Microsoft Defender for Cloud
Cloud and workloads

What is Serverless protection?

In brief

The documentation states that stale recommendations will be removed starting August 18 and adds instructions for enabling Serverless protection for Azure subscriptions and connected AWS accounts through Defender CSPM.

What Defender admins need to know

Enable the Serverless protection toggle for each environment requiring coverage to avoid potential secure score impact and maintain serverless coverage.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Serverless protection requirements and availability

Serverless protection is available as part of the Defender cloud security posture management (Defender CSPM) plan

Serverless protection is available as part of the Defender cloud security posture management (Defender CSPM) plan.

To enable serverless protection, you must enable the Defender CSPM plan on your subscription and enable the Serverless protection component of that plan. Defender for Cloud extends its CSPM capabilities to serverless workloads by providing continuous visibility and risk assessment with the following features:

  • Automatic resource discovery: Detects all serverless resources (Azure Functions, Web Apps, AWS Lambda) and lists them in a unified inventory.

  • Continuous posture assessment: Evaluates configurations for risks like public endpoints, weak authentication, and missing encryption.

  • Misconfiguration detection: Highlights risks in:

    • Access control: Restricts network exposure and enforces authentication.
    • Identity and permissions: Helps prevent lateral movement, data exfiltration, and privilege abuse.
    • Code integrity: Helps protect against unauthorized code changes, such as AWS Lambda code signing bypass risks.
  • Vulnerability assessment: Scans function packages for vulnerable dependencies and provides remediation guidance.

  • Attack path analysis: Maps potential attack chains that involve serverless resources so you can prioritize high-risk issues.

Defender for Cloud uses these features to help organizations secure serverless workloads in dynamic cloud environments.

After Defender for Cloud discovers the resources, it continuously monitors their configurations and runtime environments. It evaluates these resources against a set of security best practices and compliance standards to identify misconfigurations, vulnerabilities, and insecure dependencies. When it detects a risk, Defender for Cloud generates security recommendations with detailed remediation steps to help you address the issues.

Enable Serverless protection for your environment

Use the following steps to enable Serverless protection for each environment. You need the appropriate permissions to change Defender CSPM settings.

Azure

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

  3. Select the Azure subscription where you want to enable Serverless protection.

  4. Select Defender CSPM and turn on the Serverless protection toggle.

    :::image type="content" source="media/serverless-protection/enable-serverless-protection-azure.png" alt-text="Screenshot that shows the Serverless protection component turned on in the Defender CSPM plan settings for an Azure subscription." lightbox="media/serverless-protection/enable-serverless-protection-azure.png":::

  5. Select Save and close.

Repeat these steps for each Azure subscription that requires serverless coverage.

AWS

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Environment settings.

  3. Select the connected AWS account where you want to enable Serverless protection.

  4. Select Defender CSPM and turn on the Serverless protection toggle.

    :::image type="content" source="media/serverless-protection/enable-serverless-protection-aws.png" alt-text="Screenshot that shows the Serverless protection component turned on in the Defender CSPM plan configuration for a connected AWS account." lightbox="media/serverless-protection/enable-serverless-protection-aws.png":::

  5. Select Save and close.

Repeat these steps for each connected AWS account that requires serverless coverage.

Inventory

Defender for Cloud provides a unified inventory of all discovered serverless resources, so you can easily view and manage them. The inventory page includes details such as resource names, types, locations, and associated security findings. Simply filter the results based on resource type to focus on Web Apps, Azure Functions, or AWS Lambda functions.

After you filter your results, select a resource to view details about its security posture, including active security recommendations and their severity levels.

:::image type="content" source="media/serverless-protection/resource-health.png" alt-text="Resource details page for a serverless workload showing security health, active recommendations, and severity information." lightbox="media/serverless-protection/resource-health.png":::


You can also review the security recommendations associated with each resource to prioritize remediation based on finding severity.

Learn how to remediate security recommendations. Serverless resources that aren't eligible for vulnerability assessment include: