5.1. Manage Security Posture by Using Defender for Cloud
💡 First Principle: Posture management answers a fundamentally different question than workload protection does — not "did something bad just happen" but "how exposed am I right now, before anything happens at all" — which is why CSPM findings show up as recommendations to fix, not alerts to investigate.
Mental model: Defender for Cloud's posture side is preventive-by-visibility (it doesn't stop anything itself, but makes exposure visible enough that you can fix it before it's exploited), while its workload protection plans — covered throughout Phase 4 (Defender for Servers, Containers, AI Service) and Phase 3 (Defender for Storage, Databases) — are the detective layer watching for active threats.
⚠️ Common Misconception: Enabling Defender CSPM does not automatically enable all workload protection plans. CSPM (posture management and recommendations) is billed and enabled separately from the workload-specific Defender plans covered elsewhere in this guide — an environment can have CSPM active with zero workload protection plans turned on.