azure-resource-graph
Run an Azure Resource Graph KQL query across the subscriptions of a connect profile.
azure-resource-graph [profile=VALUE] query=VALUE
- profile=VALUE
- Optional. Azure connect profile name
- query=VALUE
- Required. Resource Graph query, for example
resources | where type =~ 'microsoft.storage/storageaccounts'
Output Fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile_name | String | Profile | Connect profile the row came from. Remaining fields are those projected by the query. |
Examples
Count every resource by type, across all subscriptions the profile can see
azure-resource-graph profile="prod" query="resources | summarize count() by type | order by count_ desc"
Storage accounts and their TLS setting
azure-resource-graph profile="prod" query="resources | where type =~ 'microsoft.storage/storageaccounts' | project name, resourceGroup, minimumTlsVersion = properties.minimumTlsVersion"
Role assignments - a different table, same endpoint
azure-resource-graph profile="prod" query="authorizationresources | where type =~ 'microsoft.authorization/roleassignments' | limit 10"
Endpoint and permissions
- Calls
POST https://management.azure.com/providers/Microsoft.ResourceGraph/resources. The subscriptions are sent in the request body, so one query spans every subscription on the profile. - Requires the Reader role on each subscription in scope, assigned to the app registration. Authentication succeeding with no subscription assigned returns an empty result rather than an error.
- Resource Graph supports a subset of KQL - no
renderand no time series functions - and exposes its own tables (resources,resourcecontainers,authorizationresources,securityresources,policyresources). It is not Log Analytics:AzureActivityandSigninLogsare not available here.