Configure Defender for Cloud plan settings including per-resource pricing tiers, extensions, and security contacts.
Configure Defender for Cloud plan settings including per-resource pricing tiers, extensions, and security contacts.
Required Fields
subscriptionIdpricingTierplansplans[0].nameplans[0].pricingTiersecurityContacts.emailsOutput will appear here...Configure Microsoft Defender for Cloud plan pricing tiers per resource type (VirtualMachines, SqlServers, StorageAccounts, Containers, KeyVaults) each with their own subPlan and extensions, since Defender for Cloud is billed per-plan, not as one flat subscription-wide toggle. Enabling the top-level pricingTier alone does nothing for a specific resource type, each plan under plans needs its own pricingTier set to Standard, and forgetting one (leaving it at Free implicitly) means that resource type gets none of Defender's threat detection even though the subscription overall looks 'protected' at a glance.
Audit every entry under plans individually rather than trusting the top-level pricingTier field, a subscription can look protected at a glance while several specific resource-type plans are silently still at Free.
Storage malware scanning's per-account monthly GB cap is a real cost control but also a real coverage gap once exceeded, size the cap based on actual expected upload volume, not an arbitrary round number, or high-traffic accounts silently lose scanning coverage mid-month.
Route securityContacts to an address/channel that's actually monitored in near-real-time for anything above Medium severity, a security contact configured but pointed at an unmonitored inbox provides no practical benefit over having no contact configured at all.
The builder validates that subscriptionId, pricingTier, plans, and the first plan's name/pricingTier plus securityContacts.emails all resolve before accepting the JSON as a plausible combined Defender for Cloud pricing and configuration payload; it can't verify that a specific plan/subPlan/extension combination is actually valid or currently available for your subscription's region, that's only confirmed against the live Microsoft.Security resource provider.
Was this tool helpful?
Disclaimer: This tool runs entirely in your browser. No data is sent to our servers. Always verify outputs before using them in production. AWS, Azure, and GCP are trademarks of their respective owners.