Microsoft Defender for Cloud
Cloud and workloads

Map Infrastructure as Code templates from code to cloud

In brief

Updated the page date and authoring metadata, clarified the Azure account and Cloud Security Explorer instructions, and renamed the sample template link.

What Defender admins need to know

No configuration or migration is required; administrators may find the setup and navigation guidance clearer.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Map Infrastructure as Code templates to cloud resources

Mapping Infrastructure as Code (IaC) templates to cloud resources helps you ensure consistent, secure, and auditable infrastructure provisioning. It supports rapid response to security threats and a security-by-design approach. You can use mapping to discover misconfigurations in runtime resources. Then, remediate at the template level to help ensure noprevent drift between the IaC templates and deployed cloud resources and to help deployment viasupport CI/CD methodology.deployments.

Prerequisites

To set Microsoft Defender for Cloud to map IaC templates to cloud resources, you need:

See the mapping between your IaC template and your cloud resources

To see the mapping between your IaC template and your cloud resources on the Cloud Security Explorer page in Cloud Security Explorer:Defender for Cloud:

  1. Sign in to the Azure portal.

  2. In your repository, add an IaC template that includes tags.

    You can start with aan IaC mapping sample template.

  3. To commit directly to the main branch or create a new branch for this commit, select Save.