Design security solutions for infrastructure
Hybrid and Multicloud Posture Management
CoreCreate one risk-prioritized posture and workload-protection program across Azure, other clouds, and on-premises resources using Defender for Cloud, Azure Arc, EASM, and Exposure Management.
Aligned to SC-100 skills measured as of October 21, 2026; candidates testing earlier should review the transition note in the lane overview.
Why this matters
Posture findings differ in impact. Architects must connect configuration baselines, workload threats, asset context, external exposure, identity paths, and business criticality so teams fix the issues most likely to reach important assets.
Must Know
- Defender for Cloud CSPM evaluates cloud configuration and risk context, while Defender plans add workload-specific threat protection for selected resource types.
- MCSB supplies a foundational control benchmark; cloud secure score summarizes posture evidence but must be interpreted with asset criticality and risk context.
- Azure Arc projects supported non-Azure servers and Kubernetes resources into Azure management so policy, inventory, monitoring, and security services can apply consistently.
- Defender EASM discovers internet-facing assets from an outside-in perspective, including unknown or unmanaged exposure that internal inventories may miss.
- Exposure Management attack paths join vulnerabilities, identities, reachability, data sensitivity, and critical assets to prioritize choke points over isolated findings.
- A posture process needs authoritative inventory, owners, service-level objectives, exception handling, verification, executive initiatives, and continuous improvement.
Compare and Distinguish
- CSPM identifies and prioritizes posture risk; cloud workload protection detects threats against running workloads.
- Azure Arc provides inside-out onboarding and governance for known resources, whereas Defender EASM performs outside-in discovery of the external attack surface.
Scenario examples
- Scenario: The security team has thousands of equal-severity findings but limited remediation capacity. Think: prioritize exploitable attack paths to critical assets and assign choke-point remediation with business context.
- Scenario: Acquired datacenters and another cloud have inconsistent inventory. Think: connect cloud accounts, onboard supported resources with Arc, and use EASM to find public assets missing from internal records.
Exam traps
- Improving secure score by closing easy findings can leave a critical attack path unchanged.
- Enabling one Defender plan does not provide every workload protection capability for every resource type.
Key takeaways
- CSPM identifies configuration risk; workload plans add resource-specific threat detection.
- Arc projects known hybrid assets into management while EASM searches for unknown exposure.
- Secure Score orders work poorly when an attack path supplies stronger risk context.
How it works
- Cloud connectors and Arc feed resource context into posture assessment, while Defender plans generate workload detections and protections.
- The security graph correlates exposures and privileges into attack paths, allowing initiatives and owners to focus on material risk.
Objects and administrative surfaces
- Defender for Cloud connectors, environment settings, standards, recommendations, secure score, Defender plans, attack paths, and governance rules.
- Arc-enabled resources, EASM inventories, exposure initiatives, critical-asset labels, remediation owners, and exception records.
When to use it
- Use an integrated posture program when estate boundaries span tenants, clouds, datacenters, and ungoverned internet assets.
Security and governance implications
- Establish enterprise risk thresholds and initiatives while delegating remediation to resource owners with verified closure evidence.
Troubleshooting signals
- If multicloud findings are incomplete, check connector permissions, plan coverage, inventory scope, and onboarding health.
- If attack paths persist after a fix, allow graph refresh time and confirm every recommended break point, not only one low-impact issue.
More detail
- Evaluate MCSB and secure-score evidence in Defender for Cloud.
- Select the correct Defender workload-protection plans.
- Integrate Arc, EASM, and Exposure Management into a governed remediation process.
Ready for the quiz?
- When is an attack path more useful than a flat recommendation list?
- Which problem is solved by Arc instead of EASM?
- How should a business-critical label influence remediation order?
Related objectives
- D3.1.S1 — Evaluate security posture by using Microsoft Defender for Cloud, including the Microsoft Cloud Security Benchmark (MCSB)
- D3.1.S2 — Evaluate security posture by using Microsoft Secure Score
- D3.1.S3 — Design integrated security posture management solutions that include Microsoft Defender for Cloud in hybrid and multi-cloud environments
- D3.1.S4 — Select cloud workload protection solutions in Microsoft Defender for Cloud
- D3.1.S5 — Design a solution for integrating hybrid and multicloud environments by using Azure Arc
- D3.1.S6 — Design a solution for Microsoft Defender External Attack Surface Management (Defender EASM)
- D3.1.S7 — Specify requirements and priorities for a posture management process that uses Microsoft Security Exposure Management attack paths, attack surface reduction, security insights, and initiatives