2 thoughts on “Exclude a Storage Account from Microsoft Defender for Storage”

Leave a comment...

  1. Hi Charbel,

    Thanks for the comprehensive implementation steps, we have a similar use case of enabling Defender for cloud on selective storage accounts and thus tried the steps by assigning the tag name “AzDefenderPlanAutoEnable” and value “off” through the portal on storage accounts to make this option disabled followed by turning off and on the defender for storage plan, however it did not work, defender for cloud is still enabled on the storage account with tag. Could you please suggest what else it could be?

    Thanks for your help,

  2. Hello Vinny, Thanks for your feedback and comment!

    First, are you using Microsoft Defender for Storage (classic) or the new Defender for Storage plan?

    The tag “AzDefenderPlanAutoEnable” with value “off” only works for the classic (legacy) plan, not for the new Defender for Storage plan. If you’re using the new plan, this method will not disable protection.

    Additionally, Defender for Storage (classic) is unavailable for new subscriptions as of February 5, 2025.

    If you want to disable Defender for Storage under the new plan—either completely or by turning off specific features (e.g., on-upload malware scanning or sensitive data threat detection)—you need to:
    1️⃣ Go to your Storage Account in the Azure portal.
    2️⃣ Navigate to Microsoft Defender for Cloud under the Security + Networking menu.
    3️⃣ Select Settings > Edit, then adjust the desired settings or toggle Microsoft Defender for Storage to Off.
    4️⃣ Click Save.

    Hope this helps!
    Best,
    Charbel

Let us know what you think, or ask a question...