Automate evidence from Microsoft Defender for Cloud for threat protection, vulnerability assessment, security posture management, and compliance monitoring. Achieve SOC 2, ISO 27001, and PCI-DSS compliance.
Continuous evidence collection from Microsoft Defender for Cloud with zero manual exports
Simple service principal connection with read-only access
In Azure Active Directory, create an app registration with Security Reader role. Grant permissions for Microsoft.Security provider with read-only access.
Select which Azure subscriptions to monitor for Defender alerts, recommendations, and secure scores. Enable multi-subscription collection for comprehensive coverage.
LowerPlane verifies access and begins collecting security alerts and posture data. Historical alerts up to 90 days are imported automatically.
LowerPlane uses read-only Azure RBAC access and cannot modify Defender settings, dismiss alerts, or change security policies. Service principals are configured with least privilege and you can revoke access at any time from Azure Portal.
Real-time threat protection and security posture evidence mapped directly to compliance controls
| Control | Evidence Type | Service | Frequency |
|---|---|---|---|
Threat DetectionSOC 2 | Security alerts & incidents | Defender Alerts | Real-time |
Security PostureISO 27001 | Secure score & recommendations | Security Center | Continuous |
Vulnerability ManagementPCI-DSS | Vulnerability assessments | Vulnerability Scanner | Daily |
Container SecuritySOC 2 | Container image scan results | Defender for Containers | Real-time |
Database SecurityHIPAA | SQL vulnerability findings | Defender for SQL | Continuous |
Compliance MonitoringISO 27001 | Regulatory compliance assessments | Compliance Dashboard | Daily |
Network ProtectionPCI-DSS | Network security recommendations | Network Security | Continuous |
Attack DetectionSOC 2 | Attack path analysis | Attack Path | Real-time |
Collecting evidence from all Microsoft Defender for Cloud features
View complete evidence mappingAzure Defender integration satisfies threat protection and security posture controls across multiple compliance frameworks
Azure Defender integration covers 24 out of 64 SOC 2 controls, focusing on Security, Availability, and Monitoring criteria for cloud workload protection.
Microsoft Defender for Cloud is essential for Azure compliance
"Our ISO 27001 auditors needed comprehensive evidence of our cloud security posture. The Azure Defender integration automatically documented our secure scores, vulnerability assessments, and threat detections. Saved us 35+ hours during our certification audit."
Everything you need to know about Azure Defender integration
Still have questions?
Contact our security teamBuild comprehensive Azure security and monitoring operations
Connect Microsoft Defender for Cloud in 2 minutes and start collecting security evidence automatically
No credit card required • 14-day free trial • Setup in 2 minutes