Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Defender for Cloud uses a proprietary algorithm to locate potential attack paths in your multicloud environment. It focuses on real, external threats that attackers can exploit, not broad scenarios. The algorithm finds attack paths that start outside your organization and lead to critical targets. This helps you cut through the noise and act faster.
You can use attack path analysis to find and fix the security issues that pose the biggest risk. Defender for Cloud shows which issues are part of exposed attack paths that attackers could use to breach your environment. Defender for Cloud also highlights the recommendations you need to resolve.
By default, attack paths are sorted by risk level. A risk engine reviews the risk factors of each resource to set its priority. For details on how Defender for Cloud ranks recommendations, see Risk prioritization.
Prerequisites
Before you begin, make sure your environment meets these requirements:
Enable Defender Cloud Security Posture Management (CSPM) and turn on agentless scanning.
Required roles and permissions: Security Reader, Security Admin, Reader, Contributor, or Owner.
Note
You might see an empty Attack Path page. Attack paths now focus on real, external threats that can be exploited. This focus helps reduce noise and highlight urgent risks.
To view attack paths related to containers:
To see container-related attack paths, complete one of the following setup options: - Enable agentless container posture extension in Defender CSPM. - Enable Defender for Containers and install the relevant agents. This option also lets you query container data plane workloads in cloud security explorer.
- Required roles and permissions: Security Reader, Security Admin, Reader, Contributor, or Owner.
Identify attack paths
You can use Attack path analysis to locate the biggest risks to your environment and to remediate them.
The attack path page shows you an overview of all of your attack paths. You can also see your affected resources and a list of active attack paths.
To identify attack paths in the Azure portal:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Attack path analysis.
Select an attack path.
Select a node.
Note
If you have limited permissions—especially across subscriptions—you might not see full attack path details. This is expected behavior designed to protect sensitive data. To view all details, make sure you have the necessary permissions.
Select Insight to view the associated insights for that node.
Select Recommendations.
Select a recommendation.
To identify attack paths in the Defender portal:
Sign in to the Microsoft Defender portal.
Navigate to Exposure Management > Attack surface > Attack paths. You will see an overview of your attack paths.
The attack paths experience provides multiple views:
- Overview tab: View attack paths over time, top 5 choke points, top 5 attack path scenarios, top targets, and top entry points
- Attack paths list: Dynamic, filterable view of all attack paths with advanced filtering capabilities
- Choke points: List of nodes where multiple attack paths converge, flagged as high-risk bottlenecks
Note
In the Defender portal, attack path analysis is part of the broader Exposure Management capabilities, providing enhanced integration with other Microsoft security solutions and unified incident correlation.
Select the Attack paths tab.
Use advanced filtering in the Attack paths list to focus on specific attack paths:
- Risk level: Filter by High, Medium, or Low risk attack paths
- Asset type: Focus on specific resource types
- Remediation status: View resolved, in-progress, or pending attack paths
- Time frame: Filter by specific time periods (for example, last 30 days)
Select an attack path to view the Attack Path Map, a graph-based view highlighting:
- Vulnerable nodes: Resources with security issues
- Entry points: External access points where attacks could begin
- Target assets: Critical resources attackers are trying to reach
- Choke points: Convergence points where multiple attack paths intersect
Select a node to investigate detailed information:
Note
If you have limited permissions—especially across subscriptions—you might not see full attack path details. This is expected behavior designed to protect sensitive data. To view all details, make sure you have the necessary permissions.
Review node details including:
- MITRE ATT&CK tactics and techniques: Understanding the attack methodology
- Risk factors: Environmental factors contributing to risk
- Associated recommendations: Security improvements to mitigate the issue
Select Insight to view the associated insights for that node.
Select Recommendations to see actionable guidance with remediation status tracking.
Select a recommendation.
Once an attack path is resolved, it can take up to 24 hours for an attack path to be removed from the list.
Remediate attack paths
After you investigate an attack path and review its findings and recommendations, you can start to fix it.
To remediate an attack path in the Azure portal:
Navigate to Microsoft Defender for Cloud > Attack path analysis.
Select an attack path.
Select Remediation.
Select a recommendation.
Once an attack path is resolved, it can take up to 24 hours for an attack path to be removed from the list.
Remediate all recommendations for an attack path
Attack path analysis lets you see all recommendations for an attack path in one place. You don't need to check each node one by one.
There are two types of recommendations:
- Recommendations - Steps that fix the attack path.
- Additional recommendations - Steps that lower risk but don't fully fix the attack path.
To resolve all recommendations in the Azure portal:
Sign in to the Azure portal.
Navigate to Microsoft Defender for Cloud > Attack path analysis.
Select an attack path.
Select Remediation.
Expand Additional recommendations.
Select a recommendation.
Once an attack path is resolved, it can take up to 24 hours for an attack path to be removed from the list.
To resolve all recommendations in the Defender portal:
Sign in to the Microsoft Defender portal.
Navigate to Exposure Management > Attack path analysis.
Select an attack path.
Select Remediation.
Note
The Defender portal provides enhanced tracking of remediation progress and can correlate remediation activities with broader security operations and incident management workflows.
Expand Additional recommendations.
Select a recommendation.
Once an attack path is resolved, it can take up to 24 hours for an attack path to be removed from the list.
Enhanced exposure management capabilities
The Defender portal provides additional capabilities for attack path analysis through its integrated Exposure Management framework:
- Unified incident correlation: Attack paths are automatically correlated with security incidents across your Microsoft security ecosystem.
- Cross-product insights: Attack path data is integrated with findings from Microsoft Defender for Endpoint, Microsoft Sentinel, and other Microsoft security solutions.
- Advanced threat intelligence: Enhanced context from Microsoft threat intelligence feeds to better understand attack patterns and actor behaviors.
- Integrated remediation workflows: Streamlined remediation processes that can trigger automated responses across multiple security tools.
- Executive reporting: Enhanced reporting capabilities for security leadership with business impact assessments.
These capabilities provide a more comprehensive view of your security posture and enable more effective response to potential threats identified through attack path analysis.
Learn more about attack paths in Defender for Cloud.