A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @Andy Gibson - Admin
This looks related to the recent Defender for Cloud transition from grouped to individual recommendations, rather than a normal Azure Policy exemption issue.
Microsoft specifically lists both recommendations you mentioned as deprecated:
Guest accounts with read permissions on Azure resources should be removed Old ID: fde1c0c9-0fd2-4ecc-87b5-98956cbc1095 New ID: 422107c6-5b9a-46a6-bb1d-26ef1cc52d65
Guest accounts with write permissions on Azure resources should be removed Old ID: 0354476c-a12a-4fcc-a79d-f0ab7ffffdbb New ID: 009678ce-adce-4c94-9cc8-cfc2bd0c6a06
Microsoft also notes that during this transition the classic Defender views can show increased or unexpected resource counts, and that this doesn't necessarily represent the actual number of Azure resources. Existing governance, export, and exemption configurations should be updated to use the replacement assessment IDs.
I would therefore first validate whether the ~367/35 entries belong to the old assessment IDs or the new ones before concluding that the assessment data itself is corrupted.
Regarding the six orphaned Microsoft.Security/standardAssignments, your findings make sense. The documented DELETE API requires the original resource scope to still be addressable. If the parent VM no longer exists and both GET/DELETE return 404, I couldn't find a documented customer-side method to remove those orphaned records.
For those six entries, opening/escalating the case to the Defender for Cloud / Microsoft.Security resource provider engineering team** for backend cleanup would be appropriate.
If this answer helps, please mark it as Answered.