defender-cloud-assessments
Lists security recommendations collected from Microsoft Defender for Cloud, one row per recommendation per resource, ordered by Defender's own risk level.
defender-cloud-assessments [profile=VALUE] [subscription=VALUE] [status=VALUE] [risk=VALUE] [min-risk-score=VALUE] [severity=VALUE] [security-issue=VALUE] [resource-type=VALUE] [resource-group=VALUE] [exposed=VALUE] [keyword=VALUE] [locale=VALUE]
- profile=VALUE
- Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
- subscription=VALUE
- Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
- status=VALUE
- Optional. Healthy, Unhealthy or NotApplicable. e.g. Unhealthy
- risk=VALUE
- Optional. Defender's risk level, stored as LOW, MEDIUM or HIGH. A Critical finding is stored as HIGH, so use min-risk-score to single it out. e.g. HIGH
- min-risk-score=VALUE
- Optional. Rank floor: 4 Critical, 3 High, 2 Medium, 1 Low. 4 returns Critical only. e.g. 4
- severity=VALUE
- Optional. Severity of the recommendation template. Not the same thing as risk: it rates the rule rather than this finding, and the two often disagree. e.g. High
- security-issue=VALUE
- Optional. Problem class, which separates package patches from configuration findings. e.g. Vulnerability
- resource-type=VALUE
- Optional. e.g. Microsoft.Compute/virtualMachines
- resource-group=VALUE
- Optional. e.g. rg-app
- exposed=VALUE
- Optional. t to return only internet-reachable resources. e.g. t
- keyword=VALUE
- Optional. Substring of the recommendation title or resource name. e.g. endpoint
- locale=VALUE
- Optional. Language of the title, description and remediation. Defaults to the console session's language; en returns Azure's original text. e.g. ko
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| assessment_name | String | Recommendation | e.g. Microsoft Defender for App Service should be enabled |
| status | String | Status | e.g. Unhealthy |
| risk | String | Risk level | Defender's own contextual rating, carried through unchanged. e.g. HIGH |
| risk_score | Integer | Risk rank | Rank of the level so ORDER BY sorts correctly, not a measurement: 4 Critical, 3 High, 2 Medium, 1 Low. e.g. 3.0 |
| severity | String | Severity | Severity of the recommendation template, which can disagree with risk. e.g. High |
| security_issue | String | Issue type | e.g. Vulnerability |
| cloud_resource_name | String | Resource name | e.g. vm-app-01 |
| cloud_resource_type | String | Resource type | e.g. Microsoft.Compute/virtualMachines |
| cloud_resource_group | String | Resource group | e.g. rg-app |
| is_internet_exposed | Boolean | Internet exposed | e.g. true |
| is_production | Boolean | Production | Decided by the resource tags named in the connect profile. e.g. true |
| attack_path_count | Integer | Attack paths | Attack paths that include this resource; 0 without the Defender CSPM plan. e.g. 1 |
| risk_factors | Array | Risk factors | Why Defender rated it this way, in its own words. e.g. ["InternetExposed"] |
| assessment_id | String | Recommendation ID | e.g. 11111111-1111-1111-1111-111111111111 |
| cloud_resource | String | Resource ID | e.g. /subscriptions/.../providers/Microsoft.Web/sites/app1 |
| status_cause | String | Status cause | e.g. OffByPolicy |
| status_description | String | Status description | Azure's explanation of the current status. e.g. The resource is not compliant |
| first_eval_time | Date | First evaluated | e.g. 2026-09-12 03:10:00 |
| status_change_time | Date | Status changed | When Azure last changed this status. e.g. 2026-10-01 11:20:00 |
| categories | Array | Categories | JSON array. e.g. ["Compute"] |
| recommendation_category | String | Recommendation category | e.g. Compute |
| threats | Array | Threats | JSON array. e.g. ["DataExfiltration","DataSpillage"] |
| tactics | Array | MITRE ATT&CK tactics | JSON array of tactic names. e.g. ["Initial Access"] |
| techniques | Array | MITRE ATT&CK techniques | JSON array of technique names; the screens resolve them to TIDs. e.g. ["Exploit Public-Facing Application"] |
| implementation_effort | String | Implementation effort | e.g. Low |
| user_impact | String | User impact | e.g. High |
| assessment_type | String | Assessment type | e.g. BuiltIn |
| is_preview | Boolean | Preview | e.g. false |
| resource_source | String | Cloud | Which cloud the resource belongs to. e.g. Azure |
| software_name | String | Package | Vulnerable package, on a vulnerability finding. e.g. openssh-client |
| software_vendor | String | Vendor | e.g. canonical |
| detected_versions | Array | Detected versions | JSON array of the versions found. e.g. ["1:8.9p1-3ubuntu0.4"] |
| fixed_version | String | Fixed version | The version that closes it, which is the actionable half of the finding. e.g. 1:8.9p1-3ubuntu0.13 |
| max_cvss_score | Double | Max CVSS | Highest CVSS among the CVEs on this finding. e.g. 9.8 |
| cves | Array | CVEs | JSON array as Defender publishes it. e.g. [{"CveId":"CVE-2023-51385"}] |
| description | String | Description | Azure writes this as an HTML fragment. e.g. Audit virtual machines without... |
| remediation_description | String | Remediation | e.g. From Defender for Cloud's Environment settings page, select the subscription... |
| policy_definition_id | String | Policy definition ID | e.g. /providers/Microsoft.Authorization/policyDefinitions/... |
| portal_uri | String | Portal link | Deep link into the Azure portal. e.g. https://portal.azure.com/#blade/... |
| row_key | String | Row key | SHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6... |
| snapshot_id | String | Snapshot ID | The collection cycle that last wrote this row. e.g. 00000000-0000-0000-... |
| updated | Date | Collected at | e.g. 2026-10-05 00:34:15 |