Foundational CSPM will switch to an opt-in model on October 27, 2026, for new subscriptions Azure
With a subscription Azure created on or after October 27, 2026, Defender for Cloud no longer automatically activates its free plan, Foundational CSPM. Existing subscriptions retain their settings; AWS and GCP are not affected. The subscription creation workflow must activate the plan to receive recommendations and Secure Score.
Starting October 27, 2026, Foundational CSPM— Microsoft Defender 's free security posture management plan— Cloud, will no longer be enabled by default on new subscriptions Azure. A subscription created on or after that date will start with the plan disabled, and you must enable the plan on each new subscription to receive security recommendations and access Secure Score. Microsoft describes this shift to an opt-in model as a step in the transition of posture management to the Microsoft Defender portal, which will become the recommended experience for posture management on the same date Azure.
Existing subscriptions are not affected by the opt-in. A subscription with Foundational CSPM enabled remains that way, unless someone disables the plan, and AWS and GCP environments continue to receive Foundational CSPM by default upon onboarding. What changes is the starting point for each subscription created manually, via a script, or through a subscription vending pipeline.
| Location | Effective October 27, 2026 |
|---|---|
| New Subscription Azure | It starts with Foundational CSPM disabled; you must enable the plan on this subscription |
| Subscription Azure Existing | Retains its current Foundational CSPM configuration |
| AWS or GCP Environment | Not applicable; Foundational CSPM remains enabled by default at theonboarding |
| Cost of the Foundational CSPM | None; the plan remains free and can be activated at any time |
| Posture Management Azure | The Microsoft Defender portal is now the recommended experience |
Retrieved on September 29, 2026 from Microsoft documentation.

What's Included in Foundational CSPM, the Free Plan
Foundational CSPM assesses the security posture of resources and provides, among other things, security recommendations and the Secure Score, which are used to identify risks and prioritize remediation. When the plan is activated, the Microsoft Cloud Security Benchmark (MCSB) generates the recommendations, and the Secure Score is calculated based on a subset of them: the higher the score, the lower the identified risk level.
According to Azure, Microsoft’s comparison chart lists eight features for Foundational CSPM: asset inventory, data export, and reports by Azure Workbooks, the Microsoft Cloud Security Benchmark, the Secure Score, security recommendations, remediation tools, and the workflow automation. All eight are also included in Defender CSPM.
The plan also covers resources connected via Azure Arc: Foundational CSPM displays them in the inventory, assesses their security configuration, and incorporates them into the recommendations and the Secure Score.
What Defender CSPM adds, and what it charges for
Defender CSPM is the paid plan. The same table lists Azure, nineteen additional features, including attack path analysis, risk discovery with the Security Explorer, regulatory compliance assessments, large-scale remediation governance, agentless vulnerability and secret analysis for virtual machines, sensitive data discovery, AI security posture, and personalized recommendations.
Defender CSPM billing applies only to certain resources: Azure, virtual machines, groups of identical virtual machines, and classic VMs; storage accounts; SQL servers; Azure Database for PostgreSQL and MySQL Flexible server , and Synapse workspaces. The page excludes deallocated VMs, Databricks VMs, and storage accounts without blob containers or file shares. Two components are billed only once they are enabled: Serverless Protection, for Function Apps and Web Apps, and Serverless Containers, for Azure Container Apps and Azure Container Instances.
Even a single authorization detail matters in an automated workflow. An account with fewer permissions than the Subscription Owner can enable Defender CSPM, but the agentless scanner is not enabled by default because it lacks the necessary permissions. As a result, the attack path analysis and Security Explorer do not receive vulnerability reports.
A subscription created on or after October 27, 2026, starts with Foundational CSPM disabled
Before this change, enabling Defender for Cloud on a subscription was sufficient to obtain Foundational CSPM. The page describing this activation, updated on June 17, 2026, still states that once Defender for Cloud is enabled on the subscription, the core features are available, including the Foundational CSPM plan, recommendations, and the Secure Score. As of October 27, 2026, the page dedicated to the opt-in process states the opposite rule for new subscriptions: to use Foundational CSPM on a new subscription Azure, you must enable the plan for that subscription.
For an organization that creates subscriptions in bulk—whether through a landing zone or a subscription vending process—the consequence is immediate. A subscription created on or after this date will not have access to Foundational CSPM capabilities until the plan is activated. Until then, the subscription will not have access to the recommendations or the “ Secure Score ” provided by that plan.
Enable Foundational CSPM: Defender portal or portal Azure
The opt-in page offers two options. The first, which Microsoft recommends, involves integrating the environment Azure into the Microsoft Defender portal and then managing posture policies Azure and security recommendations there. The second option is to enable Foundational CSPM or another Defender plan in the portal Azureand continue managing posture there.
In the portal Azure, Microsoft documents the procedure for Defender CSPM: Microsoft Defender for Cloud > Environment settings, select the subscription, then, on the Defender plans page, toggle the plan to On and click Save. The coverage workbook, accessible via Azure Workbooks, then shows which plans are enabled for each subscription.
Azure Policy: What the definition “Enable Microsoft Defender for Cloud on your subscription" evaluates and deploys
To enable Defender for Cloud on all subscriptions in an administration group, Microsoft provides documentation on assigning the built-in definition Enable " Microsoft Defender " for Cloud on your subscription, indeed deployIfNotExists, at the administration group level. The prerequisite is that the resource provider be registered Microsoft.Security for this administration group. The assignment is made using Security Admin permissions, and a remediation task incorporates the existing subscriptions.
This definition flags subscriptions that have not yet been registered with Defender for Cloud, and marks all registered subscriptions as compliant, regardless of whether Defender plans are enabled for them. The description also states that to register newly created subscriptions, you must open the compliance tab, select the non-compliant assignment, and create a remediation task. Its setting pricingTier is worth free by default, and the setting can be changed to enable one or more Defender plans.
For the paid plan, the reference for the built-in definitions lists Configure Microsoft Defender CSPM to be enabled, indeed DeployIfNotExists, and Microsoft Defender CSPM should be enabled, in AuditIfNotExists.
Note: In the Definitions Reference Azure Policy, updated on June 17, 2026, the description of the two Defender CSPM definitions still lists the free posture capabilities as enabled by default in Defender for Cloud. The opt-in page, updated on July 30, 2026, states that Microsoft will release more information about the transition as October 27, 2026, approaches.
The Defender portal is now the recommended experience, with a " Secure Score " calculated differently
Starting October 27, 2026, the Microsoft Defender portal will become the recommended way to manage security posture Azure. The opt-in page states that you can centrally manage Defender plans, posture policies, Azure and security recommendations.
The older pages describe an intermediate state. The description of Defender for Cloud in the Defender portal, updated on June 17, 2026, indicates that customers with at least one paid plan have access to the viewing experiences, and that, in the initial phase—onboarding ing new customers, connecting environments, and configuring policies and settings—these tasks still begin in the portal Azure. A comparison of the two portals, updated on the same date, shows that Azure Workbooks, data export, automation workflow , and quick fixes are not available there, and that MCSB security policy management remains within Azure, with the Defender portal displaying only the results. Four of the eight Foundational CSPM features therefore remained exclusive to the portal Azure as of that date.
Secure Score s also vary from portal to portal. The Defender portal displays the Cloud Secure Score, risk-based model, which takes into account risk factors and the criticality of resources. The Azure retains the traditional “ Secure Score .” Microsoft notes that these are two entirely different models, with different calculations and values: a score tracked in a dashboard is not comparable across portals.
Our Reading
We would treat this change as a modification to the subscription creation workflow, not as a new feature in Defender for Cloud. The plan remains free, and existing subscriptions retain their configuration; however, a landing zone that relied on default activation will, starting October 27, 2026, generate subscriptions without Foundational CSPM, and this discrepancy may go unnoticed unless someone compares the list of subscriptions to the list of activated plans.
Nor would we assume that a policy Azure covers the new model. The definition “Enable Microsoft Defender for Cloud on your subscription” is documented to register the subscription with Defender for Cloud and enable its core features, and its description in the definition reference—updated on June 17, 2026—indicates that it identifies subscriptions that Defender for Cloud is not monitoring and protects them with its free features, without mentioning the opt-in. We would create a test subscription starting October 27, 2026, in the administration group where the policy is assigned, and we would verify in Environment settings and in the coverage workbook that Foundational CSPM is indeed enabled there, before trusting the chain.
When choosing a portal, we would use this portal Azure as a reference for subscriptions on the free tier only, until Microsoft releases the announced information regarding the transition: this is where the comparison of the two portals still included workbooks, export, workflow automation, and MCSB policy management. If the organization uses its “ Secure Score ” as a metric, we would note the value of the classic model before any transition to the Defender portal, since the two figures do not align.
The situation is similar to that of the three Azure Monitor due dates between August 31 and September 30, 2026: a behavior that the automation system took for granted has become a condition that must be explicitly specified.
What to Check
- Channels that create subscriptions Azure, landing zones, subscription vending, or scripts, and the step that will enable Foundational CSPM for every new subscription created on or after October 27, 2026.
- The assignments in the definition Enable " Microsoft Defender " for Cloud on your subscription, their administrative group scope, the value of the parameter
pricingTier, and the remediation tasks scheduled for newly created subscriptions. - The current status of Foundational CSPM for a trial subscription created on or after October 27, 2026, as shown in Environment settings and in the coverage workbook.
- Subscriptions where Defender CSPM is enabled by an account that is not the Subscription Owner, and the status of the agentless scanner on those subscriptions.
- The workbooks, exports, workflow automations, and quick fixes in use, which were specific to the portal Azure in the comparison updated on June 17, 2026.
- The " Secure Score " model used in internal reports, which is standard in the portal Azure or Cloud Secure Score in the Defender portal.
- Microsoft's opt-in page, which provides additional information about the transition as October 27, 2026, approaches.
Microsoft Sources
- Opt in to Foundational CSPM
- What is Cloud Security Posture Management (CSPM)
- What's new in Microsoft Defender for Cloud
- Protect your resources with Defender CSPM
- Enable Defender for Cloud on your Azure subscription
- Enable Defender for Cloud on multiple Azure subscriptions
- Azure Policy built-in definitions for Microsoft Defender for Cloud
- Overview of Defender for Cloud in the Defender portal
- Compare Azure Portal vs. Defender Portal Features
- Secure score in Defender for Cloud
What an article Can't Know
An article describes what applies to everyone. What varies from one organization to another is the inventory: which applications, which accounts, and which pieces of equipment are actually involved in your organization. The inventory determines the scope of the effort, and it cannot be summarized on a single page.
You'll be speaking directly with the engineers who will be doing the work, not with a middleman. We'll respond within 24 business hours.
Check what is still true
Announced dates are sometimes postponed, products are renamed, and conditions change. The blog tracks these topics over time: when a rule changes, a new post announces it.
Search for a topic in the blogIn the same issue
Three articles on the same topic. The blog has 145 articles, all of which are freely accessible.

