Microsoft Defender for Cloud through Azure Resource Graph. For reference, you can find this health advisory notification in the Azure portal using tracking ID: NHC3-S18.
To improve the performance and scalability of Microsoft Defender for Cloud, Microsoft is changing how CVE details are stored and queried in Azure Resource Graph.
The CvesDetails field was removed from microsoft.security/assessments, and CVE details will instead be available in the Microsoft.Security/cveDetails table.
Who is affected
You may be impacted if you:
- Query the CvesDetails field in Azure Resource Graph
- Use custom workbooks, dashboards, automation, scripts, or reports that depend on CvesDetails
- Have alerts or processes that retrieve CVE details from microsoft.security/assessments
Impact if no action is taken
The schema change is now in effect. Queries and downstream processes that rely on microsoft.security/assessments.properties.additionalData.CvesDetails may no longer return the expected CVE-level details. This may affect saved Azure Resource Graph (ARG) queries, workbooks, dashboards, exports, automation, and SIEM/SOAR integrations that use this field.
Assessment records will remain available. To retrieve CVE-specific details, use the new microsoft.security/cvedetails resource and join the records using CveId.
Required action
As of 7 September 2026, the migration to Microsoft.Security/cveDetails is in effect. To avoid potential disruption, update any remaining dependencies:
- Identify queries, workbooks, scripts, or automation that references CvesDetails in microsoft.security/assessments.
- Update to query Microsoft.Security/cveDetails.
- Validate the updated queries against the new table.
Additional resources: Review the Microsoft Defender for Cloud release notes
Comments
0 comments
Article is closed for comments.