Understanding why Compliance Controls Matter is one of the main reasons we are doing this lab. Standing up resources in Azure is the easy part.
Knowing whether those resources actually meet security and regulatory standards is a different challenge entirely that we must deal with, and that is where Microsoft Defender for Cloud comes in.
Its regulatory compliance dashboard maps your environment against built-in benchmarks (like Azure Security Benchmark, ISO 27001, or NIST) and tells you exactly where you stand, control by control.
Firstly, let us begin by starting a browser session and signing in to the Azure portal menu.
In the Azure portal, in the Search resources, services, and docs text box at the top of the Azure portal page, type Microsoft Defender for Cloud and press the Enter key.
Next on the Microsoft Defender for Cloud Management blade, go to the Environment settings. Expand the environment settings folders until the subscription section is displayed, then click the subscription to view details.
In the Settings blade, under Defender plans, expand Cloud Workload Protection (CWP). From the Cloud Workload Protection (CWP) Plan list, select Servers. On the right side of the page, change the Status from Off to On, then click Save. To review the details of Microsoft Defender for Servers Plan 2, select Change plan.
Note: Switching the Cloud Workload Protection (CWP) Servers plan from Off to On activates Microsoft Defender for Servers Plan 2.
Now we have enabled Microsoft Defender for Servers Plan 2 on our subscription.
Key Takeaways
- Compliance is not a one-time checkbox; Defender for Cloud treats it as a continuously monitored posture.
- Secure Score gives a quick check, but the real value is in the drill-down: Each recommendation ties back to a specific, actionable fix.
If you have any feedback or tips to add to this guide, please share them in the comments below. I'd love to learn from you!



Top comments (0)