Security · Concept · 11 min read

What a CWPP Is, What It Protects, and What It Costs

Cloud workload protection is the runtime layer of cloud security: it watches what runs, not how the account is configured. This is what it does, where agentless scanning stops, how it fits with CSPM and CNAPP, and what the published prices are.

Written by Marko Ristic, Editor Updated Sep 11, 2026
$4.906a server a month, Defender for Servers Plan 1
$14.60a server a month, Plan 2 with agentless scanning and file integrity monitoring
22%the most Microsoft offers off pay-as-you-go for a one-year pre-purchase
0running processes an agentless disk snapshot can see
Short answer

A CWPP, or cloud workload protection platform, protects the workloads that run applications in the cloud: virtual machines, containers, Kubernetes and serverless functions. It watches them while they run, scans them for vulnerabilities and malware, and alerts on attacks.

CSPM checks the cloud configuration instead, and a CNAPP combines both. Microsoft publishes Defender for Servers at $4.906 a server a month on Plan 1 and $14.60 on Plan 2.

  • Protects the workload itself: VMs, containers, Kubernetes and serverless functions
  • Runtime detection needs a sensor on the workload; agentless scanning reads a disk snapshot
  • CSPM checks the cloud configuration, CWPP the workload, CNAPP combines both
  • Published price: Defender for Servers Plan 1 at $4.906 and Plan 2 at $14.60 a server a month
  • CWPP also stands for a Community Wildfire Protection Plan, which is unrelated
On this page

WorkloadsWhat a workload is, and why it needs its own category

A workload, in the CWPP sense, is the compute that runs an application across cloud environments: a virtual machine in the cloud or on premises, a container, a Kubernetes cluster, a serverless function. Microsoft's definition of a CWPP lists exactly those, and describes the platform as a cybersecurity solution that secures workloads across cloud environments.

The reason cloud workload protection became its own category of cloud security is that some of these workloads do not live long enough for traditional endpoint security.

Microsoft's own explanation draws the line clearly: endpoint detection and response tools were designed for persistent assets that stick around long enough to install agents, collect detailed data and investigate over time, while containers may run for only seconds, serverless functions start and stop on demand, and autoscaling constantly creates and removes resources.

A CWPP uses cloud context, such as resource configuration, deployment topology and runtime behavior, to protect workloads that may already be gone by the time someone looks.

That is also why CWPPs give security teams visibility across every cloud account and region in one place, rather than machine by machine.

For a company whose cloud is a handful of long-running Windows and Linux virtual machines, the distinction matters less than it sounds. Those servers are persistent, and the CWPP protecting them does much of what endpoint detection does on a laptop, with cloud-specific additions.

What it doesWhat a CWPP actually does

Feature lists vary by vendor, and Microsoft publishes a plain table of what its server workload security includes in each plan of Defender for Cloud, which makes it a useful concrete example of the category.

Runtime detection and response. Defender for Servers Plan 1 is described as entry-level and focused on the endpoint detection and response capabilities of the Defender for Endpoint integration: alerts and incidents on Windows and Linux machines in Azure, AWS, Google Cloud and on premises. This is the runtime security that defines a CWPP.

Vulnerability scanning and software inventory. Agent-based vulnerability management is in both plans, with the inventory that gives visibility into what each cloud server runs. Agentless scanning of the disk is in Plan 2.

Malware and secrets scanning. Plan 2 adds agentless malware scanning and a scan for secrets left on machines, such as keys and passwords in files.

File integrity monitoring. Plan 2 scans operating system files, Windows registries, application software and Linux system files for changes that might indicate an attack, a control that standards such as PCI DSS ask for.

Access and hardening. Plan 2 adds just-in-time machine access, which locks down inbound traffic to management ports such as RDP and SSH and opens it when a legitimate user needs it, along with operating system baseline checks and a network map.

Other cloud security vendors package the same ideas differently, and for container security the emphasis shifts to image scanning in the registry, so a vulnerable application image is caught before it ships, and runtime monitoring of the Kubernetes nodes.

AWS describes GuardDuty Runtime Monitoring as analyzing operating system behavior such as file access, network connections and process execution on EKS, ECS, including Fargate, and EC2 workloads.

EvaluatingWhat to look for when evaluating a CWPP

Cloud workload protection platforms describe themselves in similar words, and the differences show up in a few specific questions.

Coverage across your cloud environments. Which clouds, and which workload types in each: virtual machines, containers, Kubernetes, serverless functions and on-premises servers. A CWPP that covers Azure VMs well and AWS containers poorly leaves the security team with two consoles again.

Runtime threat detection, and what it takes. Which threats it detects while the workload runs, whether that needs an agent, and what the agent costs in CPU and memory on busy servers.

Visibility before and after an alert. An inventory of every workload with its vulnerabilities and exposure, and, when an alert fires, enough context for the security team to see which workload, which account and which identity were involved.

Compliance reporting. Many organizations buy cloud workload security partly for an audit. Check which frameworks the platform maps its findings to, such as PCI DSS or CIS benchmarks, and whether controls like file integrity monitoring are included or an extra plan.

Integration. Alerts need to reach wherever the security teams already work: a SIEM, the managed detection and response provider, or the ticket queue of the MSP.

Who responds. A CWPP detects threats; it does not investigate them. For most small organizations the platform matters less than the people watching it.

Agent or agentlessAgent or agentless

The most useful technical question to ask about any cloud workload protection platform is which of its protections need a sensor on the workload, because the two approaches see different things.

Agentless scanning reads a copy of the disk. Microsoft's documentation describes it precisely: Defender for Cloud takes snapshots of the VM's root and data disks, analyzes the operating system configuration and file system in the snapshot out of band, keeps the copy in the same region as the VM, and deletes it once the metadata is extracted.

The scan does not affect the running VM. That is excellent for finding vulnerable packages, malware sitting on disk and secrets in files, and it needs nothing installed.

Runtime detection needs a sensor. A snapshot shows what is stored on the disk. It does not show a process that started five minutes ago, a reverse shell, or a crypto miner that lives in memory. Seeing those requires an agent or kernel-level sensor on the workload, which is what the endpoint detection and response side of a CWPP provides.

The practical reading is that agentless coverage is the fast way to see every workload, including the ones nobody remembered to install anything on, and agent-based runtime protection is what stops an attack in progress. Microsoft's plans show the split: Plan 1 is the agent-based runtime layer, and Plan 2 adds the agentless scans.

The acronymsCWPP, CSPM, CNAPP and CIEM

The cloud security acronyms describe layers of one cloud security program, and the clearest way to tell them apart is by what each one watches.

CSPM, cloud security posture management, watches the cloud account. It finds misconfigurations and compliance gaps across cloud environments, such as a storage bucket open to the internet, a database without encryption or logging switched off, and it improves the security posture before any workload is attacked.

CWPP watches the workload. It protects and monitors what runs on those resources, detects threats at runtime, and is the runtime layer of cloud security.

CIEM, cloud infrastructure entitlement management, watches identities, roles and permissions in the cloud, enforcing least privilege for people and services. Over-permissioned cloud identities are a common way into workloads, so this layer and the workload layer meet often.

CNAPP, the cloud-native application protection platform, combines them. Microsoft describes a CWPP as often part of a broader CNAPP, where runtime protection is informed by insights from development and deployment, and serves as the runtime and workload protection layer alongside posture management and identity controls.

For buyers, that means a CWPP is often found inside a CNAPP, as Microsoft puts it, or as a plan in the cloud provider's own security service, rather than as a product with that name on the box.

PricingWhat cloud workload protection costs, from published prices

The cloud providers publish their prices, which makes them a useful reference point. Microsoft's pricing for Defender for Cloud, read in the browser for four US regions on September 11, 2026, showed the same figures in each.

Microsoft Defender for CloudPrice
Defender for Servers Plan 1$4.906 a server a month
Defender for Servers Plan 2$14.60 a server a month
Defender for Containers$6.8693 a vCore a month
Defender Experts for Servers, managed$4 a server a month

On those figures, ten Azure servers cost about $49 a month on Plan 1 and $146 on Plan 2. Defender for Containers is billed on the vCores of the Kubernetes worker nodes, so the number of containers matters less than the size of the nodes they run on.

Defender Experts for Servers is Microsoft's managed detection and response service for server workloads, sold separately and requiring Plan 1 or Plan 2 and Defender for Endpoint on the machines. The same page offers up to 22% off pay-as-you-go prices for a one-year pre-purchase.

AWS prices GuardDuty Runtime Monitoring by the number and size of protected workloads, measured in vCPUs. Third-party platforms use their own units. Before comparing quotes, count the workloads in the unit each vendor uses, and check whether containers and serverless functions are counted separately.

Small businessDoes a small business need a CWPP?

It depends on what runs in the cloud, and the honest answer is often simpler than the category makes it sound.

If you run a few servers in Azure or AWS, the cloud provider's own workload protection is the natural first step, because it installs from the console you already use and its price is published.

Plan 1 of Defender for Servers is, in effect, endpoint detection and response for those servers. The question that matters more than the product is who reads the alerts at night, which is where a cybersecurity provider or a managed service like Defender Experts comes in.

If your applications run in containers or Kubernetes, container scanning and runtime monitoring are the part of a CWPP, and of cloud security generally, that traditional business antivirus never covered, and they are worth the extra line on the bill.

If everything you use is software as a service, Microsoft 365, a CRM, an accounting package, you have no workloads of your own to protect. Your cloud security effort belongs in identity, multi-factor authentication, configuration and compliance settings in those services, not in a CWPP.

PitfallsWhere people go wrong

Assuming agentless means protected. A snapshot scan finds what is on the disk. It does not stop an attack running in memory.

Turning on Plan 2 everywhere without counting. The price is per server per month, and test machines, old jump boxes and forgotten VMs all count. Inventory first.

Buying a CNAPP for three VMs. A platform built for thousands of containers across three clouds is a lot of product for a company with a file server and a line-of-business application in one region.

Treating the CWPP as the whole of cloud security. A perfectly protected VM in an account with a public storage bucket is still a breach, which is why posture management and workload protection belong together. Posture management and identity come first, and zero trust applies to cloud workloads as much as to laptops.

Nobody watching the alerts. A CWPP that raises an alert at 2 a.m. into a mailbox nobody reads is a notification service.

Confusing the acronym. Search results for CWPP mix cloud security with Community Wildfire Protection Plans, the local wildfire risk plans authorized by federal law in 2003. Check which one a document means.

WHAT EACH LAYER WATCHESCNAPP: ALL THREE, ONE PLATFORMCLOUD ACCOUNT, WATCHED BY CSPMopen storage, missing encryption, logging offWORKLOADS, WATCHED BY CWPPVIRTUAL MACHINESCONTAINERS, K8SSERVERLESSruntime detection, vulnerabilities, malware, file integrityIDENTITIESwatched by CIEMDefinitions follow Microsoft’s Security 101 description of CWPP, CSPM, CIEM and CNAPP.
The cloud security layers by what each one watches. A CWPP protects the workloads; CSPM the account they run in; CIEM the identities acting on both.

ComparisonCWPP, CSPM, CNAPP and EDR, by what each one watches

CriterionCWPPCSPMCNAPPEDR
WatchesRunning workloadsCloud configurationBoth, plus identityDevices and servers
Covers containers and serverlessYesConfiguration onlyYesRarely
Detects an attack in progressYes, with a sensorNoYesYes
Finds a public storage bucketNoYesYesNo
Needs an agentFor runtime, yesNoFor runtime, yesYes

The middle rows are the decision. An attack in progress is caught by the workload layer; a misconfiguration is caught by the posture layer; a CNAPP is the name for buying both from one vendor.

FAQFrequently asked questions

What does CWPP stand for?

Cloud workload protection platform. In a different field, CWPP also stands for Community Wildfire Protection Plan, a local wildfire risk plan, which has nothing to do with IT.

What is a CWPP in simple terms?

Security software for the virtual machines, containers and serverless functions that run your applications in the cloud. It scans them for vulnerabilities and malware and watches them while they run for signs of an attack.

What is the difference between CWPP and CSPM?

CSPM checks how the cloud account is configured, such as open storage or missing encryption. A CWPP protects the workloads running in that account. One finds the unlocked door, the other watches who is inside.

What is the difference between CWPP and CNAPP?

A CNAPP combines workload protection with posture management and identity controls in one platform. The CWPP is the runtime and workload layer inside it.

Is a CWPP the same as EDR?

They overlap on servers. Endpoint detection and response was built for persistent devices; a CWPP adds cloud context and covers short-lived workloads such as containers and serverless functions. Microsoft's Defender for Servers Plan 1 is built on its EDR.

Does a CWPP need an agent?

For runtime detection, yes. Agentless scanning, which reads a snapshot of the disk, finds vulnerabilities, malware and secrets at rest without installing anything, and it cannot see an attack running in memory.

How much does a CWPP cost?

Microsoft publishes Defender for Servers at $4.906 a server a month on Plan 1 and $14.60 on Plan 2, and Defender for Containers at $6.8693 per vCore of Kubernetes worker nodes a month. AWS prices GuardDuty Runtime Monitoring per vCPU.

What does Defender for Servers Plan 2 add over Plan 1?

Agentless vulnerability, malware and secrets scanning, file integrity monitoring, just-in-time machine access, operating system baseline and update checks, a network map, DNS alerts and 500 MB of free data ingestion, on top of Plan 1's endpoint detection and response.

Do I need a CWPP if I only use Microsoft 365?

No. With only software as a service there are no workloads of your own to protect. Identity, MFA and configuration are where the effort belongs.

Which workloads does a CWPP protect?

Virtual machines in the cloud and on premises, containers and Kubernetes clusters, and serverless functions. Coverage for each type varies by vendor and by plan.

Why do organizations use CWPPs?

To protect workloads that traditional endpoint security was not built for, especially short-lived containers and serverless functions, and to give security teams one view of threats and vulnerabilities across cloud environments, often with compliance reporting attached.

Can an MSP manage a CWPP for me?

Yes, and for a small company that is usually the point. The platform raises alerts; someone has to investigate them, around the clock, and respond. Ask who that is before choosing the product.

Read next · Identity and access Zero Trust Explained The model that treats every workload and identity as untrusted by default. Open this next13 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.