defender-cloud-controls
Lists secure score controls collected from Microsoft Defender for Cloud, ordered by the score still available - the controls worth fixing first.
defender-cloud-controls [profile=VALUE] [subscription=VALUE]
- profile=VALUE
- Optional. Profile identifier. Omit to read every registered tenant. e.g. mdc
- subscription=VALUE
- Optional. Azure subscription ID. e.g. 00000000-0000-0000-0000-000000000000
Output fields
| Field | Type | Name | Description |
|---|---|---|---|
| profile | String | Profile | e.g. mdc |
| cloud_account | String | Subscription ID | e.g. 00000000-0000-0000-0000-000000000000 |
| control_name | String | Control | Display name as Azure publishes it, English only. e.g. Enable MFA |
| potential_score_increase | Double | Score available | e.g. 6.0 - what fixing this control would add |
| current_score | Double | Current score | e.g. 4.0 |
| max_score | Integer | Max score | e.g. 10 |
| score_percentage | Double | Score percentage | Current score as a percentage of the maximum. e.g. 40.0 |
| unhealthy_resource_count | Integer | Unhealthy resources | e.g. 3 |
| healthy_resource_count | Integer | Healthy resources | e.g. 1 |
| not_applicable_resource_count | Integer | Not applicable resources | Resources the control does not apply to. Not the same as compliant. e.g. 2 |
| control_id | String | Control ID | e.g. 22222222-2222-2222-2222-222222222222 |
| control_type | String | Control type | e.g. BuiltIn |
| row_key | String | Row key | SHA-256 of the identity columns, stable across cycles. e.g. a1b2c3d4e5f6... |
| snapshot_id | String | Snapshot ID | The collection cycle that last wrote this row. e.g. 00000000-0000-0000-... |
| updated | Date | Collected at | e.g. 2026-10-05 00:34:15 |