Microsoft has expanded the Azure security workloads that can count toward the Solutions Partner designation for Security. For cloud partners, managed service providers, CSP organizations, and systems integrators, this is a practical change: more of the security-related Azure consumption already happening in customer tenants may now help demonstrate performance toward the designation.

The update does not remove the need for a deliberate partner strategy. Designation progress still depends on meeting Microsoft’s published requirements, tracking the right customer activity, and validating the score in Partner Center. But the broadened workload list gives partners more recognized paths, especially those already building customer practices around identity, network security, data governance, threat detection, and AI-assisted security operations.

What changed

Microsoft has added and renamed eligible Azure security Azure Consumed Revenue workloads for the Solutions Partner designation for Security. In plain terms, additional security-related services can now contribute to the Azure consumption component used in the designation path.

The eligible workload list now includes services such as Application Gateway, Azure Bastion, Azure DDoS Protection, Azure Firewall, Azure Front Door Service, Key Vault, Microsoft Defender for Cloud, Microsoft Entra, Microsoft Purview, Microsoft Security Copilot, and Microsoft Sentinel. Identity-related services such as Azure Active Directory B2C, Azure Active Directory for External Identities, Microsoft Entra Domain Services, and Microsoft Entra Verified ID are also included in the updated list.

One workload moves in the opposite direction: Network Watcher is no longer listed as an eligible workload for this designation. Partners that previously assumed Network Watcher usage would support their Security designation progress should review the impact in Partner Center rather than relying on historical assumptions.

Why this matters for Microsoft partners

The Solutions Partner designation for Security is more than a badge. For many partners, it supports marketplace credibility, customer trust, Microsoft co-sell conversations, internal specialization, and access to benefits tied to the Microsoft AI Cloud Partner Program. When customers evaluate security partners, designation status can help separate a general cloud provider from a partner with measurable security delivery experience.

This announcement matters because security work in Azure is often distributed across several technical domains. A modern customer security project may include network controls, identity hardening, privileged access architecture, key management, SIEM integration, cloud security posture management, data protection, and incident response. Before this expansion, some partner activity may have felt adjacent to the Security designation without clearly helping toward the workload eligibility path.

By recognizing more Azure security workloads, Microsoft is aligning the designation path more closely with how security practices actually operate. A partner delivering Microsoft Sentinel deployments, Defender for Cloud posture improvements, Key Vault governance, Entra identity architecture, Azure Firewall design, or Purview compliance projects now has a broader set of activities that may help support designation progress.

Practical impact by partner type

For CSP indirect resellers and direct bill partners, the change may improve the value of security attach motions. If customer Azure environments already include firewalling, identity, key management, monitoring, or threat detection services, those workloads may now be more relevant to designation attainment. This can make it easier to connect day-to-day customer projects with long-term partner program goals.

For distributors and scale solution providers, the announcement creates an opportunity to educate reseller communities. Many smaller partners do not continuously monitor designation workload lists. A targeted enablement campaign can help them identify which customer projects now map to the Security designation and where gaps remain.

For global systems integrators and systems integrators, the update may help translate large security transformation programs into clearer Microsoft partner program outcomes. Security architecture is rarely a single-product motion; it often spans Sentinel, Defender for Cloud, Entra, Purview, Key Vault, network protection, and secure application delivery. The expanded list better reflects that breadth.

Default behavior and what partners should not assume

Partners should not assume that every customer deployment of a listed service automatically guarantees designation progress. The announcement identifies eligible workloads, but actual progress depends on how Microsoft measures partner performance, association, revenue attribution, customer eligibility, timing, and the rules shown in Partner Center.

That distinction is important. A partner may deploy or manage an eligible service, but if the customer relationship is not correctly associated, if attribution is missing, or if consumption does not meet program rules, the expected progress may not appear. The safest default is to treat the announcement as an expanded opportunity, then confirm the measured effect directly in the Partner Center dashboard.

Partners should also review any previous reliance on Network Watcher. Because Microsoft states that Network Watcher is no longer eligible for this designation, partners should avoid including it in internal calculators or sales guidance unless Partner Center confirms otherwise for a specific reporting period.

Recommended partner next steps

First, check the Security designation dashboard in Partner Center. Look at current progress, eligible workload contribution, and any gaps between expected customer activity and Microsoft’s measured data. If the expanded workload list changes your trajectory, document which services are contributing and which customer projects are involved.

Second, update internal solution mapping. Security offerings should be reviewed against the new eligible workload list. If your managed security service includes Sentinel, Defender for Cloud, Entra, Purview, Key Vault, Azure Firewall, or Front Door, make sure those services are clearly reflected in sales material, delivery checklists, and partner performance tracking.

Third, validate partner association. For CSP and services-led partners, attribution problems can quietly undermine designation progress. Confirm that customer relationships, partner of record settings, CSP associations, and any relevant program links are configured correctly before assuming consumption will count.

Fourth, brief sales and account teams. This update gives sellers a better way to connect security modernization projects with partner capability. The message should be practical: the customer value remains better security, governance, and resilience, while the partner may also gain clearer progress toward Microsoft’s Security designation.

Fifth, review reporting and forecasting models. If your organization tracks designation attainment internally, update dashboards to include the newly added or renamed workloads and remove Network Watcher from forward-looking assumptions. This is especially important for partners close to meeting requirements, where a small reporting difference can affect planning.

Workloads to pay attention to

Several workloads in the expanded list are especially relevant to common customer security priorities.

Microsoft Sentinel remains central for partners building security operations and SIEM practices. Microsoft Defender for Cloud supports cloud security posture management and workload protection. Microsoft Entra connects the designation path to identity and access work, which is often the foundation of zero trust projects. Microsoft Purview brings data governance, compliance, and risk management into scope. Key Vault supports secrets and key management, a core requirement in secure Azure architecture.

Network and edge security are also represented through Azure Firewall, Azure Firewall Manager, Azure DDoS Protection, Azure Front Door Service, Application Gateway, and Azure Bastion. These services often appear in landing zone, secure connectivity, and application modernization projects.

The inclusion of Microsoft Security Copilot is also notable. While adoption will vary by customer maturity and licensing, its presence signals that Microsoft sees AI-assisted security operations as part of the broader security partner opportunity.

Bottom line

Microsoft’s expanded workload eligibility gives partners more ways to translate real Azure security work into progress toward the Solutions Partner designation for Security. The immediate action is not to change every offer, but to review the Partner Center dashboard, update internal workload mapping, confirm attribution, and remove Network Watcher from future assumptions.

For partners already delivering identity, threat protection, SIEM, network security, key management, data governance, or AI-assisted security services on Azure, this update may make the Security designation path more attainable and easier to explain internally.

Source: Microsoft Partner Center announcement