Install Guide
What you need before installing
Microsoft Defender for Cloud publishes its posture data through Azure Resource Graph. This app reads it with a service principal, so the work is mostly in Azure: register an application, give it the right role, and enter its credentials.
Defender for Cloud itself must already be enabled on the subscriptions you want to see. The app reads what Defender has assessed; it does not turn Defender on.
1. Register an application in Microsoft Entra ID
- Open Microsoft Entra ID → App registrations → New registration.
- Give it a name such as
logpresso-defender-cloud, choose Single tenant, and register. - From the overview page, copy the Application (client) ID and the Directory (tenant) ID.
- Open Certificates & secrets → New client secret, set an expiry, and copy the Value immediately. It is shown once.
No API permissions need to be added. Access to Azure resources comes from the role assignment in the next step, not from Entra ID application permissions.
2. Assign the Reader role
Assign Reader to the application on every subscription you want to collect.
SP=$(az ad sp show --id APPLICATION_ID --query id -o tsv)
az role assignment create \
--assignee-object-id $SP --assignee-principal-type ServicePrincipal \
--role Reader --scope /subscriptions/SUBSCRIPTION_ID
Replace APPLICATION_ID with the client ID from step 1 and SUBSCRIPTION_ID with each
subscription. In the portal the same assignment is Subscription → Access control (IAM) → Add
role assignment → Reader → the registered application.
To cover subscriptions created later, assign the role once at the management group root instead. This requires elevated access at the root scope, which not every tenant permits.
az role assignment create \
--assignee-object-id $SP --assignee-principal-type ServicePrincipal \
--role Reader --scope /providers/Microsoft.Management/managementGroups/TENANT_ID
Reader, not Security Reader. Security Reader grants Microsoft.Security/*/read, which is
enough for recommendations and compliance but not for the resource graph that the inventory is
built from. With Security Reader alone the recommendations appear and the inventory is missing
the resources they refer to. Reader covers both.
3. Register the connect profile
Open System → Connect profiles → Add and choose Microsoft Defender for Cloud.
| Field | Value |
|---|---|
| Tenant ID | Directory (tenant) ID from step 1 |
| Client ID | Application (client) ID from step 1 |
| Client secret | The secret value from step 1 |
| Subscription IDs | Leave empty to collect every visible subscription |
| HTTP proxy | IP:PORT, only if outbound traffic requires one |
| Connect timeout | Seconds. Default 30 |
| Read timeout | Seconds. Default 120 |
Leaving Subscription IDs empty is the usual choice: the app then collects every subscription the service principal can see, and a new subscription appears without editing the profile. Fill it in only to deliberately narrow the scope.
Select Test connection before saving. The test reports three failures separately, because each has a different fix:
| Message | Cause |
|---|---|
| Token request failed | Tenant ID, client ID or secret is wrong, or the secret has expired |
| No subscriptions visible | The role assignment is missing or has not propagated yet |
| Resource Graph query failed | The role is assigned but lacks read access to security data |
A role assignment can take a few minutes to take effect. If the test fails immediately after assigning the role, wait and try again before changing anything.
4. Run the first collection
Open Microsoft Defender for Cloud → Security Posture and select Collect now. The cycle runs through subscriptions, the asset inventory, attack paths, recommendations, controls, compliance, vulnerabilities, scores and the change log, reporting progress as it goes.
A full cycle takes seconds to a few minutes depending on tenant size. Most of it is the compliance data, which is the largest single result.
Then select Auto collect and enable a schedule. Hourly suits most tenants; Defender itself re-evaluates on its own cadence, so collecting more often mostly repeats identical data.
On a redundant pair both nodes run the timer, but only one runs the cycle. The claim is a conditional update in the database rather than a check of which node is active, because during a failover both nodes can believe they are active and two cycles against one database delete each other's rows.
5. Confirm it worked
Compare the app against the Azure portal. The numbers should agree exactly.
| Screen | Portal page |
|---|---|
| Security Posture | Defender for Cloud → Overview |
| Recommendations | Defender for Cloud → Recommendations |
| Inventory | Defender for Cloud → Inventory |
| Regulatory Compliance | Defender for Cloud → Regulatory compliance |
From a query prompt:
Replace PROFILE with the profile identifier you registered.
Troubleshooting
| Symptom | What to check |
|---|---|
| Only some subscriptions appear | The role is assigned per subscription; az role assignment list --assignee APPLICATION_ID --all shows the scopes |
| Resources are missing from the inventory | The role is Security Reader rather than Reader. The app logs a warning naming the subscription and keeps the assessed resources rather than hiding them |
| Attack paths are empty | Attack path analysis requires the Defender CSPM plan. The screen says so rather than showing an empty table |
| Risk levels are blank | Defender publishes a contextual risk level only for some findings. The app leaves the rest unrated rather than substituting severity, which is what the portal does |
| Collection stops working after months | The client secret expired. Create a new one and update the profile |
See the extension command documentation for the full option and output field definitions.