Skip to content
Jussi Metso
Jussi Metso

It's all about The Cloud and The Security

  • Posts
  • About the blog
  • Activity
  • Connect!
  • Privacy Policy
Jussi Metso

It's all about The Cloud and The Security

June 22, 2024May 25, 2025

Defender for Cloud – Part 2: The Asset Inventory 

Table of Contents

Asset Inventory

The asset inventory page  shows the security posture of the resources you’ve connected to Defender for Cloud. Defender for Cloud periodically analyzes the security state of resources connected to your subscriptions to identify potential security issues and provides you with active recommendations. 

Use this view and its filters to address such questions as:

  • Which of my subscriptions with Defender plans enabled have outstanding recommendations?
  • Which of my machines with the tag ‘Production’ are missing the Log Analytics agent?
  • How many of my machines tagged with a specific tag have outstanding recommendations?
  • Which machines in a specific resource group have a known vulnerability (using a CVE number)?

The security recommendations on the asset inventory page are also shown in the Recommendations page, but here they’re shown according to the affected resource.

Also a new feature called Critical Assets are shown.

Key features

1. Inventory

Inventory shows ALL your Azure resources, your other connected resources like in my case Amazon Web Services -connected resources. It shows where they are located, recommedations for those resources. You can search for example installed applications and vulnerabilities to those. These features were in lot of use before the Cloud Security Explorer function. 

And if you like to drill in to resource you just click the resource like in this example of my ubuntu server:

2. Summaries

  • Total resources: The total number of resources connected to Defender for Cloud.
  • Unhealthy resources: Resources with active security recommendations that you can implement. Learn more about implementing security recommendations.
  • Unmonitored resources: Resources with agent monitoring issues – they have the Log Analytics agent deployed, but the agent isn’t sending data or has other health issues.
  • Unregistered subscriptions: Any subscription in the selected scope that hasn’t yet been connected to Microsoft Defender for Cloud.

3. Filters

With filters you can provide a quick way to refine the list of resources according to the question you’re trying to answer.

4. Export tools

Inventory includes an option to export the results of your selected filter options to a CSV file. You can also export the query itself to Azure Resource Graph Explorer to further refine, save, or modify the Kusto Query Language (KQL) query.

You can also add non-Azure servers to the inventory which actually means that you can install a log analytics agent to a non-Azure like on-prem windows/linux server.

So if you press that link above you end up this view:

and from there you finally end up this view if you do as instructions say:

1.You can see the summary of connected windows or linux servers and you can add Data Collection rules to that Azure monitor agent you are about to install:

2.Here you can have installers for a windows/linux machines and get the needed information to those installers:

  • Workspace ID
  • Primary key
  • Secondary key

It’s also possible download the Log Analytics Gateway to act as a proxy if you have machines without Internet connectivity

That was kind of all from the Asset inventory. Stay tuned. The next part is coming. 

The parts of the MDC blog series

 
  • Part 0: Microsoft Defender for Cloud – The EPIC blog series – introduction
  • Part 1: Getting started aka Setup 
  • Part 2: The Asset Inventory 
  • Part 3: Security posture
  • Part 4: Security recommendations
  • Part 5: Security alerts
  • Part 6: Attack path analysis
  • Part 7: Cloud security explorer
  • Part 8: Workbooks
  • Part 9: Regulatory compliance
  • Part 10: Workload protections
  • part 10.5: Advanced Workload protection
  • Part 11: Data and AI security – The end of the series
Picture of Jussi Metso

Jussi Metso

Author is a a lifelong IT enthusiast, Microsoft Security MVP and interested in Cloud Security, XDR, SIEM and AI. Motto: Learning is the key for your future.
Share on Social Media
xfacebooklinkedinwhatsapp

Discover more from Jussi Metso

Subscribe to get the latest posts sent to your email.

DEFENDER FOR CLOUD #cloudsecurity#mdcseries

Post navigation

Previous post
Next post

Related Posts

DEFENDER FOR CLOUD

Defender for Cloud – Part 11: Data and AI Security

May 27, 2025May 25, 2025

The Data and AI security overview section displays your cloud data and AI estate for each cloud. It includes all data and AI resources, categorized into storage assets, managed databases, hosted databases (IaaS), and AI services.

Read More
DEFENDER FOR CLOUD

Enabling Cloud Security in Defender portal

June 22, 2026June 22, 2026

Microsoft Defender for Cloud (MDC) is now deeply integrated into the Defender portal at security.microsoft.com and part of the broader Microsoft Security eco-system.

Read More
DEFENDER FOR CLOUD

Defender for Cloud – Part 9: Regulatory compliance

March 13, 2025May 25, 2025

Microsoft Defender for Cloud provides Regulatory Compliance capabilities to help organizations assess and maintain compliance with industry standards, frameworks, and regulatory requirements. It continuously monitors cloud resources and provides insights into security posture, ensuring alignment with compliance benchmarks.

Read More

Link to my MVP profile:

Subscribe my blog to get updates!

Join 42 other subscribers

Recent Posts

  • The PAW, PIM and the Conditional Access setup and some Entra ID attack vectors
  • Descriptions (& some instructions) for the Red Tenant
  • Enterprise Access Model (EAM) – part of Red tenant story
  • Red Forest: The predecessor of EAM
  • Conditional Access (CA) Policy templates

Top posts:

Defender for Cloud – Part 10: Cloud Workload protection (CWP)
NextGen Defender for Cloud: Phase 1 - public preview
Malware automated remediation in Defender for Storage
Defender for Cloud - Part 6: Attack Path Analysis
Defender for Cloud – Part 5: Security Alerts

Categories

  • AI (7)
  • AUTHOR (1)
  • BOOKREVIEW (1)
  • CSPM (2)
  • DATA SECURITY (1)
  • DEFENDER FOR CLOUD (19)
  • DEFENDER FOR DEVOPS (1)
  • entraid (1)
  • IDENTITY_ACCESS (3)
  • LEARNING (1)
  • MVP (1)
  • RED (3)
  • SECURITY (14)
  • SECURITYCOPILOT (1)
  • SENTINEL (5)
  • THREAT INTELLIGENCE (1)
  • XDR (3)

Tags

#activedirectory (1) #architecture (1) #azure (1) #bookreview (2) #cloudsecurity (18) #condiftionalaccess (1) #defenderforcloud (2) #defenderforstorage (1) #defenderxdr (3) #entraid (1) #identityaccess (2) #malwarescan (1) #mdcseries (13) #mitreattack (1) #redforest (1) #redtenant (4) #securitycopilot (1) #sentinel (3) #siem (3) #soc (3) entraid (1) identityaccess (1)

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • March 2026
  • February 2026
  • December 2025
  • November 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025
  • April 2025
  • March 2025
  • February 2025
  • January 2025
  • November 2024
  • October 2024
  • September 2024
  • August 2024
  • June 2024
  • April 2024
  • January 2024
  • December 2023
  • October 2023
  • August 2023
  • June 2023
  • May 2023
  • April 2023
  • January 2023
  • December 2022
  • November 2022

Visits on my site

27,087 hits

©2022-2026 Jussi Metso. All rights reserved.