Microsoft Defender for Cloud
Cloud and workloads

Protect your applications with Microsoft Defender for App Service

In brief

The page date was updated to 07/03/2026, an authoring tag was added, and wording was revised to clarify that a single host cannot easily identify distributed attacks across multiple hosts.

What Defender admins need to know

Administrators can refer to the revised explanation; no action is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Protect your applications with Microsoft Defender for App Service

Microsoft Defender for App Service uses cloud scale to identify attacks that target applications running on Azure App Service. Requests to Azure applications pass through gateways that inspect and log traffic before routing it to your environment. ThisThe logged traffic data helps identify exploits and attackers, and it helps learn new patterns.

When you enable Defender for App Service, you get these capabilities:

  • The underlying sandboxes and VMs.
  • App Service internal logs - available because of the visibility that Azure has as a cloud provider.

As a cloud-native solution, Defender for App Service can identify attack methods that apply to multiple targets. From a single host, ita single host can's hard tot easily identify a distributed attack from a small subset of Internet Protocol (IP) addresses that crawl similar endpoints across multiple hosts.

Together, the log data and infrastructure can show the full attack story, from a new attack in the wild to compromises on customer machines. Even if you deploy Microsoft Defender for App Service after a web app is exploited, it might still detect ongoing attacks.