Assign regulatory compliance standards in Microsoft Defender for Cloud
In brief
The article now explicitly covers assigning standards to Azure subscriptions, AWS accounts, and GCP projects, reviewing compliance assessments, and checking prerequisites. It also clarifies where the enabled standard appears in the Regulatory compliance dashboard.
What Defender admins need to know
Administrators can use the expanded guidance when assigning standards across supported cloud scopes; no action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Assign regulatory compliance standards in Microsoft Defender for Cloud
This article shows how to assign regulatory compliance standards to supported scopes in Microsoft Defender for Cloud and review the resulting compliance assessments.
In Microsoft Defender for Cloud, regulatory compliance standards use Azure Policy initiatives. Defender for Cloud evaluates these standards in the Regulatory compliance dashboard.
You can assign regulatory compliance standards to specific scopes such as Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects.
Prerequisites
Before you assign a standard, make sure you meet the following prerequisites:
To access compliance standards in Defender for Cloud, onboard any Defender for Cloud plan, except Defender for Servers Plan 1 or Defender for API Plan 1.
You need
OwnerorPolicy Contributorpermissions to add a standard.If any information is needed to enable the standard, the Set parameters page appears for you to type in the information.
The selected standard appears in the Regulatory compliance dashboard as enabled for the subscription
itwhere the standard wasenabled on.enabled.
Related content
@@ -1,15 +1,18 @@ --- title: Assign regulatory compliance standards in Microsoft Defender for Cloud-description: Learn how to assign regulatory compliance standards in Microsoft Defender for Cloud.-ms.date: 05/25/2026+description: Assign regulatory compliance standards to Azure subscriptions, AWS accounts, and GCP projects in Defender for Cloud, and track compliance results in the Regulatory compliance dashboard.+ms.date: 07/03/2026 ms.topic: how-to+ms.custom: msecd-doc-authoring-1013 #customer intent: As a security administrator, I want to assign regulatory compliance standards in Microsoft Defender for Cloud so that I can evaluate compliance across selected scopes. ai-usage: ai-assisted --- # Assign regulatory compliance standards in Microsoft Defender for Cloud -In Microsoft Defender for Cloud, regulatory compliance standards use Azure Policy initiatives. Defender for Cloud evaluates these standards in the Regulatory compliance dashboard.+This article shows how to assign regulatory compliance standards to supported scopes in Microsoft Defender for Cloud and review the resulting compliance assessments.++In Defender for Cloud, regulatory compliance standards use Azure Policy initiatives. Defender for Cloud evaluates these standards in the Regulatory compliance dashboard. You can assign regulatory compliance standards to specific scopes such as Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. @@ -17,6 +20,8 @@ Defender for Cloud continually assesses the selected scope against each standard ## Prerequisites +Before you assign a standard, make sure you meet the following prerequisites:+ - To access compliance standards in Defender for Cloud, onboard any Defender for Cloud plan, except Defender for Servers Plan 1 or Defender for API Plan 1. - You need `Owner` or `Policy Contributor` permissions to add a standard. @@ -42,7 +47,7 @@ If you assign a regulatory standard but have no relevant assessed resources, the If any information is needed to enable the standard, the **Set parameters** page appears for you to type in the information. - The selected standard appears in the **Regulatory compliance** dashboard as enabled for the subscription it was enabled on.+ The selected standard appears in the **Regulatory compliance** dashboard as enabled for the subscription where the standard was enabled. ## Related content 