Skip to main content
Shield Coverage

Shield Cloud

Your cloud control plane is where an attacker changes what your environment is - not just what runs on it. Shield Cloud watches that, priced per onboarded account.

3
Regional officesBaltimore, Charlotte and Knoxville
1,400+
Detection rulesShipped via peer-reviewed CI/CD pipeline
100%
U.S.-based analystsZero offshore escalation paths

What it is

Monitoring of control-plane telemetry from your cloud subscriptions, accounts and tenant boundaries:

  • Identity and role changes.
  • Policy and network modifications.
  • Key and secret activity.
  • Logging being disabled.
  • Resources appearing in regions you don't use.

Endpoint agents see the workload. They cannot see somebody granting themselves a role.

What you receive

Control-plane detections triaged and investigated alongside your endpoint, identity and email telemetry by the same SOC - so a suspicious sign-in and the privilege change that followed it are one investigation.

The unit - per onboarded subscription, account or tenant boundary

  • Counted: each onboarded subscription, account or tenant boundary generating control-plane telemetry.
  • Not counted: individual virtual machines inside an onboarded subscription. Those are endpoints if they carry the Shield Agent, and they are billed as endpoints - never twice.
  • Counted on the last calendar day of the month, billed in arrears.

Part of the coverage scope of Shield Enterprise.

How it pairs

Cloud sits over Shield MDR and Shield ITDR: MDR covers what runs inside the subscription, ITDR covers the identities that reach it, Cloud covers the control plane that governs both.

See the full Shield Coverage catalog.

Ready for a SOC behind your business?

Contact SOClogix for a scoped Shield quotation. Every quotation is built from a scoped count of your real environment.

(443) 409-5426

We will get back to you within one business day.