Azure cloud security benchmark in Defender for Cloud

Important

Attention: All Microsoft Defender for Cloud features will be officially retired in Azure in China region on August 18, 2026 per the announcement posted by 21Vianet.

Microsoft Defender for Cloud presents industry standards, regulatory standards, and benchmarks as security standards. These standards are assigned to scopes such as Azure subscriptions, and are assessed continuously in the Regulatory compliance dashboard.

When Defender for Cloud is enabled, the Microsoft Cloud Security Benchmark (MCSB) automatically starts assessing resources in scope. This benchmark builds on the cloud security principles defined by the Azure Security Benchmark and applies these principles with detailed technical implementation guidance for Azure, for other cloud providers, and for other Azure clouds.

MCSB v2 (preview) is also available and can be enabled from the Regulatory compliance dashboard. This version introduces expanded guidance with additional risk-based controls, expanded Azure Policy mappings, and coverage for emerging workloads such as artificial intelligence (AI).

Image that shows the components that make up the Azure cloud security benchmark.

The compliance dashboard provides a dedicated benchmark view to help you monitor resource compliance against benchmark controls. Non-Azure platforms follow the same cloud-neutral security principles as Azure. Each control provides a consistent level of technical implementation guidance across Azure and other cloud resources.

Screenshot of a sample regulatory compliance page in Defender for Cloud.

From the compliance dashboard, you're able to manage all of your compliance requirements for your cloud deployments, including automatic, manual, and shared responsibilities.

Note

Shared responsibilities is only compatible with Azure.

Next steps