Microsoft Defender for Cloud

Download 0
Last updated Oct 5, 2026

defender-cloud-assessments

Lists security recommendations collected from Microsoft Defender for Cloud, one row per recommendation per resource, ordered by Defender's own risk level.

defender-cloud-assessments [profile=VALUE] [subscription=VALUE] [status=VALUE] [risk=VALUE] [min-risk-score=VALUE] [severity=VALUE] [security-issue=VALUE] [resource-type=VALUE] [resource-group=VALUE] [exposed=VALUE] [keyword=VALUE] [locale=VALUE]
profile=VALUE
Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
subscription=VALUE
Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
status=VALUE
Optional. Healthy, Unhealthy or NotApplicable. e.g. Unhealthy
risk=VALUE
Optional. Defender's risk level, stored as LOW, MEDIUM or HIGH. A Critical finding is stored as HIGH, so use min-risk-score to single it out. e.g. HIGH
min-risk-score=VALUE
Optional. Rank floor: 4 Critical, 3 High, 2 Medium, 1 Low. 4 returns Critical only. e.g. 4
severity=VALUE
Optional. Severity of the recommendation template. Not the same thing as risk: it rates the rule rather than this finding, and the two often disagree. e.g. High
security-issue=VALUE
Optional. Problem class, which separates package patches from configuration findings. e.g. Vulnerability
resource-type=VALUE
Optional. e.g. Microsoft.Compute/virtualMachines
resource-group=VALUE
Optional. e.g. rg-app
exposed=VALUE
Optional. t to return only internet-reachable resources. e.g. t
keyword=VALUE
Optional. Substring of the recommendation title or resource name. e.g. endpoint
locale=VALUE
Optional. Language of the title, description and remediation. Defaults to the console session's language; en returns Azure's original text. e.g. ko

Output fields

FieldTypeNameDescription
profileStringProfilee.g. mdc
cloud_accountStringSubscription IDe.g. 00000000-0000-0000-0000-000000000000
assessment_nameStringRecommendatione.g. Microsoft Defender for App Service should be enabled
statusStringStatuse.g. Unhealthy
riskStringRisk levelDefender's own contextual rating, carried through unchanged. e.g. HIGH
risk_scoreIntegerRisk rankRank of the level so ORDER BY sorts correctly, not a measurement: 4 Critical, 3 High, 2 Medium, 1 Low. e.g. 3.0
severityStringSeveritySeverity of the recommendation template, which can disagree with risk. e.g. High
security_issueStringIssue typee.g. Vulnerability
cloud_resource_nameStringResource namee.g. vm-app-01
cloud_resource_typeStringResource typee.g. Microsoft.Compute/virtualMachines
cloud_resource_groupStringResource groupe.g. rg-app
is_internet_exposedBooleanInternet exposede.g. true
is_productionBooleanProductionDecided by the resource tags named in the connect profile. e.g. true
attack_path_countIntegerAttack pathsAttack paths that include this resource; 0 without the Defender CSPM plan. e.g. 1
risk_factorsArrayRisk factorsWhy Defender rated it this way, in its own words. e.g. ["InternetExposed"]
assessment_idStringRecommendation IDe.g. 11111111-1111-1111-1111-111111111111
cloud_resourceStringResource IDe.g. /subscriptions/.../providers/Microsoft.Web/sites/app1
status_causeStringStatus causee.g. OffByPolicy
status_descriptionStringStatus descriptionAzure's explanation of the current status. e.g. The resource is not compliant
first_eval_timeDateFirst evaluatede.g. 2026-09-12 03:10:00
status_change_timeDateStatus changedWhen Azure last changed this status. e.g. 2026-10-01 11:20:00
categoriesArrayCategoriesJSON array. e.g. ["Compute"]
recommendation_categoryStringRecommendation categorye.g. Compute
threatsArrayThreatsJSON array. e.g. ["DataExfiltration","DataSpillage"]
tacticsArrayMITRE ATT&CK tacticsJSON array of tactic names. e.g. ["Initial Access"]
techniquesArrayMITRE ATT&CK techniquesJSON array of technique names; the screens resolve them to TIDs. e.g. ["Exploit Public-Facing Application"]
implementation_effortStringImplementation efforte.g. Low
user_impactStringUser impacte.g. High
assessment_typeStringAssessment typee.g. BuiltIn
is_previewBooleanPreviewe.g. false
resource_sourceStringCloudWhich cloud the resource belongs to. e.g. Azure
software_nameStringPackageVulnerable package, on a vulnerability finding. e.g. openssh-client
software_vendorStringVendore.g. canonical
detected_versionsArrayDetected versionsJSON array of the versions found. e.g. ["1:8.9p1-3ubuntu0.4"]
fixed_versionStringFixed versionThe version that closes it, which is the actionable half of the finding. e.g. 1:8.9p1-3ubuntu0.13
max_cvss_scoreDoubleMax CVSSHighest CVSS among the CVEs on this finding. e.g. 9.8
cvesArrayCVEsJSON array as Defender publishes it. e.g. [{"CveId":"CVE-2023-51385"}]
descriptionStringDescriptionAzure writes this as an HTML fragment. e.g. Audit virtual machines without...
remediation_descriptionStringRemediatione.g. From Defender for Cloud's Environment settings page, select the subscription...
policy_definition_idStringPolicy definition IDe.g. /providers/Microsoft.Authorization/policyDefinitions/...
portal_uriStringPortal linkDeep link into the Azure portal. e.g. https://portal.azure.com/#blade/...
row_keyStringRow keySHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6...
snapshot_idStringSnapshot IDThe collection cycle that last wrote this row. e.g. 00000000-0000-0000-...
updatedDateCollected ate.g. 2026-10-05 00:34:15