Microsoft Defender for Cloud

Download 0
Last updated Oct 5, 2026

defender-cloud-changes

Lists posture transitions found between collection cycles of Microsoft Defender for Cloud data: newly found, resolved and reopened recommendations. Unchanged findings produce no rows.

defender-cloud-changes [profile=VALUE] [subscription=VALUE] [change-type=VALUE] [risk=VALUE]
profile=VALUE
Optional. e.g. mdc
subscription=VALUE
Optional. e.g. 00000000-0000-0000-0000-000000000000
change-type=VALUE
Optional. NEW, RESOLVED or REOPENED. e.g. NEW
risk=VALUE
Optional. Defender's risk level as of the change. LOW, MEDIUM or HIGH. e.g. HIGH

Output fields

FieldTypeNameDescription
changed_atDateChanged ate.g. 2026-10-04 09:00:00
profileStringProfilee.g. mdc
cloud_accountStringSubscription IDe.g. 00000000-0000-0000-0000-000000000000
change_typeStringChange typee.g. NEW - NEW, RESOLVED or REOPENED
assessment_nameStringRecommendatione.g. Microsoft Defender for App Service should be enabled
cloud_resource_nameStringResourcee.g. app1
cloud_resource_typeStringResource typee.g. Microsoft.Compute/virtualMachines
prev_statusStringPrevious statuse.g. Healthy - empty on first sighting
curr_statusStringCurrent statuse.g. Unhealthy
riskStringRisk levelDefender's rating at the time of the change. e.g. HIGH
risk_scoreIntegerRisk rankRank of the level, for sorting: 4 Critical, 3 High, 2 Medium, 1 Low. e.g. 3.0
severityStringSeveritySeverity of the recommendation template. e.g. High
assessment_idStringRecommendation IDe.g. 11111111-1111-1111-1111-111111111111 - joins to defender-cloud-assessments
cloud_resourceStringResource IDe.g. /subscriptions/.../providers/Microsoft.Web/sites/app1
idIntegerEvent IDAuto-increment, so it also orders events recorded in the same second. e.g. 4821