Microsoft Defender for Cloud
Cloud and workloads

Assign regulatory compliance standards in Microsoft Defender for Cloud

In brief

The article now explicitly covers assigning standards to Azure subscriptions, AWS accounts, and GCP projects, reviewing compliance assessments, and checking prerequisites. It also clarifies where the enabled standard appears in the Regulatory compliance dashboard.

What Defender admins need to know

Administrators can use the expanded guidance when assigning standards across supported cloud scopes; no action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Assign regulatory compliance standards in Microsoft Defender for Cloud

This article shows how to assign regulatory compliance standards to supported scopes in Microsoft Defender for Cloud and review the resulting compliance assessments.

In Microsoft Defender for Cloud, regulatory compliance standards use Azure Policy initiatives. Defender for Cloud evaluates these standards in the Regulatory compliance dashboard.

You can assign regulatory compliance standards to specific scopes such as Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects.

Prerequisites

Before you assign a standard, make sure you meet the following prerequisites:

  • To access compliance standards in Defender for Cloud, onboard any Defender for Cloud plan, except Defender for Servers Plan 1 or Defender for API Plan 1.

  • You need Owner or Policy Contributor permissions to add a standard.

    If any information is needed to enable the standard, the Set parameters page appears for you to type in the information.

    The selected standard appears in the Regulatory compliance dashboard as enabled for the subscription itwhere the standard was enabled on.enabled.

Related content