Aller au contenu principal

Discover AI workloads & models with Defender CSPM

Implementation Effort: Medium – Requires enabling the Defender CSPM plan on Azure subscriptions hosting AI workloads; for AWS accounts, permissions must be reconfigured to enable AI posture capabilities.

User Impact: Low – Infrastructure-level security assessment; end users are not affected.

Overview

Before AI workloads can be secured, they must be discovered. Azure AI Foundry models, Azure OpenAI deployments, MCP servers, and AI-enabled applications are cloud resources that accumulate misconfigurations and exposure risks just like any other workload — but they often fall outside the scope of existing cloud security reviews because they are newer, moved quickly through deployment, and lack the same governance maturity as traditional infrastructure. Defender CSPM provides the discovery and posture assessment layer that brings AI resources into the same security management surface as the rest of the cloud estate.

Enabling the Defender CSPM plan on subscriptions hosting AI workloads activates agentless scanning that identifies Azure OpenAI and Azure AI Foundry resources, assesses their configurations against the Microsoft Cloud Security Benchmark, and surfaces AI-specific security recommendations. These recommendations cover model endpoint exposure, network access controls, diagnostic logging enablement, private endpoint configuration, and identity-based access to model deployments. The cloud security explorer allows security teams to query relationships between AI resources, the identities that access them, and the data they interact with — enabling attack path analysis that reveals how a misconfigured AI endpoint could serve as a lateral movement vector into broader cloud infrastructure.

For multicloud environments, the CSPM plan can be extended to AWS accounts where AI workloads are deployed. The resulting asset inventory feeds directly into the Microsoft Security Dashboard for AI, providing the model and application layer of the AI inventory alongside agents registered in Agent 365.

This supports Assume breach by providing continuous posture assessment of AI resources, ensuring that newly deployed models and endpoints are evaluated against security requirements before they can be exploited. It supports Verify explicitly by maintaining a live inventory of AI workloads with their current configuration state, making it possible to verify that every deployed model meets the organization's security baseline. Without this plan enabled, AI resources are invisible to the cloud security posture management surface — misconfigurations go undetected, attack paths through AI endpoints go unanalyzed, and the Security Dashboard for AI shows an incomplete inventory.

Reference