Microsoft Defender for Cloud: Azure Resource Graph Not Returning VM Vulnerability Assessment Coverage

Joshua Li 0 Reputation points
2026-09-25T20:56:23.74+00:00

Problem description

I am experiencing an issue where Azure Resource Graph is not returning the vulnerability coverage assessment for my virtual machines in Microsoft Defender for Cloud. Specifically, when querying for the assessment by its ID, no results are returned, even though other assessments are visible in Resource Graph.

Environment

Microsoft Defender for Cloud assessment data queried through Azure Resource Graph for one Azure subscription; no specific subscription name, resource group, VM name, or region provided.

What I've already tried

I used the following query to look for the assessment:

securityresources
| where type =~ 'microsoft.security/assessments'
| where name =~ '{assessment-id}'

This query returned no rows. I also ran a broader query:

microsoft.security/assessments

which returned other Defender for Cloud assessments, confirming that assessment data exists in Resource Graph generally.

Current status

The issue persists: the specific VM vulnerability coverage assessment is missing from Resource Graph, while other assessments are present. I am seeking guidance on potential causes and steps to resolve or troubleshoot further.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud

1 answer

Sort by: Most helpful
  1. Joshua Li 0 Reputation points
    2026-10-05T17:12:10.3166667+00:00

    With thanks to Microsoft Support: I am told that

    As part of the transition from grouped to individual recommendations in Microsoft Defender for Cloud, the"Machines should have a vulnerability assessment solution" recommendation is being deprecated.
    At this time, I have not found any Microsoft documentation that provides a replacement assessment ID for ffff0522-1e88-47fc-8382-2a80ba848f5d. Instead, the current guidance is to use the individual recommendations available in Defender for Cloud to review vulnerability assessment coverage.
    To help identify machines that do not have vulnerability assessment coverage, please use the Azure Resource Graph (ARG) query below.
    Before running the query, please replace 'xxx' with the appropriate Subscription ID(s).  Reference Article: Transition from grouped to individual recommendations in Defender for Cloud - Microsoft Defender for Cloud | Microsoft Learn  Please review the Microsoft Defender for Servers section in the article for additional details regarding the deprecation of the recommendation.

    resources 
    | where type in ('microsoft.compute/virtualmachines','microsoft.hybridcompute/machines') 
    | where subscriptionId in ('xxx') 
    | where type != 'microsoft.hybridcompute/machines' or tostring(properties.status) == 'Connected' 
    | extend machineId = tolower(id) 
    | extend nodeResourceGroupKey = strcat(subscriptionId, '/', tolower(resourceGroup)) 
    | join kind=leftouter ( 
       resources 
       | where type == 'microsoft.containerservice/managedclusters' 
       | project nodeResourceGroupKey = strcat(subscriptionId, '/', tolower(tostring(properties.nodeResourceGroup))), isKubernetesNode = 1 
       | distinct nodeResourceGroupKey, isKubernetesNode 
    ) on nodeResourceGroupKey 
    | where isempty(isKubernetesNode) 
    | join kind=leftouter ( 
       securityresources 
       | where type == 'microsoft.security/softwareinventories' 
       | project machineId = tolower(substring(id, 0, indexof(tolower(id), '/providers/microsoft.security/softwareinventories/'))), hasSoftwareInventory = 1 
       | distinct machineId, hasSoftwareInventory 
    ) on machineId 
    | where isempty(hasSoftwareInventory) 
    | project Machine = name, ResourceGroup = resourceGroup, Subscription = subscriptionId, Type = type, Location = location, MachineId = id 
    | order by Machine asc
    
    

    Therefore: the answer to the question is "it disappeared; but it is meant to". It is up to us the users to adapt.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.