defender-cloud-changes
Lists posture transitions found between collection cycles of Microsoft Defender for Cloud data: newly found, resolved and reopened recommendations. Unchanged findings produce no rows.
defender-cloud-changes [profile=VALUE] [subscription=VALUE] [change-type=VALUE] [risk=VALUE]
- profile=VALUE
- Optional. e.g. mdc
- subscription=VALUE
- Optional. e.g. 00000000-0000-0000-0000-000000000000
- change-type=VALUE
- Optional. NEW, RESOLVED or REOPENED. e.g. NEW
- risk=VALUE
- Optional. Defender's risk level as of the change. LOW, MEDIUM or HIGH. e.g. HIGH
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| changed_at | Date | Changed at | e.g. 2026-10-04 09:00:00 |
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| change_type | String | Change type | e.g. NEW - NEW, RESOLVED or REOPENED |
| assessment_name | String | Recommendation | e.g. Microsoft Defender for App Service should be enabled |
| cloud_resource_name | String | Resource | e.g. app1 |
| cloud_resource_type | String | Resource type | e.g. Microsoft.Compute/virtualMachines |
| prev_status | String | Previous status | e.g. Healthy - empty on first sighting |
| curr_status | String | Current status | e.g. Unhealthy |
| risk | String | Risk level | Defender's rating at the time of the change. e.g. HIGH |
| risk_score | Integer | Risk rank | Rank of the level, for sorting: 4 Critical, 3 High, 2 Medium, 1 Low. e.g. 3.0 |
| severity | String | Severity | Severity of the recommendation template. e.g. High |
| assessment_id | String | Recommendation ID | e.g. 11111111-1111-1111-1111-111111111111 - joins to defender-cloud-assessments |
| cloud_resource | String | Resource ID | e.g. /subscriptions/.../providers/Microsoft.Web/sites/app1 |
| id | Integer | Event ID | Auto-increment, so it also orders events recorded in the same second. e.g. 4821 |