Azure Policy and Defender for Cloud
Azure Policy decides what is allowed and records compliance state. Defender for Cloud turns that state into a secure score and a regulatory compliance dashboard. Together they are most of your Azure configuration evidence.
Assign one baseline initiative at your top management group, normally the Microsoft cloud security benchmark that Defender for Cloud applies by default. Add a handful of deny policies for rules you never want broken. Enable Defender plans only for the resource types that hold customer data. The regulatory compliance dashboard then maps your state to ISO 27001, SOC 2, PCI DSS and other standards, and Azure Policy keeps the history.
Azure Policy
Policy definitions describe a rule. Initiatives group them. Assignments apply them at a scope: management group, subscription or resource group. Each policy has an effect, and the effect decides how strong the evidence is.
| Effect | What happens | Evidence value |
|---|---|---|
| Deny | Non-compliant resource creation is blocked | Strongest: the problem could not occur |
| DeployIfNotExists | Missing configuration is deployed automatically | Strong: the control fixes itself |
| Modify | Properties such as tags are changed on create or update | Strong for tagging and settings |
| Audit | Non-compliance is reported | Detective: needs a remediation record |
Good deny candidates: allowed locations limited to Canada Central and Canada East, no public network access on storage and databases, minimum TLS 1.2, and required diagnostic settings through DeployIfNotExists.
Defender for Cloud
The free foundational tier gives cloud security posture management: secure score, recommendations and the regulatory compliance dashboard with the Microsoft cloud security benchmark. You can add other standards to the dashboard. Paid plans add workload protection per resource type.
| Plan | Enable when |
|---|---|
| Defender for Servers | You run virtual machines in production |
| Defender for Containers | You run AKS or container registries |
| Defender for SQL and open-source databases | Customer data sits in Azure databases |
| Defender for Storage | Customers upload files to storage accounts |
| Defender CSPM (paid) | You need attack path analysis or agentless scanning at scale |
| Defender for Key Vault, Resource Manager, DNS | Useful threat detection; check cost against value |
Cost
Defender plans are priced per resource, per server or per transaction. On a small estate they cost little. On an estate with many servers or storage accounts, enabling every plan subscription-wide can cost more than the rest of your compliance tooling. Enable deliberately and check the pricing page for your resource counts first.
Turning it into evidence
- Export the regulatory compliance report for the standard your auditor uses at points across the period.
- Keep the policy assignment list with scope and effect.
- For audit-effect policies, show non-compliant resources were remediated or exempted with a reason. Azure Policy exemptions record who exempted what and when.
- Route Defender alerts to a queue and keep triage notes for CC7.
Does Defender for Cloud show SOC 2 compliance?
The regulatory compliance dashboard can show assessments mapped to SOC 2 and ISO 27001, alongside the default Microsoft cloud security benchmark. It covers technical controls only. It does not make you SOC 2 compliant and does not replace the audit.
Is the free tier of Defender for Cloud enough for an audit?
For configuration evidence, often yes. It gives secure score, recommendations and the compliance dashboard. Paid plans add threat detection on workloads, which strengthens CC7 evidence where customer data lives.
Where should Azure policies be assigned?
At the highest management group that should follow them, so every subscription inherits the rules, including subscriptions created later. Exceptions go in exemptions, not in separate assignments.
Need an Azure policy baseline?
Firms in the network design the initiatives and Defender setup.
Get matched