User Guide
Decide what to fix first
Microsoft Defender for Cloud reports hundreds of recommendations across a tenant. This app collects them on a schedule and presents them so the list can be ordered, filtered and shared - the three things a browser tab on the Azure portal cannot do.
The usual flow is check the posture → work the recommendations → verify against compliance.
Security Posture
Opens on the secure score, its trend, and what changed since the last cycle.
The trend is the part the portal does not keep. Defender shows today's score; this screen shows whether it moved, and the change cards say how: how many findings are new, how many were resolved, and how many came back. Selecting a card opens the recommendations list already filtered to those findings.
Below that, each subscription is listed with its score and its unhealthy count, and the controls are ordered by how much score each one is still withholding. That ordering answers "what gives the most back for the least work" directly - the control at the top is worth more than the one below it.
Recommendations
The screen most of the work happens on. The header counts the risk spread across whatever the filters currently select, and the grid lists one row per recommendation per resource.
Risk is Defender's own verdict, carried through unchanged. Defender publishes a contextual risk level that accounts for exposure and reachability; it is not the same thing as severity, which rates the recommendation template. The two routinely disagree - a High severity finding on an unreachable resource is a Low risk - and the risk column is the one worth sorting by. Findings Defender did not rate in context are shown as unrated rather than filled in from severity.
Filters are checkboxes, so "High or Medium" is one view rather than two passes. Status, risk, issue type, severity, resource type, resource group and internet exposure can all be combined.
Every filter lives in the URL. Copy the link and the recipient sees the same rows. This is what makes a recommendation assignable: send the link, not a description of how to recreate it.
Selecting a row opens a panel with the description, the remediation steps, the affected resources, the MITRE ATT&CK tactics and techniques with their IDs, the compliance controls the finding maps to, and its status history. The panel overlays the list rather than resizing it, so closing it returns to the same scroll position.
Inventory
What the tenant has, which is a different question from what is wrong with it.
A resource with no findings is not necessarily safe - it may simply be unexamined - and only an asset list makes that visible. Each row shows the resource, its type, its scope, whether a Defender plan actually covers it, and a red-green bar of its findings.
The Defender plan column is worth reading carefully. A resource whose plan is Off is listed by Defender but not protected by it. That gap is invisible on the recommendations screen, because a plan that is off produces no findings to list.
Selecting a row opens the resource in three tabs: its properties, its recommendations, and its vulnerabilities. They are separated because a single virtual machine can carry hundreds of package CVEs, and stacked in one column they bury everything else.
Vulnerabilities
One row per CVE rather than one per occurrence, because the question is which CVE to deal with, not which of the thousands of CVE-and-resource pairs.
Ordered by EPSS, not CVSS. CVSS rates how damaging a flaw would be if someone exploited it; EPSS estimates the probability that anyone will. With hundreds of CVEs open and a limited patch window, the second question is the one that decides this week's work - a 9.8 nobody is exploiting can wait behind a 6.1 that is in an exploit kit.
The Known exploited filter narrows to CVEs in an exploit kit or publicly disclosed. The panel shows the EPSS score with its percentile, the CVSS vectors, the CWE identifiers, and every affected resource with the version that closes it.
Regulatory Compliance
Standards, their controls, and the assessments beneath each control.
Compliance is recorded per subscription in Azure, so the same control is evaluated separately in each one. This screen sums them: one control is one requirement however many subscriptions it applies to. Where subscriptions disagree, the worst state wins - passing in two and failing in the third is a failure.
The pass count is shown as a fraction rather than a percentage, matching the portal. 39/63 and
0/1 are different situations that a percentage would render identically.
Controls are grouped by domain and split by cloud provider, so Azure and AWS controls under the same standard stay separate. Selecting an assessment opens the same detail panel the recommendations screen uses.
Queries
Everything on the screens is also available at a query prompt, reading the same tables through the same filters.
Sorted by risk, highest first, so a bare command already answers "what first". Replace PROFILE
with your profile identifier.
To find what is both unpatched and reachable:
To see which machines carry one CVE - the vulnerability screen rolls up to one row per CVE, while this command stays at one row per affected resource:
To see what changed overnight:
To list resources no Defender plan protects:
Command output can be piped into any Logpresso query, which is how these feed alerts, reports and
dashboards. Titles follow the console language; add locale=en for the original English.
Reading the numbers honestly
| What you see | What it means |
|---|---|
| Risk is blank | Defender computed no contextual rating. Not "low risk" - unrated |
| Risk and severity disagree | Expected. Severity rates the rule, risk rates this finding on this resource |
| A resource has no findings | It was not assessed, which is not the same as compliant |
| An assessment is Not applicable | The control does not apply here. Also not the same as compliant |
| Attack paths are empty | The Defender CSPM plan is off, or its first analysis has not finished |
| A number disagrees with the portal | Collection is periodic. Check the last successful collection time in the header first |
See the extension command documentation for the full option and output field definitions.