Defender for Cloud's Free CSPM Is Becoming Opt-In: What to Do Before October 27
From October 27, 2026, new Azure subscriptions start without Foundational CSPM. What changes, who is exposed, and the four steps to take before the date.
Techrupt Team5 min read

From October 27, 2026, new Azure subscriptions no longer get Foundational CSPM, the free posture plan in Microsoft Defender for Cloud, turned on by default. A subscription created after that date has no secure score and no security recommendations until someone enables the plan. Existing subscriptions keep their current setting, and the plan stays free.
The change is small on paper and easy to miss in practice. The subscriptions most likely to be created after October 27 are the ones application teams request for new projects, and those are exactly the subscriptions nobody on the security team is watching yet. If your landing zone relies on Defender for Cloud being on by default, it needs one change before the date.
What changes on October 27
Microsoft announced the change in the Defender for Cloud release notes on July 30, 2026, as part of moving posture management into the Microsoft Defender portal.
| Before October 27 | From October 27 | |
|---|---|---|
| New Azure subscription | Foundational CSPM on by default | Foundational CSPM off until enabled |
| Existing Azure subscription | Unchanged | Unchanged, unless someone turns the plan off |
| AWS and GCP connectors | On by default when onboarded | Still on by default |
| Price of Foundational CSPM | Free | Free |
| Recommended management experience | Azure portal | Microsoft Defender portal |
Foundational CSPM is what gives you the Microsoft cloud security benchmark assessment, security recommendations, secure score, asset inventory and workflow automation. Without it, a new subscription can hold a storage account open to the internet or a VM with management ports exposed, and nothing in Defender for Cloud will say so.
Who is exposed
Any organization that creates Azure subscriptions after October 27. In practice, three patterns carry most of the risk.
Subscription vending. If new subscriptions are created through a pipeline or a request form, that process now has to switch the plan on. Nothing about the vending process fails, so nobody notices.
Sandbox and project subscriptions. Development teams often get short-lived subscriptions with looser guardrails. These are where public endpoints and test credentials tend to appear, and they would now be invisible to posture reporting.
Mergers and new business units. A new tenant or a new enrollment brings a batch of fresh subscriptions at once.
What we see in our security assessments is that posture gaps rarely come from missing tools. They come from resources nobody knew were in scope. A subscription with no secure score is one of those. It doesn’t show up as a bad score. It doesn’t show up at all.
Four things to do before October 27
1. Know which subscriptions you have and how they get created
List every subscription, and write down every path that creates a new one: the landing zone vending process, the enterprise agreement or Microsoft Customer Agreement portal, and anyone with rights to create subscriptions directly. The paths you don’t control are the ones to close or monitor.
This is also a good moment to check that every existing subscription sits under a management group. A subscription outside the hierarchy won’t inherit the policy in the next step. We cover the management group structure in your first 30 days with a landing zone partner.
2. Enable Defender for Cloud through policy, not by hand
Microsoft’s documented way to cover every subscription in a management group is Azure Policy. Register the resource provider at the management group scope first:
az provider register --namespace Microsoft.Security --management-group-id <management-group-id>
Then assign the built-in definition Enable Microsoft Defender for Cloud on your subscription at the top management group, and create a remediation task so existing subscriptions are brought into line. Every new subscription placed under that management group is then evaluated automatically.
Microsoft has said more guidance on the transition will be published closer to the date. Until it is, don’t assume an existing assignment turns on the new opt-in plan. Treat step 4 as the proof.
3. Decide where your team will manage posture
From October 27, Microsoft recommends the Microsoft Defender portal for managing Azure posture, with Defender plans, posture policies and recommendations in one place alongside the rest of Microsoft’s security tools. You can keep managing plans in the Azure portal.
For most mid-sized organizations the Defender portal is the better long-term choice, because Microsoft Sentinel is also leaving the Azure portal after March 31, 2027. Moving posture and incident work into one console in the same planning cycle is less disruptive than two separate migrations. If your runbooks, training or automation point at Azure portal screens, list them now.
4. Test it with a real subscription after October 27
Create a new test subscription after the change lands, place it in the right management group, and confirm within a day that Foundational CSPM is on, recommendations are appearing and the secure score is populated. Then delete the subscription. It takes an hour and it is the only way to know the vending process works, rather than assuming it does.
Is the paid Defender CSPM plan worth it?
The free plan tells you what is misconfigured. The paid Defender CSPM plan adds attack path analysis, the cloud security explorer, agentless scanning of VMs for vulnerabilities and secrets, and posture management for AI and API workloads. Billing is per protected resource, and only certain resource types count, such as VMs, storage accounts, SQL servers and, since this year, Function Apps and Container Apps when those components are enabled.
In our experience, the paid plan pays for itself when you have internet-facing workloads and a team that will act on attack paths. If nobody works through the free recommendations today, start there. Paying for more findings doesn’t fix a backlog.
Where to start
Check how your subscriptions are created, add the policy assignment and plan the test for the week of October 27. If you want to know what else a free-plan gap might be hiding, our Practical Guide to Azure Cloud Security Posture walks through the eight areas we review in an assessment, with checklists for each. The related governance work is covered in reducing AI agent permission risk with Entra Agent ID, since agent identities are now part of the same posture picture.
Techrupt’s Azure security consulting team can review your landing zone and subscription vending before the deadline. Book a consultation and we’ll look at it with you.



