Microsoft Azure

다운로드 168
업데이트 2026. 9. 7.

azure-resource-graph

접속 프로파일에 설정된 구독 전체를 대상으로 Azure Resource Graph KQL 질의를 실행합니다.

azure-resource-graph [profile=값] query=값
profile=값
선택. Azure 접속 프로파일 이름
query=값
필수. Resource Graph 질의. 예: resources | where type =~ 'microsoft.storage/storageaccounts'

출력 필드

필드타입이름설명
profile_name문자열프로파일행을 조회한 접속 프로파일. 나머지 필드는 질의가 반환하는 컬럼입니다.

예제

프로파일이 볼 수 있는 모든 구독에서 리소스 종류별 개수

azure-resource-graph profile="prod" query="resources | summarize count() by type | order by count_ desc"

스토리지 계정과 최소 TLS 버전

azure-resource-graph profile="prod" query="resources | where type =~ 'microsoft.storage/storageaccounts' | project name, resourceGroup, minimumTlsVersion = properties.minimumTlsVersion"

역할 할당 - 테이블은 다르지만 같은 엔드포인트

azure-resource-graph profile="prod" query="authorizationresources | where type =~ 'microsoft.authorization/roleassignments' | limit 10"

호출 대상과 권한

  • POST https://management.azure.com/providers/Microsoft.ResourceGraph/resources를 호출합니다. 구독 목록이 요청 본문에 실리므로 질의 한 번이 프로파일의 모든 구독을 대상으로 합니다.
  • 점검 대상 구독마다 앱 등록에 Reader 역할이 부여되어 있어야 합니다. 인증은 되는데 할당된 구독이 없으면 오류가 아니라 빈 결과가 돌아옵니다.
  • Resource Graph는 KQL의 부분집합만 지원하며(render와 시계열 함수 없음) 자체 테이블(resources, resourcecontainers, authorizationresources, securityresources, policyresources)을 제공합니다. Log Analytics가 아니므로 AzureActivity나 SigninLogs는 조회할 수 없습니다.