5.1.2. Workload Protection Plans and Multicloud Connectors
💡 First Principle: Defender for Cloud's protection isn't limited to Azure — connecting AWS and GCP environments extends the same posture visibility and, where configured, workload protection plans across your entire multicloud footprint, recognizing that most real organizations don't run in just one cloud.
Enabling and configuring Defender for Cloud workload protection plans covers turning on the specific plans relevant to your workloads — Defender for Servers, Storage, Databases, Containers, Key Vault, and AI Service, each covered in their respective domain sections of this guide. Connecting hybrid cloud and multicloud environments — specifically Amazon Web Services (AWS) and Google Cloud Platform (GCP) — extends CSPM findings and, depending on which plans are enabled on the connector, workload protection across a broader set of service types in those clouds, not solely virtual machine equivalents (EC2, Compute Engine).
⚠️ Exam Trap: An AWS or GCP connector's scope depends on which specific plans are enabled on that connector — assuming a connected multicloud account automatically gets the same coverage as native Azure resources, or that it's limited only to compute instances, are both incorrect assumptions the exam may test directly.
Reflection Question: An organization connects their AWS account to Defender for Cloud expecting full CSPM and workload protection coverage identical to their Azure resources. What would you need to verify before confirming that expectation is accurate?