Skip to main content

Improving Your Azure Secure Score with Defender for Cloud

Learn to read Microsoft Defender for Cloud's Secure Score, prioritize its recommendations, and fix a real misconfiguration to raise the score.

Overview and What You Will Learn

In this lab, you will enable Microsoft Defender for Cloud, review its Secure Score and recommendations, deliberately create a misconfiguration to see it get flagged, then fix it and watch the score respond - connecting an abstract number to concrete, actionable fixes.

Why This Matters in Production

A team assumes their Azure environment is reasonably secure because nothing has gone wrong yet, without ever checking whether basic protections like disk encryption or public access restrictions are actually enabled across their resources. Secure Score turns that vague assumption into a specific, prioritized list of exactly what to fix, ranked by how much each fix actually improves the environment's real security posture.

Core Principles

Defender for Cloud continuously scans your actual deployed resources and compares their configuration against a set of security best practices, producing both a single overall score and a specific list of recommendations behind that score.

◈ DIAGRAM
+------------------------------------------+
| Defender for Cloud scans deployed resources|
+------------------------------------------+
|
v
+------------------------------------------+
| Compares against security best practices |
| (encryption, network exposure, patching, |
| identity hygiene, and more) |
+------------------------------------------+
|
v
+------------------------------------------+
| Secure Score: a single number reflecting |
| how many recommended controls are actually |
| implemented, out of the total that apply |
+------------------------------------------+
|
v
+------------------------------------------+
| Specific, actionable recommendations |
| (e.g. "enable disk encryption on this VM") |
+------------------------------------------+

The score itself is less important than the specific recommendations behind it - a low score with three critical, easy fixes is a better position to be in than a slightly higher score hiding one deeply entrenched, hard-to-fix issue.

Detailed Step-by-Step Practical Lab

  1. Create a Resource Group and a storage account with an intentionally weak configuration to observe being flagged:
Bash
az group create --name rg-defender-lab-mumbai --location centralindia
az storage account create \
--name stdefenderlabrahul \
--resource-group rg-defender-lab-mumbai \
--location centralindia \
--sku Standard_LRS \
--allow-blob-public-access true
Note

--allow-blob-public-access true deliberately creates a misconfiguration for this lab - allowing public access to blobs is a common real-world finding Defender for Cloud specifically checks for and flags.

  1. Check your current Secure Score for the subscription:
Bash
az security secure-scores list --output table
  1. List current recommendations, which should include a flag for the storage account's public access setting created in step 1:
Bash
az security tasks list --output table
  1. Review the specific recommendation details for the public blob access finding, then fix it by disabling public access:
Bash
az storage account update \
--name stdefenderlabrahul \
--resource-group rg-defender-lab-mumbai \
--allow-blob-public-access false
  1. Recommendations and score updates are not instantaneous - Defender for Cloud re-evaluates on its own schedule, so re-check after some time has passed:
Bash
az security secure-scores list --output table
  1. Review recommendations by severity to understand prioritization - high-severity findings should generally be addressed before lower-severity ones, even if a lower-severity fix would be quicker to implement:
Bash
az security tasks list \
--query "[?properties.severity=='High']" --output table
  1. Clean up:
Bash
az group delete --name rg-defender-lab-mumbai --yes --no-wait

Production Best Practices & Common Pitfalls

Common Mistake

Chasing Secure Score as a number to maximize, rather than actually reading and prioritizing the specific recommendations behind it. A slightly lower score with all critical, high-severity issues resolved is a stronger security position than a higher score that still has one serious unresolved finding sitting among many minor ones.

Tip

Review Secure Score recommendations regularly, not just once during initial setup. New resources get created, configurations drift over time, and a recommendation that didn't apply last month may apply today simply because something new was deployed.

  • Not every recommendation applies equally to every environment. A recommendation about a service you don't actually use can often be safely dismissed rather than chased purely to raise the score - use judgment about which recommendations genuinely matter for your specific workloads.
  • Free-tier Defender for Cloud gives you Secure Score and basic recommendations; paid tiers add active threat protection. Understand which tier you're on so you know whether you're getting recommendations only, or genuine real-time threat detection as well.

Quick Reference & Troubleshooting Commands

Command Description
az security secure-scores list Check the current Secure Score
az security tasks list List current security recommendations
az security tasks list --query "[?properties.severity=='High']" Filter recommendations by severity
az storage account update --allow-blob-public-access false Fix a common public-access misconfiguration

Explore More in Azure Monitoring, Identity, and Production Readiness

All 6 Topics

Frequently Asked Questions

Is Improving Your Azure Secure Score with Defender for Cloud free to learn on DevOps Network?

Yes - this topic, like everything on DevOps Network, is 100% free with no paywall or sign-up gate.

What does the Improving Your Azure Secure Score with Defender for Cloud topic cover?

Learn to read Microsoft Defender for Cloud's Secure Score, prioritize its recommendations, and fix a real misconfiguration to raise the score.