Microsoft Defender for Cloud Posture Report
Delivers a weekly report on Defender for Cloud coverage across your subscriptions, how the secure score moved, and anything in the configuration that needs an admin, from missing plans to exemptions nobody reviewed.
What this agent does
This read-only agent checks the health of Microsoft Defender for Cloud across a tenant every week. It finds subscriptions where the Defender plans the team expects are off, and resources where the required agents or extensions are missing. It compares the enabled plans and the active exemptions with a baseline the team approved. It summarizes the secure score, the High severity recommendations that appeared and were resolved, and the alerts that fired since last week. It flags anything that needs an admin, such as a connected AWS or GCP account whose connector is failing.
The challenge
Defender for Cloud protects only the subscriptions and workloads where its plans are on. Coverage changes one subscription at a time, and no single view shows the drift. A new subscription is created with no plans. A plan is turned off in one subscription to cut cost, and nobody tracks it. An agent extension fails to install on a fleet of virtual machines. Each new exemption lifts the secure score, and nobody checks who granted it. A multicloud connector loses its role, and the AWS recommendations stop updating.
The solution
The agent checks plan coverage, agent coverage, exemptions, connectors, and score movement in one pass each week and compares them with the previous week and with the approved baseline. It lists what changed and what someone needs to act on, with the fix for each item. Provides a weekly briefing an admin can read in a few minutes.
Workflow
- 01
Check coverage
List the tenant's subscriptions and connected accounts, and find where expected plans are off and where agents or extensions are missing.
- 02
Check configuration
Compare enabled plans and active exemptions with the approved baseline, and check each multicloud connector's status.
- 03
Check activity
Summarize the secure score, High severity recommendations that appeared and were resolved, and alerts that fired since last week.
- 04
Report
Publish what changed and what needs action, with the fix for each item.
Agent template
# Microsoft Defender for Cloud Posture Report
## Measurable outcomes
Every week, the admin knows which subscriptions and workloads Defender for Cloud is not covering, how the configuration differs from the baseline, how the secure score and High severity recommendations moved, and what needs action. Track covered and uncovered subscriptions, baseline differences, and open action items on every run.
## Procedure
Once a week, list the tenant's subscriptions and the AWS and GCP accounts connected through Defender for Cloud. For each subscription, compare the enabled Defender plans with a baseline I approve, and flag each plan that is off or on outside the baseline. Treat a subscription with no approved baseline as a candidate, never as drift. Flag virtual machines, Kubernetes clusters, and other workloads where a required agent or extension is missing or unhealthy, from the recommendations Defender for Cloud raises for them. List every active exemption with its scope, category, expiry, and who created it. Flag waiver (risk accepted) exemptions and exemptions with no expiry. Check each multicloud connector and flag any whose status is failing or whose last sync is outside the window. Read the secure score and the per-control scores and compare them with last week. Summarize the High severity recommendations that became unhealthy and the ones resolved since the last report, and the security alerts that fired, by severity and resource type. Compare everything with last week's report, and lead with what changed. Give every action item the specific fix. Report a check it cannot run as not checked, never as fine.
## Requirements
It needs read-only Microsoft Defender for Cloud access across the tenant to plans, recommendations, exemptions, alerts, secure scores, and connectors, read access to list subscriptions, and nothing more. It never changes plans, exemptions, policies, or alerts, and never approves a baseline. Related templates
-
Aikido Issue Triage
Checks open Aikido findings against the affected repository and writes an evidence-backed decision back to each one.
Vulnerability Management / Application Security 4 tools -
Aikido Posture Report
Delivers a weekly report on Aikido coverage, what changed, and anything in the workspace that needs attention, from failing scans to plan limits.
Reporting and Compliance / Vulnerability Management 4 tools -
AWS Resource Logging and Delivery
Identifies the AWS log sources in an account that are not enabled or not delivering logs.
Reporting and Compliance / Infrastructure Operations 1 tools -
AWS Security Hub CSPM Finding Triage
Writes an evidence-based judgment for each open Critical and High Security Hub CSPM finding, verifies it against the live resource, and suppresses the ones the checks prove are false positives.
Featured Vulnerability Management 2 tools