Microsoft Defender for Cloud
Vulnerabilities and exposure

Cloud overview dashboard in Microsoft Defender for Cloud

In brief

The article adds navigation anchors, renames section headings, clarifies dashboard section and graph descriptions, and adds links to related cloud security resources and Azure portal guidance.

What Defender admins need to know

Administrators can find dashboard guidance and related resources more easily.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

::: zone pivot="defender-portal"

Cloud overview dashboard in the Defender portal

The Cloud Overview dashboard is the landing page for Microsoft Defender for Cloud in the unified security portal (Defender portal). It gives security teams a clear view of cloud security status before and after a breach. Use it to prioritize work, track progress over time, and take action quickly. You can review data at tenant level or by selected scope.

  1. Sign in to the Defender portal.
  2. Go to Cloud security > Overview

TopFilter the dashboard with top controls

At the top of the dashboard, you find key filters:

:::image type="content" source="media/defender-portal-dashboard/top-controls.png" alt-text="Screenshot of filters on cloud overview dashboard.":::

DashboardUnderstand the dashboard sections

The dashboard is organized into the following sections, each highlighting a different aspect of your security posture.

Security at a glance

ThisThe Security at a glance section gives you a quick snapshot of your current security status:

  • Cloud Secure Score (preview): Your overall cloud security risk score with a trend indicator.
  • Threat Protection: Number of alerts by severity.

Top Actions

ThisThe Top Actions section helps you decide where to start. ItThe Top Actions section guides next steps that reduce attack surface efficiently. ItThe Top Actions section highlights:

Critical Recommendations: Help you focus on the most critical recommendations found in your environment. High-Severity Incidents: Investigate active alerts.

:::image type="content" source="media/defender-portal-dashboard/threat-detection.png" alt-text="Screenshot of cloud overview dashboard threat detection trends.":::

Each graph updatesThe Security Posture and Threat Detection graphs update daily and reflectsreflect the selected time range. Hover over data points to see daily breakdowns.

Workload Insights

Each tile in thisthe Workload Insights section surfaces insights from Microsoft Cloud-native application protection platform (CNAPP).

Workloads include:

Next steps

Use the following resources to continue exploring and configuring your cloud security environment:

::: zone pivot="azure-portal"

Overview dashboard in the Azure portal

Microsoft Defender for Cloud gives a unified view of the security posture of hybrid cloud workloads with the interactive Overview dashboard. Select any element on the dashboard to get more information.

:::image type="content" source="./media/overview-page/overview-07-2023.png" alt-text="Screenshot of Defender for Cloud's overview page." lightbox="./media/overview-page/overview-07-2023.png":::

MetricsView metrics on the dashboard

The top menu bar offers:

:::image type="content" source="./media/overview-page/top-bar-of-overview-new.png" alt-text="Screenshot of Defender for Cloud's overview page's top bar." lightbox="media/overview-page/top-bar-of-overview-new.png":::

FeatureExplore the feature tiles

The center of the page displaysshows the feature tiles, each linkingtiles. Each tile links to a high-profilekey feature or a dedicated dashboard:

  • Security posture - Defender for Cloud continually assesses your resources, subscriptions, and organization for security issues. It aggregates findings into one score so you can quickly evaluate current risk: the higher the score, the lower the identified risk level. For details, see Secure Score and security controls.
  • Workload protections - The cloud workload protection platform (CWPP) in Defender for Cloud provides advanced protection for workloads on Azure, on-premises machines, and other cloud providers. Each resource type has a related Microsoft Defender plan. The tile shows coverage for connected resources in selected subscriptions and recent alerts by severity. For plan details, see Defender plans and CWPP coverage.
  • Regulatory compliance - Defender for Cloud continuously assesses hybrid and multicloud resources and maps findings to supported compliance standards. This mapping helps you track compliance status against the standards that matter to your organization. For guidance, see Regulatory compliance dashboard.
  • Inventory - Asset inventory gives you a unified view of the security posture for connected resources. It includes resources with unresolved recommendations. If you enable integration with Microsoft Defender for Endpoint and Microsoft Defender for Servers, you also get software inventory. The overview tile shows healthy and unhealthy resource counts for selected subscriptions. To explore this view, see Asset inventory in Defender for Cloud.

InsightsReview dashboard insights

The Insights pane offers customized items for your environment including:

Next steps

For related tasks and follow-up guidance, see the following articles: