Microsoft Defender for Cloud

Download 0
Last updated Oct 5, 2026

Install Guide

What you need before installing

Microsoft Defender for Cloud publishes its posture data through Azure Resource Graph. This app reads it with a service principal, so the work is mostly in Azure: register an application, give it the right role, and enter its credentials.

Defender for Cloud itself must already be enabled on the subscriptions you want to see. The app reads what Defender has assessed; it does not turn Defender on.

1. Register an application in Microsoft Entra ID

  1. Open Microsoft Entra ID → App registrations → New registration.
  2. Give it a name such as logpresso-defender-cloud, choose Single tenant, and register.
  3. From the overview page, copy the Application (client) ID and the Directory (tenant) ID.
  4. Open Certificates & secrets → New client secret, set an expiry, and copy the Value immediately. It is shown once.

No API permissions need to be added. Access to Azure resources comes from the role assignment in the next step, not from Entra ID application permissions.

2. Assign the Reader role

Assign Reader to the application on every subscription you want to collect.

SP=$(az ad sp show --id APPLICATION_ID --query id -o tsv)

az role assignment create \
  --assignee-object-id $SP --assignee-principal-type ServicePrincipal \
  --role Reader --scope /subscriptions/SUBSCRIPTION_ID

Replace APPLICATION_ID with the client ID from step 1 and SUBSCRIPTION_ID with each subscription. In the portal the same assignment is Subscription → Access control (IAM) → Add role assignment → Reader → the registered application.

To cover subscriptions created later, assign the role once at the management group root instead. This requires elevated access at the root scope, which not every tenant permits.

az role assignment create \
  --assignee-object-id $SP --assignee-principal-type ServicePrincipal \
  --role Reader --scope /providers/Microsoft.Management/managementGroups/TENANT_ID

Reader, not Security Reader. Security Reader grants Microsoft.Security/*/read, which is enough for recommendations and compliance but not for the resource graph that the inventory is built from. With Security Reader alone the recommendations appear and the inventory is missing the resources they refer to. Reader covers both.

3. Register the connect profile

Open System → Connect profiles → Add and choose Microsoft Defender for Cloud.

FieldValue
Tenant IDDirectory (tenant) ID from step 1
Client IDApplication (client) ID from step 1
Client secretThe secret value from step 1
Subscription IDsLeave empty to collect every visible subscription
HTTP proxyIP:PORT, only if outbound traffic requires one
Connect timeoutSeconds. Default 30
Read timeoutSeconds. Default 120

Leaving Subscription IDs empty is the usual choice: the app then collects every subscription the service principal can see, and a new subscription appears without editing the profile. Fill it in only to deliberately narrow the scope.

Select Test connection before saving. The test reports three failures separately, because each has a different fix:

MessageCause
Token request failedTenant ID, client ID or secret is wrong, or the secret has expired
No subscriptions visibleThe role assignment is missing or has not propagated yet
Resource Graph query failedThe role is assigned but lacks read access to security data

A role assignment can take a few minutes to take effect. If the test fails immediately after assigning the role, wait and try again before changing anything.

4. Run the first collection

Open Microsoft Defender for Cloud → Security Posture and select Collect now. The cycle runs through subscriptions, the asset inventory, attack paths, recommendations, controls, compliance, vulnerabilities, scores and the change log, reporting progress as it goes.

A full cycle takes seconds to a few minutes depending on tenant size. Most of it is the compliance data, which is the largest single result.

Then select Auto collect and enable a schedule. Hourly suits most tenants; Defender itself re-evaluates on its own cadence, so collecting more often mostly repeats identical data.

On a redundant pair both nodes run the timer, but only one runs the cycle. The claim is a conditional update in the database rather than a check of which node is active, because during a failover both nodes can believe they are active and two cycles against one database delete each other's rows.

5. Confirm it worked

Compare the app against the Azure portal. The numbers should agree exactly.

ScreenPortal page
Security PostureDefender for Cloud → Overview
RecommendationsDefender for Cloud → Recommendations
InventoryDefender for Cloud → Inventory
Regulatory ComplianceDefender for Cloud → Regulatory compliance

From a query prompt:

defender-cloud-assessments profile=PROFILE status=Unhealthy | head 10

Replace PROFILE with the profile identifier you registered.

Troubleshooting

SymptomWhat to check
Only some subscriptions appearThe role is assigned per subscription; az role assignment list --assignee APPLICATION_ID --all shows the scopes
Resources are missing from the inventoryThe role is Security Reader rather than Reader. The app logs a warning naming the subscription and keeps the assessed resources rather than hiding them
Attack paths are emptyAttack path analysis requires the Defender CSPM plan. The screen says so rather than showing an empty table
Risk levels are blankDefender publishes a contextual risk level only for some findings. The app leaves the rest unrated rather than substituting severity, which is what the portal does
Collection stops working after monthsThe client secret expired. Create a new one and update the profile

See the extension command documentation for the full option and output field definitions.