Skip to main content
{ Reporting and Compliance / Vulnerability Management }

Microsoft Defender for Cloud Posture Report

Delivers a weekly report on Defender for Cloud coverage across your subscriptions, how the secure score moved, and anything in the configuration that needs an admin, from missing plans to exemptions nobody reviewed.

What this agent does

This read-only agent checks the health of Microsoft Defender for Cloud across a tenant every week. It finds subscriptions where the Defender plans the team expects are off, and resources where the required agents or extensions are missing. It compares the enabled plans and the active exemptions with a baseline the team approved. It summarizes the secure score, the High severity recommendations that appeared and were resolved, and the alerts that fired since last week. It flags anything that needs an admin, such as a connected AWS or GCP account whose connector is failing.

The challenge

Defender for Cloud protects only the subscriptions and workloads where its plans are on. Coverage changes one subscription at a time, and no single view shows the drift. A new subscription is created with no plans. A plan is turned off in one subscription to cut cost, and nobody tracks it. An agent extension fails to install on a fleet of virtual machines. Each new exemption lifts the secure score, and nobody checks who granted it. A multicloud connector loses its role, and the AWS recommendations stop updating.

The solution

The agent checks plan coverage, agent coverage, exemptions, connectors, and score movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.

Workflow

  1. 01

    Check coverage

    List the tenant's subscriptions and connected accounts, and find where expected plans are off and where agents or extensions are missing.

  2. 02

    Check configuration

    Compare enabled plans and active exemptions with the approved baseline, and check each multicloud connector's status.

  3. 03

    Check activity

    Summarize the secure score, High severity recommendations that appeared and were resolved, and alerts that fired since last week.

  4. 04

    Report

    Publish what changed and what needs action, with the fix for each item.

Agent template

# Microsoft Defender for Cloud Posture Report

## Measurable outcomes

Every week, the admin knows which subscriptions and workloads Defender for Cloud is not covering, how the configuration differs from the baseline, how the secure score and High severity recommendations moved, and what needs action. Track covered and uncovered subscriptions, baseline differences, and open action items on every run.

## Procedure

Once a week, list the tenant's subscriptions and the AWS and GCP accounts connected through Defender for Cloud. For each subscription, compare the enabled Defender plans with a baseline I approve, and flag each plan that is off or on outside the baseline. Treat a subscription with no approved baseline as a candidate, never as drift. Flag virtual machines, Kubernetes clusters, and other workloads where a required agent or extension is missing or unhealthy, from the recommendations Defender for Cloud raises for them. List every active exemption with its scope, category, expiry, and who created it. Flag waiver (risk accepted) exemptions and exemptions with no expiry. Check each multicloud connector and flag any whose status is failing or whose last sync is outside the window. Read the secure score and the per-control scores and compare them with last week. Summarize the High severity recommendations that became unhealthy and the ones resolved since the last report, and the security alerts that fired, by severity and resource type. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.

## Requirements

It needs read-only Microsoft Defender for Cloud access across the tenant to plans, recommendations, exemptions, alerts, secure scores, and connectors, read access to list subscriptions, and nothing more. It never changes plans, exemptions, policies, or alerts, and never approves a baseline.