← Back to Feed

​​Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)

August 5, 2026 · Microsoft Security · Severity: HIGH

Microsoft has been named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms. The report highlights how CNAPP is evolving from a consolidation of cloud security tools into a unified platform for securing AI-native enterprises. It emphasizes the need to address interconnected risks across cloud infrastructure, applications, identities, data, and AI systems.

As organizations adopt AI, they must secure both cloud and AI environments through a unified security control plane as their attack surface expands. Because modern applications and AI workloads are built and run in the cloud, security teams must understand which exposures matter most, prioritize what can truly be exploited, and reduce risk across cloud infrastructure, applications, identities, data, and AI systems in one place. 

Modern IT estates now span multiple clouds and on-premises systems, with architectures built on containers, Kubernetes, serverless functions, microservices, APIs, and AI-powered workloads. This increases both the volume and the interconnectedness of security signals. The challenge is no longer identifying individual risks, but determining how misconfigurations, identities, and data exposures combine to create real attack paths, and which of these are most critical to fix at the source. 

KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift. The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.

Within this evolving market, KuppingerCole names Microsoft a Leader across all four of its Leadership categories: Overall, Product, Innovation, and Market. In the report’s words: 

“Microsoft earns its Overall Leadership with its Defender for Cloud that is redefining the CNAPP market by extending cloud security beyond infrastructure protection and into a unified security platform for cloud, data, identity, AI, and security operations, supported by one of the industry’s most advanced agentic AI ecosystems.” 

Graphic of the KuppingerCole Leadership Compass showing Microsoft in the under right quadrant to indicate it is an overall leader.

That recognition reflects where the category is heading: toward platforms that unify cloud and AI security into one operational view of risk. 

Why CNAPP is being redefined 

KuppingerCole makes a clear point: CNAPP is no longer about posture or visibility alone. It is becoming the operational foundation for securing AI-powered applications, services, and business processes, across the full software lifecycle from cloud infrastructure to the AI systems running on top of it.

Modern environments introduce complexity across: 

  • Multicloud and hybrid infrastructure. 
  • Rapid development and continuous deployment. 
  • Containers, serverless, microservices, and APIs. 
  • AI models, agents, pipelines, and machine identities. 

This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console. Organizations now need platforms that can: 

  • Correlate posture, runtime, identity, data, application, and AI signals. 
  • Prioritize risk based on exploitability, not severity alone. 
  • Integrate security across development, cloud operations, and the SOC. 
  • Bring AI systems into the same risk model as the rest of the cloud. 

Runtime intelligence is now central to this shift. Across the platforms KuppingerCole evaluated, 94% detect active exploitation of the complex attack paths they surface, moving teams from long lists of findings to the exposures threat actors can actually use. 

What distinguishes leading platforms 

KuppingerCole evaluates providers on product strength, innovation, and market presence, and, more importantly, on how effectively they help organizations manage real risk across cloud and AI. Several themes define the next generation of platforms: 

  • AI security posture management that governs models, pipelines, and AI-specific attack paths. 
  • Agentic AI that investigates, validates exposures, and helps remediate, not just detect. 
  • Runtime-driven risk prioritization focused on what is exploitable in production. 
  • Security graphs and attack path analysis across identity, data, network, workload, and AI. 
  • Convergence of CNAPP with cloud detection and response, integrated with the SOC. 

Taken together, these capabilities represent a move from fragmented visibility to connected, contextual risk management that spans cloud and AI in a single fabric. 

How Microsoft helps organizations manage real risk 

1. Connect cross-domain signals to prioritize real attack paths 

Most security tools surface large volumes of findings, but isolated findings do not reflect how cyberattacks actually happen. Microsoft Defender for Cloud uses the Cloud Security Graph and risk-based, multicloud attack path analysis to correlate posture, identity (human and non-human), data, network, and workload signals and identify which risks are truly exploitable. A misconfigured storage resource may look low priority on its own. Exposed to the internet, combined with excessive permissions, and connected to sensitive data, it becomes part of a clear attack path.  

What this means: Security teams can prioritize real attack paths instead of individual findings, helping reduce alert fatigue and improve remediation speed and precision.  

2. Secure AI as part of cloud risk, and use AI to run security 

Defender for Cloud brings AI security posture management into the same model as the rest of the cloud, helping organizations validate AI deployment configurations, access controls, model provenance, approved model usage, and identify potential shadow AI risks within supported environments. Through

Key Takeaways

☕ Buy a Coffee