Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft has been recognized as a Leader in Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026, highlighting its runtime security capabilities and unified framework for protecting cloud-native workloads.
Microsoft has been named a Leader in Frost & Sullivan’s Frost Radar™: Cloud Workload Protection Platforms, 2026, ranking among the top vendors in a market moving toward runtime security. The report benchmarks 20 of over 45 qualified vendors, emphasizing a shift from static scanning to continuous protection of workloads in production. Frost & Sullivan highlights Microsoft’s Defender for Cloud as a standout for its broad coverage across infrastructure, workloads, identities, and applications, with deep integration into Microsoft’s security ecosystem.
The Frost Radar™ report underscores the growing importance of runtime telemetry, container security, and workload behavior analysis in modern cloud security. Frost & Sullivan notes that leadership in this space is increasingly defined by the ability to detect and respond to threats in real time, rather than relying solely on pre-deployment scans. Microsoft’s Defender for Cloud is cited for its runtime protection capabilities, including Kubernetes event monitoring, process activity tracking, and network traffic analysis, with detections mapped to MITRE ATT&CK frameworks.
Microsoft’s Defender for Cloud now includes expanded capabilities such as DNS detection for Kubernetes across major cloud platforms, anti-malware blocking, and drift prevention for running workloads. The platform also integrates preventive controls, such as blocking non-compliant container images before deployment, aligning security with production environments. Frost & Sullivan emphasizes this approach as critical for addressing the complexity of modern cloud estates, which span multiple clouds and hybrid environments.
Runtime signals are only effective if they reach the right responders quickly. Defender for Cloud consolidates telemetry from Kubernetes audits, process activity, network traffic, and identity signals into specific workload incidents, feeding them into Microsoft Defender XDR and Microsoft Sentinel. This integration enables faster incident response and reduces manual signal stitching. The platform also supports AI workload protection, including model scanning and threat detection for services like Azure AI Foundry and Azure OpenAI, extending security across Microsoft Azure, AWS, GCP, and hybrid environments.