Cloud Security Envisioning Workshop
Defender for Cloud against your real workloads and real data, ending in actionable next steps.
What this is
Designed to build customer intent for deploying or expanding Microsoft Defender for Cloud. Customers explore how to detect threats, understand their security posture, and identify risks and opportunities. Concludes with clear, actionable next steps aligned to their goals. Delivered in the customer's production environment, using real-world data to uncover security threats and vulnerabilities.
What you leave with
- Threats detected and your security posture understood using real-world data
- Risks and opportunities identified across your cloud workloads
- Clear, actionable next steps aligned to your goals
Who qualifies
Your commitment
- Time from a sponsor and the technical owners for the workshop days
- Read-level access to your production environment for the discovery work
- A customer attestation form at the end, which Microsoft requires as proof of delivery
- Any fee on our side is stated in writing before anything begins
How we run it
- A scoping call, and a written consent checklist naming exactly what the evaluation will touch in your environment and what it will read.
- The discovery window itself, run against your production tenant, with a check-in at the end of each day so nothing in the readout is a surprise.
- A readout delivered by the engineers who did the work, walking through what was actually found rather than a deck written by somebody else.
- The customer attestation form, which is how Microsoft is shown the engagement was delivered.
In and out
In the funded scope
- Threats detected and your security posture understood using real-world data
- Risks and opportunities identified across your cloud workloads
- Clear, actionable next steps aligned to your goals
Not in it
- Remediation. The engagement finds and explains; fixing what it finds is a separate engagement, quoted at our normal fixed price.
- Production policy changes and deployment. Nothing in your tenant is altered under this engagement without a separate, quoted piece of work.
- Ongoing monitoring. The workshop is a window in time; running what it recommends is a service, not a workshop.
The funding, plainly
Microsoft describes this incentive as a co-investment that is not intended to cover the full cost of deployment activities. In practice, Microsoft pays us for a defined portion of this engagement; your commitment is the time and access listed above, plus any fee we state in writing before work begins. We never state Microsoft's funding amount: it varies by customer band and programme period, and quoting it would be guessing. If the programme window closes while your request is in flight, we tell you and requote the same work at our normal fixed price.
Asked before booking
Does Microsoft pay for all of it?
No. Microsoft describes the incentive as a co-investment that is not intended to cover the full cost of deployment activities. Microsoft pays us for a defined portion; your side is the time, access and any fee we state in writing before work begins.
Do you need access to our production environment?
Yes, read-level. That is the whole point of this shape of engagement: Microsoft funds it to find real findings in a real tenant, not to demonstrate on a sample one. The consent checklist lists every place we look before anyone signs it.
What if we do not qualify?
We say so and quote the same work at our normal fixed price. The eligibility check itself costs you nothing but the conversation.