Defender for Cloud's Serverless Containers Posture Finally Covers ACA
We have spent the last two years telling clients that their Azure Container Apps environments were a blind spot in Defender for Cloud. AKS clusters got the full posture treatment. Container Apps got asset inventory and not much else. That gap just closed.
Microsoft shipped general availability for Defender for Cloud support for Azure Container Apps under Serverless Containers Posture on September 1, 2026 (azure.microsoft.com/updates?id=570282). The update brings ACA into the same posture workflow that already covered Azure Container Instances, so security teams stop juggling two different views of what is, functionally, the same container estate.
What was actually missing
Container Apps sits in an awkward spot architecturally: it is a managed Kubernetes environment under the hood, but Microsoft does not expose the cluster to you, so none of the AKS-flavored Defender for Containers tooling (control plane hardening, node vulnerability scans, runtime sensors) applied cleanly. Teams running ACA workloads next to AKS clusters ended up with a split picture: rich posture data for one, almost nothing for the other, inside the same Defender for Cloud blade.
Defender for Cloud's Cloud Security Posture Management (CSPM) is built around continuous assessment of cloud assets against the Microsoft Cloud Security Benchmark, with recommendations and a secure score tied to that assessment (learn.microsoft.com/en-us/azure/defender-for-cloud/concept-cloud-security-posture-management). Serverless Containers is one of the resource categories under that umbrella, and until now it meant ACI. Adding ACA means the same discovery, misconfiguration detection, and risk-prioritized recommendations now apply to the compute model most of our clients actually picked for new microservice work, because it is the one that doesn't force them to run a cluster.
Where this sits in the plan structure
This is a Defender CSPM feature, not a separate SKU. Defender for Cloud offers two CSPM plans: Foundational CSPM, which is free, and Defender CSPM, the paid tier that adds agentless vulnerability scanning, attack path analysis, and discovery and posture for serverless container workloads specifically (that capability is listed as Defender CSPM-only in the plan comparison table). If you are still on Foundational CSPM, enabling this for ACA does nothing until you upgrade.
Inside Defender CSPM, serverless containers (ACA and ACI together) are billed as a distinct component. Per the Microsoft Learn CSPM concept article, billing for Serverless Containers became effective July 1, 2026, and requires you to explicitly enable the Serverless Containers component in Defender CSPM, with Registry access enabled separately for full coverage. This mirrors how Serverless protection for Function Apps and Web Apps works under the same plan, which became billable April 1, 2026. Both are opt-in sub-components, not something that turns on the moment you flip Defender CSPM to Standard.
Worth separating in your own head: this is a different lane from Defender for Containers, the CWPP plan that does runtime threat detection, node-level vulnerability assessment, and software supply chain protection for Kubernetes clusters, with its own per-image and per-vCore billing meters. Serverless Containers Posture under Defender CSPM is the discovery-and-misconfiguration layer for ACA/ACI. It is not runtime protection for those workloads. If a client's actual requirement is detecting active exploitation inside a running container app, this GA doesn't give you that; it gives you the configuration hygiene layer underneath it.
Turning it on and confirming it took
Before you touch anything, check what is already enabled on the subscription. We always start here because clients routinely believe a plan is on when it was enabled on a different subscription, or a connector, or never actually saved:
# list which Defender for Cloud plans and tiers are active on this subscription
az security pricing list \
--query "value[].{plan:name, tier:pricingTier}" \
-o table
From there, enabling Serverless Containers coverage for ACA is a Defender CSPM settings change: open Defender CSPM, turn on the Serverless Containers component, then separately enable Registry access if you want the full coverage path rather than just discovery. Treat this as two switches, not one. We have seen teams flip the component, see ACI data populate, and assume ACA is covered too, when Registry access was still off and half the posture signal was missing.
What it actually costs to run next to it
The GA note doesn't carry its own price line, since Serverless Containers Posture billing is folded into Defender CSPM's existing resource-based billing model described above. But if your ACA workloads also sit under Defender for Containers for runtime protection, here is what that adjacent plan costs at list price, East US, pay-as-you-go, pulled from the Azure Retail Prices API on 2026-10-03:
| Meter | Unit | Price |
|---|---|---|
| Microsoft Defender for Containers, Standard Images | per image | $0.29 |
| Microsoft Defender for Containers, Standard vCore (vCore Pack) | per vCore/hour | $0.00941 |
These are separate meters from the CSPM resource-based billing that covers Serverless Containers Posture itself. Run both calculators before you quote a client a number; Defender CSPM's cost calculator is the one to use for the posture layer, not the Containers plan pricing above.
Judgement: where we'd push back on rollout order
Our opinion, not Microsoft's: don't enable this as a blanket subscription-wide toggle on day one if you're running a lot of ACA environments across dev and prod. Defender CSPM protects all Azure workloads but only bills on resources where the component is active, so there's no cost reason to hold back, but there is an alert-fatigue reason. ACA apps built quickly by app teams tend to have messy ingress and identity configs that will generate a wave of new recommendations the moment posture coverage switches on. Pilot it on one subscription, let the secure score and recommendation list settle, and tune suppression rules before you roll it fleet-wide. This is the same sequencing mistake we've watched teams make with AKS posture rollouts, just on a newer surface.
The other gap we'd flag: this GA is Azure-only. If your container estate spans AWS or GCP serverless container services, Defender CSPM's multicloud support exists for CSPM broadly, but confirm current coverage for non-Azure serverless container posture specifically before you promise a client parity across clouds.
When to call us
If you're untangling Defender for Cloud plan sprawl across a mixed AKS and Container Apps estate, or need the posture and detection layers actually talking to each other in Sentinel, reach out through /contact or see how we approach this kind of work on our detection engineering practice page.
