A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
With thanks to Microsoft Support: I am told that
As part of the transition from grouped to individual recommendations in Microsoft Defender for Cloud, the"Machines should have a vulnerability assessment solution" recommendation is being deprecated.
At this time, I have not found any Microsoft documentation that provides a replacement assessment ID for ffff0522-1e88-47fc-8382-2a80ba848f5d. Instead, the current guidance is to use the individual recommendations available in Defender for Cloud to review vulnerability assessment coverage.
To help identify machines that do not have vulnerability assessment coverage, please use the Azure Resource Graph (ARG) query below.
Before running the query, please replace 'xxx' with the appropriate Subscription ID(s). Reference Article: Transition from grouped to individual recommendations in Defender for Cloud - Microsoft Defender for Cloud | Microsoft Learn Please review the Microsoft Defender for Servers section in the article for additional details regarding the deprecation of the recommendation.
resources
| where type in ('microsoft.compute/virtualmachines','microsoft.hybridcompute/machines')
| where subscriptionId in ('xxx')
| where type != 'microsoft.hybridcompute/machines' or tostring(properties.status) == 'Connected'
| extend machineId = tolower(id)
| extend nodeResourceGroupKey = strcat(subscriptionId, '/', tolower(resourceGroup))
| join kind=leftouter (
resources
| where type == 'microsoft.containerservice/managedclusters'
| project nodeResourceGroupKey = strcat(subscriptionId, '/', tolower(tostring(properties.nodeResourceGroup))), isKubernetesNode = 1
| distinct nodeResourceGroupKey, isKubernetesNode
) on nodeResourceGroupKey
| where isempty(isKubernetesNode)
| join kind=leftouter (
securityresources
| where type == 'microsoft.security/softwareinventories'
| project machineId = tolower(substring(id, 0, indexof(tolower(id), '/providers/microsoft.security/softwareinventories/'))), hasSoftwareInventory = 1
| distinct machineId, hasSoftwareInventory
) on machineId
| where isempty(hasSoftwareInventory)
| project Machine = name, ResourceGroup = resourceGroup, Subscription = subscriptionId, Type = type, Location = location, MachineId = id
| order by Machine asc
Therefore: the answer to the question is "it disappeared; but it is meant to". It is up to us the users to adapt.