2 orphan resources pop up in Defender Inventory. How to remove?

FreGee 1 Reputation point
2024-04-03T00:27:01.2433333+00:00

This are the two resources I can not remove.

The resource-groups do not exist: default-oms-westeurope, default-loganalytics-workspace

"RESOURCETYPE","EXEMPTIONTYPE","TYPEFULLPATH","RESOURCEID","RESOURCENAME","SUBSCRIPTIONDISPLAYNAME","SUBSCRIPTIONID","ENVIRONMENT","OSTYPE","WORKSPACENAME","AGENTMONITORING","ASSESSMENTSSUMMARY","SUBSCRIPTIONPRICING","PRICING","UNHEALTHYASSESSMENTSCOUNT","RESOURCEGROUP"

"microsoft.operationalinsights/workspaces/onpremisemachines","No","microsoft.operationalinsights/workspaces/onpremisemachines","/subscriptions/b12566c0-af69-4b40-9b51-0217c396ed63/resourcegroups/default-oms-westeurope/providers/microsoft.operationalinsights/workspaces/workspacenameplaceholder/onpremisemachines/vsql5.dc1.xxxxxx_49434d53-0200-2500-90d7-002590d7eef8","vsql5.dc1.xxxxxx_49434d53-0200-2500-90d7-002590d7eef8","xxxxxx","b12566c0-af69-4b40-9b51-0217c396ed63","non-azure","","","","{""notapplicable"":1,""low"":0,""medium"":0,""high"":0,""healthy"":0}","null","","0","default-oms-westeurope"

"microsoft.operationalinsights/workspaces/onpremisemachines","No","microsoft.operationalinsights/workspaces/onpremisemachines","/subscriptions/b12566c0-af69-4b40-9b51-0217c396ed63/resourcegroups/default-loganalytics-workspace/providers/microsoft.operationalinsights/workspaces/workspacenameplaceholder/onpremisemachines/vws6.dc1.vrumun_00000000-0000-0000-0000-ac1f6becb0e8","vws6.dc1.xxxxxx_00000000-0000-0000-0000-ac1f6becb0e8","xxxxxx","b12566c0-af69-4b40-9b51-0217c396ed63","non-azure","","","","{""notapplicable"":1,""low"":0,""medium"":0,""high"":0,""healthy"":0}","null","","0","default-loganalytics-workspace"

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,281 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Shweta Mathur 29,681 Reputation points Microsoft Employee
    2024-04-03T06:34:54.0833333+00:00

    Hi @FreGee ,

    Thanks for reaching out.

    Defender for Cloud relies on an Azure Monitor workspace and the Azure Resource Graph. The data in these tables may take time to drop from your views. Especially anything originating from the workspace.

    This data is largely immutable and cannot be modified or removed. I assume you many need to let these records expire. It depends on how the view you are using is designed.

    It usually took 36 hours from deletion to disappear from inventory.

    Hope this will help.

    Thanks,

    Shweta

    Please remember to "Accept Answer" if answer helped you.