Assessments Metadata - List

Get metadata information on all assessment types

GET https://management.azure.com/providers/Microsoft.Security/assessmentMetadata?api-version=2020-01-01

URI Parameters

Name In Required Type Description
api-version
query True

string

API version for the operation

Responses

Name Type Description
200 OK

SecurityAssessmentMetadataList

OK

Other Status Codes

CloudError

Error response describing why the operation failed.

Security

azure_auth

Azure Active Directory OAuth2 Flow

Type: oauth2
Flow: implicit
Authorization URL: https://login.microsoftonline.com/common/oauth2/authorize

Scopes

Name Description
user_impersonation impersonate your user account

Examples

List security assessment metadata

Sample Request

GET https://management.azure.com/providers/Microsoft.Security/assessmentMetadata?api-version=2020-01-01

Sample Response

{
  "value": [
    {
      "id": "/providers/Microsoft.Security/assessmentMetadata/21300918-b2e3-0346-785f-c77ff57d243b",
      "name": "21300918-b2e3-0346-785f-c77ff57d243b",
      "type": "Microsoft.Security/assessmentMetadata",
      "properties": {
        "displayName": "Install endpoint protection solution on virtual machine scale sets",
        "policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/26a828e1-e88f-464e-bbb3-c134a282b9de",
        "description": "Install an endpoint protection solution on your virtual machines scale sets, to protect them from threats and vulnerabilities.",
        "remediationDescription": "To install an endpoint protection solution: 1.  <a href=\"https://docs.microsoft.com/azure/virtual-machine-scale-sets/virtual-machine-scale-sets-faq#how-do-i-turn-on-antimalware-in-my-virtual-machine-scale-set\">Follow the instructions in How do I turn on antimalware in my virtual machine scale set</a>",
        "categories": [
          "Compute"
        ],
        "severity": "Medium",
        "userImpact": "Low",
        "implementationEffort": "Low",
        "threats": [
          "dataExfiltration",
          "dataSpillage",
          "maliciousInsider"
        ],
        "assessmentType": "BuiltIn"
      }
    },
    {
      "id": "/providers/Microsoft.Security/assessmentMetadata/bc303248-3d14-44c2-96a0-55f5c326b5fe",
      "name": "bc303248-3d14-44c2-96a0-55f5c326b5fe",
      "type": "Microsoft.Security/assessmentMetadata",
      "properties": {
        "displayName": "Close management ports on your virtual machines",
        "policyDefinitionId": "/providers/Microsoft.Authorization/policyDefinitions/22730e10-96f6-4aac-ad84-9383d35b5917",
        "description": "Open remote management ports expose your VM to a high level of risk from internet-based attacks that attempt to brute force credentials to gain admin access to the machine.",
        "remediationDescription": "We recommend that you edit the inbound rules of the below virtual machines to restrict access to specific source ranges.<br>To restrict the access to your virtual machines: 1. Click on a VM from the list below 2. At the 'Networking' blade, click on each of the rules that allow management ports (e.g. RDP-3389, WINRM-5985, SSH-22) 3. Change the 'Action' property to 'Deny' 4. Click 'Save'",
        "categories": [
          "Networking"
        ],
        "severity": "Medium",
        "userImpact": "High",
        "implementationEffort": "Low",
        "threats": [
          "dataExfiltration",
          "dataSpillage",
          "maliciousInsider"
        ],
        "preview": true,
        "assessmentType": "CustomPolicy"
      }
    },
    {
      "id": "/providers/Microsoft.Security/assessmentMetadata/ca039e75-a276-4175-aebc-bcd41e4b14b7",
      "name": "ca039e75-a276-4175-aebc-bcd41e4b14b7",
      "type": "Microsoft.Security/assessmentMetadata",
      "properties": {
        "displayName": "My organization security assessment",
        "description": "Assessment that my organization created to view our security assessment in Azure Security Center",
        "remediationDescription": "Fix it with these remediation instructions",
        "categories": [
          "Compute"
        ],
        "severity": "Medium",
        "userImpact": "Low",
        "implementationEffort": "Low",
        "threats": [],
        "assessmentType": "CustomerManaged"
      }
    }
  ]
}

Definitions

Name Description
assessmentType

BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition

categories
CloudError

Common error response for all Azure Resource Manager APIs to return error details for failed operations. (This also follows the OData error response format.).

CloudErrorBody

The error detail.

ErrorAdditionalInfo

The resource management error additional info.

implementationEffort

The implementation effort required to remediate this assessment

SecurityAssessmentMetadata

Security assessment metadata

SecurityAssessmentMetadataList

List of security assessment metadata

SecurityAssessmentMetadataPartnerData

Describes the partner that created the assessment

severity

The severity level of the assessment

threats
userImpact

The user impact of the assessment

assessmentType

BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition

Name Type Description
BuiltIn

string

Microsoft Defender for Cloud managed assessments

CustomPolicy

string

User defined policies that are automatically ingested from Azure Policy to Microsoft Defender for Cloud

CustomerManaged

string

User assessments pushed directly by the user or other third party to Microsoft Defender for Cloud

VerifiedPartner

string

An assessment that was created by a verified 3rd party if the user connected it to ASC

categories

Name Type Description
Compute

string

Data

string

IdentityAndAccess

string

IoT

string

Networking

string

CloudError

Common error response for all Azure Resource Manager APIs to return error details for failed operations. (This also follows the OData error response format.).

Name Type Description
error.additionalInfo

ErrorAdditionalInfo[]

The error additional info.

error.code

string

The error code.

error.details

CloudErrorBody[]

The error details.

error.message

string

The error message.

error.target

string

The error target.

CloudErrorBody

The error detail.

Name Type Description
additionalInfo

ErrorAdditionalInfo[]

The error additional info.

code

string

The error code.

details

CloudErrorBody[]

The error details.

message

string

The error message.

target

string

The error target.

ErrorAdditionalInfo

The resource management error additional info.

Name Type Description
info

object

The additional info.

type

string

The additional info type.

implementationEffort

The implementation effort required to remediate this assessment

Name Type Description
High

string

Low

string

Moderate

string

SecurityAssessmentMetadata

Security assessment metadata

Name Type Description
id

string

Resource Id

name

string

Resource name

properties.assessmentType

assessmentType

BuiltIn if the assessment based on built-in Azure Policy definition, Custom if the assessment based on custom Azure Policy definition

properties.categories

categories[]

The categories of resource that is at risk when the assessment is unhealthy

properties.description

string

Human readable description of the assessment

properties.displayName

string

User friendly display name of the assessment

properties.implementationEffort

implementationEffort

The implementation effort required to remediate this assessment

properties.partnerData

SecurityAssessmentMetadataPartnerData

Describes the partner that created the assessment

properties.policyDefinitionId

string

Azure resource ID of the policy definition that turns this assessment calculation on

properties.preview

boolean

True if this assessment is in preview release status

properties.remediationDescription

string

Human readable description of what you should do to mitigate this security issue

properties.severity

severity

The severity level of the assessment

properties.threats

threats[]

Threats impact of the assessment

properties.userImpact

userImpact

The user impact of the assessment

type

string

Resource type

SecurityAssessmentMetadataList

List of security assessment metadata

Name Type Description
nextLink

string

The URI to fetch the next page.

value

SecurityAssessmentMetadata[]

Security assessment metadata

SecurityAssessmentMetadataPartnerData

Describes the partner that created the assessment

Name Type Description
partnerName

string

Name of the company of the partner

productName

string

Name of the product of the partner that created the assessment

secret

string

Secret to authenticate the partner and verify it created the assessment - write only

severity

The severity level of the assessment

Name Type Description
High

string

Low

string

Medium

string

threats

Name Type Description
accountBreach

string

dataExfiltration

string

dataSpillage

string

denialOfService

string

elevationOfPrivilege

string

maliciousInsider

string

missingCoverage

string

threatResistance

string

userImpact

The user impact of the assessment

Name Type Description
High

string

Low

string

Moderate

string