Microsoft Azure

Download 168
Last updated Sep 7, 2026

azure-resource-graph

Run an Azure Resource Graph KQL query across the subscriptions of a connect profile.

azure-resource-graph [profile=VALUE] query=VALUE
profile=VALUE
Optional. Azure connect profile name
query=VALUE
Required. Resource Graph query, for example resources | where type =~ 'microsoft.storage/storageaccounts'

Output Fields

FieldTypeNameDescription
profile_nameStringProfileConnect profile the row came from. Remaining fields are those projected by the query.

Examples

Count every resource by type, across all subscriptions the profile can see

azure-resource-graph profile="prod" query="resources | summarize count() by type | order by count_ desc"

Storage accounts and their TLS setting

azure-resource-graph profile="prod" query="resources | where type =~ 'microsoft.storage/storageaccounts' | project name, resourceGroup, minimumTlsVersion = properties.minimumTlsVersion"

Role assignments - a different table, same endpoint

azure-resource-graph profile="prod" query="authorizationresources | where type =~ 'microsoft.authorization/roleassignments' | limit 10"

Endpoint and permissions

  • Calls POST https://management.azure.com/providers/Microsoft.ResourceGraph/resources. The subscriptions are sent in the request body, so one query spans every subscription on the profile.
  • Requires the Reader role on each subscription in scope, assigned to the app registration. Authentication succeeding with no subscription assigned returns an empty result rather than an error.
  • Resource Graph supports a subset of KQL - no render and no time series functions - and exposes its own tables (resources, resourcecontainers, authorizationresources, securityresources, policyresources). It is not Log Analytics: AzureActivity and SigninLogs are not available here.