Azure Security Assessment

Microsoft secures the cloud. What you put in it is on you.

Azure estates drift by default: resources deployed outside the baseline, “temporary” exceptions never reverted, access never removed. A senior engineer maps the few paths an attacker would actually take through yours - not a 400-item recommendation dump.

Attack-path assessed, not Secure Score printed Microsoft-native: no CNAPP platform to buy Read-only, no changes to resources Sized by estate, quoted before we start
A Falconer engineer tracing an Azure architecture diagram on a large screen
Why now

You are probably here because…

Cloud misconfiguration is self-inflicted by definition - which means it is also fixable by definition.

The assumption
"It’s Azure - Microsoft handles security"

Microsoft secures the platform. Your configuration in it is the shared-responsibility half nobody assigned.

Velocity
Engineers ship resources faster than anyone secures them

Every sprint adds VMs, storage, and roles. Nobody’s job is to look back.

Drift
The baseline was set two years ago

Exceptions, hotfixes, and "temporary" rules have been accumulating ever since.

The unknown
You cannot say what is internet-exposed right now

And the honest answer to "who has Owner?" is a shrug.

The audit
NIS2 or ISO evidence needs cloud controls

Documented and tested against a named benchmark - not assumed.

The bill
Defender for Cloud costs money and nobody tuned it

Plans on that do nothing, plans off that would matter. Both cost you.

99%

of cloud security failures are the customer’s side of the shared-responsibility model - configuration, not platform.

Gartner projection
44%

of organisations have already had a cloud data breach - with misconfiguration and human error the #1 root cause.

Thales Cloud Security Study 2024
The assessment question

The two or three paths from the internet to subscription owner

We don’t hand you 400 recommendations. We map which of your findings chain together into a breach an attacker would actually run - and put those first.

T+0
An exposed resource
An internet-facing VM, RDP open to 0.0.0.0/0. A "temporary" NSG rule from last year that nobody reverted.
Network review: NSG audit, JIT VM access, Bastion, private endpoints
T+2h
The workload falls
Password spray or an unpatched service. No endpoint plan, no diagnostic settings - nothing notices.
Defender plans right-sized to the workload · logging that actually flows
T+3h
Its managed identity is harvested
Contributor on the whole subscription. One metadata request, one valid token - no alert fires.
RBAC least privilege · scoped role assignments · PIM for Azure roles
T+4h
Subscription-wide access
Storage, databases, Key Vault, all reachable. One NSG rule was the whole distance.
No control fires here

A Secure Score treats every finding as a line item. An attacker treats them as a route - we assess the route.

Scope

What we actually assess

Six planes of your Azure estate - IaaS, PaaS, containers, and serverless all in scope by default. This is infrastructure; the productivity tenant and Entra ID have their own assessments.

Access & privilege

01/06
  • Owner and Contributor sprawl across subscriptions
  • Standing privileged access vs PIM for Azure roles
  • Over-permissioned service principals and managed identities
  • Least privilege across management groups

Network

02/06
  • Public exposure inventory, resource by resource
  • Open management ports: RDP and SSH to the internet
  • NSG rules allowing 0.0.0.0/0
  • Private endpoints vs public, firewall and Bastion posture

Storage & data

03/06
  • Public blob access and anonymous containers
  • Secure transfer, encryption, soft delete
  • Database firewalls, TLS, auditing
  • Backup posture and immutability

Key Vault & secrets

04/06
  • RBAC data-plane model vs legacy access policies
  • Soft delete and purge protection
  • Deny-default firewall and private endpoints
  • Secret, key, and certificate expiry - and secrets in code

Compute & workloads

05/06
  • Disk encryption and JIT VM access
  • Endpoint protection coverage
  • AKS posture: API exposure, RBAC, policies
  • Functions and Container Apps configuration

Logging & governance

06/06
  • Activity Log diagnostic settings and retention
  • Agent coverage and log flow to Sentinel
  • Azure Policy guardrails and CIS initiatives
  • The compliance dashboard, actually configured
Before you buy anything

You probably don’t need a CNAPP platform.

The cloud-security market wants to sell you an enterprise posture platform. But Azure already ships its own: Defender for Cloud’s foundational posture, Secure Score, and the Microsoft Cloud Security Benchmark are free and already running in your tenant - most estates simply never look at them, and never tune the paid plans on top. We make what you own work first.

The honest cost nuance
  • Some protection genuinely costs money: Defender plans are priced per resource, per month. Part of the assessment is deciding which ones earn their keep at your size.
  • The paid Defender CSPM plan adds attack-path analysis and agentless scanning - useful, but our assessment does not depend on you buying it.
  • If your estate spans AWS or GCP, Defender for Cloud can extend there. We stay Azure-first and will say when multicloud coverage is worth the step.
Already on, freeSecure Score · MCSB · foundational CSPM
Costs per resourceDefender plans, per workload type
Third-party CNAPPEnterprise pricing, per resource
Our incentiveWe sell the fix, not a license
Anchored, not opinionated

Named benchmarks, mapped to EU regulation

An assessment is only as strong as what it measures against.

Microsoft Cloud Security Benchmark

The baseline

Microsoft’s own security baseline for Azure, auto-assessed by Defender for Cloud and cross-mapped to NIST, ISO 27001, CIS, and PCI. Our findings anchor here - named controls, not opinion.

Auto-assessed · expert-interpreted

CIS Azure Foundations Benchmark

Level 1 / Level 2

The independent hardening standard for Azure, evaluated through the regulatory compliance dashboard. Level 1 for every estate; Level 2 where your risk profile justifies the friction.

Configured in your tenant · evidence stays with you

Mapped to your regulations

NIS2 · ISO 27001 · GDPR

Every finding carries the compliance references your auditor and insurer ask about, so the report doubles as audit evidence - same format as our other assessments.

EU-first mapping · audit-ready
A Falconer engineer working through an Azure estate from a laptop in a quiet meeting room
Method & safety

Safe enough to run on a Tuesday morning

Same ground rules as every Falconer assessment. Your workloads never notice.

Read-only, always

Reader and Security Reader roles - no write access, no changes to resources, no impact on running workloads.

Access you control

Scoped role assignments you grant and can remove the day we finish. Every read is in your Activity Log.

Native tooling for breadth

Defender for Cloud recommendations, Resource Graph queries, and MCSB/CIS evaluation cover the whole estate.

Humans for the route

A senior engineer chains findings into attack paths and prioritises ruthlessly. The tooling finds 400 items; we tell you which three matter.

Days, not weeks

Collection is hours, analysis is days. Findings arrive while they are still true.

Your data stays yours

Evidence handled under GDPR, stored in the EU, deleted on the schedule we agree.

The deliverable

The three-reader report, plus four Azure artifacts

Same format as our other assessments: an executive summary for the board, remediation-ready findings for engineering, and compliance mapping for the auditor. Azure adds four artifacts of its own.

Secure Score baseline

Where you stand today and the realistic target, so progress is measurable - not a screenshot, a plan.

Prioritised findings

Every finding by severity, each with the fix - portal steps, CLI, or policy. The 400-item list, put in honest order.

Attack-path map

The two or three real chains from the internet to your subscriptions, drawn end to end with the break points.

Defender-plan right-sizing

A per-plan verdict for your estate: what to turn on, what to skip, and what it costs - so the bill matches the risk.

The four printed Azure artifacts on a desk: Secure Score baseline, prioritised findings, attack-path map and Defender plan
Four separable documents

Each artifact is written to be handed on alone - the Defender plan to whoever holds the budget, the attack-path map to your architects - without the rest of the report attached.

Every finding in them carries its own fix - portal steps, CLI, or Azure Policy - so an engineering team can work from the documents without us in the room.

Includes a 1:1 readout call. We walk the attack paths with your team, agree the fix order, and give the Defender-plan verdicts in plain numbers.
How this fits

Three assessments, three different planes

Different domains, different buyers, one report format. Doing two makes sense precisely because the planes connect.

The tenant
Microsoft 365 Security Assessment

The productivity estate: email, collaboration, data protection, posture. Explore the M365 assessment.

The directory
Identity & Access Assessment

Entra ID: who signs in, Conditional Access, privileged roles. The one link that matters here: a compromised Entra admin can grant themselves Owner across your subscriptions - the directory is the front door to the infrastructure. Explore the identity assessment.

This page
Azure infrastructure

Subscriptions, RBAC, network, storage, Key Vault, compute, logging. Run workloads in AWS or GCP too? Defender for Cloud can extend there - we stay Azure-first and scope multicloud honestly when asked.

After the report

From findings to protected

Find, fix, watch - and the report stands alone whichever parts you take.

Fix it yourselves
Every finding ships with the fix

Portal steps, CLI, or Azure Policy, per finding. Many engineering teams remediate in-house with the report alone.

We fix it
Scoped hardening

We close the attack paths and the top findings, stand up the policy guardrails, and hand the estate back measurably harder.

We keep watch
Azure won’t stay fixed

Posture is a snapshot of a thing that drifts. Managed Sentinel ingests your Activity logs and Defender for Cloud alerts; MDR watches the workloads around the clock. Explore Managed Sentinel and MDR.

FAQ

The questions Azure buyers ask

Isn’t Azure secure by default? Isn’t that Microsoft’s job?

Microsoft secures the platform: the datacenters, the hypervisors, the physical network. Everything you deploy on it - access, network rules, storage exposure, secrets - is your side of the shared-responsibility model. Industry analysis consistently attributes the overwhelming majority of cloud security failures to customer configuration, not the platform.

What exactly do you check?

Six planes: access and privilege (RBAC, PIM, service principals), network exposure, storage and data, Key Vault and secrets, compute and workloads (VMs, AKS, serverless), and logging and governance. All workload types are in scope by default; the scope section above lists the specific checks.

Do you need write access to our environment?

No. Reader and Security Reader roles only - read-only by design, granted by you, removable by you the day we finish. Every read we make lands in your Activity Log.

How is this different from just reading our Secure Score?

Secure Score treats every finding as an independent line item. An attacker treats your findings as a route. The value of the assessment is the correlation: which of your 400 recommendations chain together into the two or three real paths from the internet to subscription owner - and closing those first.

Do we need a tool like Wiz or Orca?

At SMB and mid-market scale, usually not. Defender for Cloud is the native posture platform - the foundational tier is free and already on - and it covers what a CNAPP is sold to cover for a single-cloud Azure estate. We make it work before anyone buys anything.

Which Defender for Cloud plans should we actually pay for?

That is a named deliverable: the Defender-plan right-sizing review. Plans are priced per resource, so the honest answer depends on your estate - which workloads face the internet, what the data is worth, what you already license. The report gives a per-plan verdict with the monthly cost next to the risk it buys down.

Do you cover AWS or GCP too?

We are Azure-first. Defender for Cloud can extend posture management to AWS and GCP, and if part of your estate lives there we will say honestly whether that extension is worth it - but this assessment, and our depth, is Azure.

How does this differ from the M365 and identity assessments?

Different planes. M365 covers the productivity tenant, identity covers Entra ID and who signs in, this covers the infrastructure your workloads run on. They connect - a compromised Entra admin can escalate into the Azure resource plane - which is exactly why they are assessed separately but designed to pair.

Do you map findings to NIS2 / ISO 27001 / GDPR?

Yes. Findings anchor to the Microsoft Cloud Security Benchmark and CIS Azure Foundations Benchmark, and every finding carries NIS2, ISO 27001, and GDPR references where relevant - so the report doubles as audit and insurance evidence.

Do you fix the findings, or just report them?

Your choice. Every finding ships with the fix, so your engineers can remediate in-house. If you want help, we offer scoped hardening - and because Azure drifts, the natural next step for many is continuous monitoring through Managed Sentinel and MDR.

How long does it take, and what does it cost?

Days, not weeks: collection is hours, expert analysis takes a few days. It is a fixed-fee engagement sized by your estate - subscriptions, resource count, workload mix - and quoted before we start.

Contact

Tell us what you’re dealing with

A Microsoft security specialist reads every message and replies, usually within one business day. Whether you need monitoring, help with a specific tool, or just have a question, start here.

New to this? Ask about a free Microsoft security review as a starting point.

What we can help with
  • Managed detection and response
  • Microsoft Sentinel engineering
  • Identity and email security
  • A free Microsoft security review
1You send a message
2A specialist replies within a business day
3We set up a call to scope what you need

"*" indicates required fields

This field is for validation purposes and should be left unchanged.