it is routinely more than the security team was told.

Three positions

What organisations actually know about their cloud security posture.

The right column is more common than people admit, and it is not usually negligence. Subscriptions get created for projects, workloads move, and nobody was ever made responsible for the posture of the whole estate.
A posture score you can track over time
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Misconfigurations surfaced against a benchmark
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
AWS and GCP in the same view
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Attack paths identified across resources
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Sensitive data located across cloud storage
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Regulatory compliance reporting
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Threat detection on servers and containers
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Storage and SAS token misuse detected
Defender for Cloud in useYes
Free tier onlyNo
Nothing enabledNo
Infrastructure as code issues caught before deployment
Defender for Cloud in useYes
Free tier onlyYes
Nothing enabledNo
Frequency in the UAE market
Defender for Cloud in useUncommon
Free tier onlyUncommon
Nothing enabledCommon
Feature
Defender for Cloud in use
Free tier only
Nothing enabled
A posture score you can track over time
YesYesNo
Misconfigurations surfaced against a benchmark
YesYesNo
AWS and GCP in the same view
YesYesNo
Attack paths identified across resources
YesNoNo
Sensitive data located across cloud storage
YesNoNo
Regulatory compliance reporting
YesNoNo
Threat detection on servers and containers
YesNoNo
Storage and SAS token misuse detected
YesNoNo
Infrastructure as code issues caught before deployment
YesYesNo
Frequency in the UAE market
UncommonUncommonCommon
The plans

Ten plans, and what each one is actually protecting.

Reproduced from the Microsoft plan list. The decision is which of these your estate genuinely contains, because enabling all of them is neither necessary nor how the product is designed to be bought.
PlanWhat it protects
Foundational CSPM, freePosture, secure score, policy, multicloud connection and code pipeline insights
Defender CSPMAttack path analysis, cloud security explorer, governance, regulatory compliance, data and AI posture
Defender for ServersWindows and Linux machines in Azure, AWS, GCP and on-premises
Defender for ContainersKubernetes hardening, vulnerability assessment and runtime protection
Defender for StorageMalware, storage-specific threats, sensitive data leakage and SAS token misuse
Defender for DatabasesAzure SQL, SQL on machines, open-source relational databases and Cosmos DB
Defender for App ServiceAttacks targeting web applications and APIs running on App Service
Defender for Key VaultUnusual or harmful attempts to access or exploit Key Vault accounts
Defender for Resource ManagerUnusual and potentially harmful resource management operations
Defender for APIsVisibility into business critical APIs and real-time threat detection
AI ServicesThreats to generative AI applications, detected in real time
How an engagement runs

Five steps, and the first one is free.

Typically three to six weeks to a working state depending on estate size. The technical enablement is quick. Establishing ownership across subscriptions is what takes the time.
  1. 1

    Enable foundational CSPM across every subscription

    Including the ones nobody remembered, and connecting AWS and GCP where they exist. This is the free tier, it produces a secure score and a ranked set of recommendations, and it establishes the baseline everything afterwards is measured against.

  2. 2

    Interpret the findings rather than forwarding them

    A large estate produces a lot of recommendations and handing over the raw list achieves nothing. We work through them with you, separate the genuinely exposed from the theoretically imperfect, and produce a remediation list somebody can actually complete in a quarter.

  3. 3

    Decide which workload plans your estate warrants

    Mapped to what you actually run: servers, containers, storage, databases, App Service, Key Vault, APIs or AI services. We name the plans we would not enable as clearly as the ones we would, because selective enablement is how the product is designed to be used.

  4. 4

    Add attack path analysis and prioritise by chain

    Where Defender CSPM is justified, attack path analysis and the cloud security explorer reduce hundreds of findings to the handful of chains that lead somewhere. This is the point at which the reporting stops being a compliance artefact and starts driving engineering decisions.

  5. 5

    Establish ownership and the response path

    Who owns remediation per subscription, how a recommendation becomes a ticket, who receives a security alert from a workload plan and what happens out of hours. Governance rules can assign tasks to resource owners and track progress, and that is what stops the score drifting back down.

Straight answers

What organisations ask about Defender for Cloud.

A meaningful amount of it. Microsoft states that Defender for Cloud includes free foundational CSPM capabilities, and lists secure score, centralised policy management, multicloud coverage for AWS and GCP, the posture dashboard and code pipeline insights in that free tier. In our experience most UAE Azure estates have never enabled it, which makes it the cheapest security improvement available to them and the right place to start.

Foundational is free and gives you posture visibility: score, recommendations, policy and multicloud connection. Defender CSPM is paid and adds the capabilities that make the findings actionable at scale, specifically attack path analysis, the cloud security explorer, regulatory compliance verification, security governance for assigning and tracking remediation, data security posture management and AI security posture management.

Yes, and the connection is agentless. Microsoft lists multicloud coverage in the free foundational tier, and the Microsoft cloud security benchmark is described as a built-in standard providing detailed technical implementation guidance for Azure and other cloud providers including AWS and GCP. For a mixed estate that means one benchmark and one view rather than three separate assessments.

It models your environment to identify how risks chain together into a route somebody could actually use, rather than listing misconfigurations individually. For a small estate with few findings the free tier may be enough. For a large estate producing hundreds of recommendations it is usually the single most valuable paid capability, because it turns an unmanageable backlog into a short list where fixing one link removes an entire path.

No, and you should not. There are ten plans covering servers, containers, storage, databases, App Service, Key Vault, Resource Manager, APIs, AI services and CSPM, and the product is designed for selective enablement based on what your estate contains. Most organisations we work with need two or three. We will tell you which ones we would not enable as clearly as the ones we would.

An audit is a point-in-time assessment producing a findings report and a remediation list, and it is the right choice when you need an independent view or an answer for a specific auditor. Defender for Cloud is continuous posture management inside the platform. The usual sequence is to enable the free tier first, because it may answer most of what an audit would tell you, and then commission the audit for the parts it does not cover.

Microsoft states that as of 1 August 2023, customers with an existing subscription to Defender for DNS can continue using it as a standalone plan, and that for new subscriptions alerts about suspicious DNS activity are included as part of Defender for Servers Plan 2. Microsoft is explicit that there is no change to the protection scope and that the change affects how DNS protection is billed and bundled rather than what is covered.

Microsoft lists malware, storage-specific threats, sensitive data leakage and Shared Access Signature token misuse. The SAS token element is worth highlighting because in most Azure estates tokens are issued freely during projects, over-scoped for convenience, rarely revoked and never monitored. It is a recurring finding for us and it is the kind of exposure that no amount of network security addresses.

Yes, and this is one of the more underused capabilities. Code pipeline insights connect GitHub, Azure DevOps and GitLab repositories and surface infrastructure as code misconfigurations and exposed secrets, correlating those findings with cloud security context so remediation can be prioritised in code. Microsoft lists this in the free foundational tier as well as Defender CSPM, so the barrier to trying it is low.

AI security posture management discovers generative AI applications, identifies vulnerabilities and reduces risks using built-in recommendations and attack path analysis, producing what Microsoft describes as an AI bill of materials. AI threat protection detects threats targeting generative AI workloads in real time. There is also a data and AI security dashboard. The most common first finding is simply how many AI workloads exist that security did not know about.

Both currently, and it is moving. Microsoft states that Defender for Cloud is expanding to the Defender portal to provide a unified security experience across cloud and code environments, with some features already available there and more to follow. Microsoft documentation now indicates which portal a given article applies to. In practice, expect the Defender portal to become the primary place over time.

Microsoft Defender Experts for Servers is a managed detection and response service adding Microsoft analyst expertise to a Defender for Servers deployment, covering Windows and Linux servers across Azure, AWS, GCP and on-premises. Microsoft states it is sold separately from Defender for Servers Plan 1 and Plan 2 and that you opt in when you want Microsoft to operate detection and response on your behalf. We can also cover the response function ourselves, and we will discuss both.

On a first enablement across a mature estate, more than anybody wants. That is expected and it is why interpretation matters more than enablement. We separate the genuinely exposed from the theoretically imperfect, use attack paths where available to identify what actually chains together, and produce a list somebody can complete in a quarter rather than a report that sits unread.

Three to six weeks to a working state for most estates. Enabling the free tier takes hours. Interpreting the findings takes a week or two depending on size. Deciding and enabling workload plans is quick once the estate is understood. The part that genuinely takes time is establishing who owns remediation in each subscription, and that is a conversation rather than a configuration.

We scope per organisation, driven by the number of subscriptions, whether AWS and GCP are in scope, and whether you want the remediation delivered or just identified. Microsoft plan costs are separate and are billed by Microsoft. What we will do free in the first conversation is tell you whether the free foundational tier is already enabled, and if not, that is where we would start regardless of anything else.
Before deploying

Fifteen questions worth answering first.

The first group is what you actually run, which determines which plans matter. The second is what you already have free. The third is whether findings will be acted on, which is the difference between a score and an improvement.

What you actually run

  • How many Azure subscriptions do you have?
    Including the ones a project team created and forgot.
  • Do you also have AWS or GCP workloads?
    Multicloud posture is in the free tier.
  • Do you run containers or Kubernetes?
    A separate plan, and a common blind spot.
  • Do you have storage accounts with SAS tokens issued?
    SAS misuse is specifically covered.
  • Are you building anything on Azure OpenAI?
    AI posture management applies.

What you already have

  • Has foundational CSPM ever been enabled?
    It is free and frequently untouched.
  • Do you know your current secure score?
    If not, that is the first number to get.
  • Are your repositories connected?
    Code pipeline insights are in the free tier.
  • Is the Microsoft cloud security benchmark applied?
    Built in, and covers AWS and GCP too.
  • Do you have Defender for Servers Plan 2?
    It now includes suspicious DNS activity alerts.

Would findings be acted on

  • Who owns remediation of a cloud misconfiguration?
    Frequently nobody, which is the real finding.
  • Is there a change process for production subscriptions?
    Recommendations become tickets or they become noise.
  • Would attack path findings reach a decision maker?
    They are the ones worth escalating.
  • Do you need regulatory compliance reporting?
    That sits in the paid Defender CSPM plan.
  • Do you have anybody watching alerts out of hours?
    Workload plans generate alerts that need a responder.
Related reading

The pages around this one.

Azure security audit

The independent point-in-time assessment, and how it differs from continuous posture management inside the platform.

Learn more

Azure cloud solutions

The wider platform work: architecture, migration, cost management and the estate this posture applies to.

Learn more

Defender for Endpoint

The endpoint half of the same family, which Defender for Servers builds on for server protection.

Learn more
Next step

Find out your secure score. It costs nothing and it takes an afternoon.

Foundational CSPM is free, covers every subscription including the ones nobody remembers, and connects AWS and GCP agentlessly. If that number is bad, you will know what to do next. If it is good, you have saved yourself a purchase.

Book a cloud posture reviewCall +971 56 613 2743

Related Services

Explore more solutions that work great with this service

Azure Security Audit

Subscription audit, starting with the free tier you already own

Learn more

Azure Cloud Solutions

Azure landing zone, migration, FinOps, managed

Learn more

Defender for Endpoint

Business, Plan 1 or Plan 2, and what each actually gives you

Learn more

Microsoft Security Dubai

Entra, Defender, Purview, Sentinel, and what you already own

Learn more

VAPT Testing

CREST-certified vulnerability assessment and penetration testing

Learn more

Microsoft Sentinel

Cloud-native SIEM and threat intelligence

Learn more

NESA / IA Compliance

UAE Information Assurance Standards compliance

Learn more

ISO 27001 Certification UAE

The 2022 edition, and whether you should certify at all

Learn more
GR IT SERVICES

Leading IT services provider in Dubai,
delivering enterprise-grade solutions
for businesses across the UAE.

Microsoft CSP PartnerCISGuard

Get the Helpdesk app

Raise and track IT tickets from your phone.

Download on the App StoreGet it on Google Play
Learn more about the app

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support Dubai
  • IT AMC Dubai
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • Iris Bay Tower, Office 903,
    Business Bay, Dubai, UAE
  • +971 56 613 2743
  • hello@gritservices.ae
  • gritservices.ae

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie Policy