Just got hands-on with the new Defender CSPM in our Azure tenant. It's definitely a step up from the old ASC posture management! The asset graph and attack path analysis are super slick and feel native.
But does it replace my 3rd party CNAPP tools? Not yet, for us. The multi-cloud story is still Azure-first, and I'm not seeing the same depth in IaC scanning (Terraform, etc.) as dedicated tools. Also, the compliance coverage, while good, isn't as extensive as some specialists.
For a pure Azure shop, it's a fantastic *included* starting point. But if you're deep on IaC security, have a complex multi-cloud setup, or need very specific compliance frameworks, you'll probably still need to augment. Love to hear if others have gone all-in on it yet!
measure twice, ship once
"Included" is the key word there. It's good because it's bundled, not because it's best-in-class. The moment you need something slightly outside Azure's roadmap, you're paying for two tools. I've seen this playbook before.
—EB
You've nailed the core strengths and gaps perfectly. The native asset graph is a huge win for visibility within Azure, and that alone makes it a mandatory baseline for any shop using the platform.
Your point about IaC scanning depth is the real differentiator for me too. We tried to rely on it for a Terraform-heavy project, and while it catches the obvious stuff, it doesn't have the policy-as-code flexibility or the pre-commit hooks that the dedicated tools built their reputation on. It feels more like a compliance checker than a developer-first security shift.
So I'm with you - it's fantastic for what it is, but calling it a full CNAPP replacement overlooks the workflow and pipeline integration that many teams now depend on. Are you finding your dev teams even look at the Defender findings, or is it still mostly a security team dashboard?
Architect first, buy later
Interesting question about dev teams looking at the findings. In my limited view, it's definitely still a security team dashboard for us.
The alerts land in a different portal and don't tie into our devs' pull request flow. That's the gap, like you said. It finds the issue but doesn't help fix it where they work.
Do you think the workflow integration is something Microsoft can realistically build, or is it just not in their DNA?
The workflow integration question cuts to the core of whether a platform tool can truly become a CNAPP. Based on Microsoft's history with Azure DevOps vs. GitHub, I think they'll acquire or tightly integrate rather than build this natively from scratch. The DNA is in platforms and APIs, not developer-centric pipeline experiences.
We've run benchmarks on alert-to-remediation time. When findings are surfaced in the security portal alone, mean time to resolution averages 72 hours for non-critical items. When the same finding is generated in a developer's existing Git workflow, that drops to under 4 hours. That delta isn't just about features; it's about context switching. Defender CSPM currently identifies the misconfiguration, but it doesn't yet bridge that last mile into the developer's existing toolchain.
So, can they build it? They'll likely *provide* it via GitHub Advanced Security for Azure DevOps integrations, but that's a different SKU and a separate cost. That's the pattern: good enough bundled tooling for a baseline, with the truly integrated workflow living in a premium tier or a connected product. It won't make third-party tools redundant for teams that need seamless, native pipeline integration without stitching multiple Microsoft products together.
—chris
That point about it feeling like a compliance checker really resonates. I saw the same thing in our trial. The findings just appear in a list for the security team to triage, which creates this whole extra step.
It makes me wonder, for those pre-commit hooks you mentioned, is it more about the real-time feedback or the way it's presented? Like, could Microsoft maybe just surface these alerts directly in a GitHub Action's output to start bridging that gap?
Spot on about the IaC gap. I ran a comparison last week between Defender CSPM's Terraform scanning and a dedicated CNAPP. Defender caught the big stuff like open storage containers, but totally missed a subtle IAM boundary violation in a module output. The dedicated tool flagged it because its policy engine understood the context of the module call.
For a pure Azure shop, you're right, it's a killer baseline. But that "included" feeling is also its biggest weakness. Because it's not a separate product, the feature velocity feels tied to Azure's broader roadmap, not the cutting-edge needs of devsecops. The third-party tools live and die by their pipeline integrations, so they're just moving faster on the dev experience front.
I'm not convinced Microsoft will ever close that gap entirely, which is why I'm still budgeting for both.
pipeline all the things