Azure Estate Report

Quarterly estate review · Contoso Ltd

Snapshot dced93ea-6655-418a-ac15-a87608cee6ab · collected 2026-09-15T17:34:04.175996+00:00 · tenant fixture-tenant · status complete · golden fixture

2subscriptions
3resource groups
18resources
13findings
50%tag coverage

Operational and compliance evidence

Microsoft service evidence recorded during collection. Results cover only the accessible scope; an empty dataset is not proof of zero cost, compliance, protection or service enablement. Detailed records remain in the snapshot database and data exports.

Azure Advisor cost opportunities

Collection: Recorded evidence

Estimates from Azure Advisor, grouped by currency and reported period. Annual estimates are separate. Missing amounts or periods remain unknown. Recommendations can overlap; totals are not guaranteed savings or billed costs.

CurrencyPeriodItemsSavingsAnnual savings
GBPMonth1125.50Unknown

Azure Policy evaluation states

Collection: Recorded evidence

Counts are policy evaluations, not distinct resources. Recorded states stay separate; missing evaluations never imply compliance. Full assignment and initiative IDs identify each group. A missing initiative may indicate a standalone policy or missing evidence.

Sub. IDAssignmentInitiative IDStateResults
sub-prod/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/baseline/providers/microsoft.authorization/policysetdefinitions/security-baselineExempt1

Azure Policy exemptions

Collection: Recorded evidence

Expiry is assessed at collection time. Review expired exemptions and those due within 90 days with their owners. No expiry specified does not mean permanent approval; assignment scope and justification remain in the stored evidence.

CategoryExpiry at collectionExemptions
WaiverDue after 90 days1

Defender regulatory standards

Collection: Recorded evidence

Standard states across accessible subscriptions. Detailed control counts remain in the stored evidence. Missing or unsupported coverage does not establish compliance or certification.

StandardStateStandard records
Azure-Security-BenchmarkFailed1

Defender regulatory controls

Collection: Recorded evidence

Control states across accessible subscriptions, grouped by standard. Skipped, unsupported and unknown states remain distinct from passes. Full control IDs remain in the stored evidence.

StandardStateControl records
Azure-Security-BenchmarkUnsupported1

Defender regulatory assessments

Collection: Recorded evidence

Passed, failed and skipped counts are resource occurrences across assessments; resources can be counted more than once. Missing counts remain unknown. These assessments do not establish certification or compliance of unassessed resources.

StandardStateChecksPassedFailedSkipped
Azure-Security-BenchmarkFailed1122Unknown

Policy assignment inventory

Collection: Recorded evidence

Assignment inventory includes the requested inherited scope. Enforcement mode and excluded scopes affect interpretation; an assignment does not establish a passing evaluation.

EnforcementAssignments
Default1
DoNotEnforce1

Patch assessments

Collection: Recorded evidence

Counts describe pending updates at the recorded assessment time and may overlap across classifications. Missing counts remain unknown. ARG assessment history is limited to seven days.

OSStateChecksSecurity updatesCritical updates
LinuxSucceeded12Unknown

Backup and restore outcomes

Collection: Recorded evidence

Backup and restore jobs retain the provider status, including warnings. ARG exposes up to 14 days of jobs; an empty result does not prove successful backups.

OperationStateJobs
BackupCompletedWithWarnings1
RestoreFailed1

Recent ARM changes

Collection: Recorded evidence

Recorded ARM changes can include actor, client and changed properties. ARG retains 14 days; this is not a complete activity or data-plane audit log.

TypeActor typeEvents
UpdateApplication1

Policy evaluation coverage

Collection: Recorded evidence

Assignments are matched to stored policy states using full normalised ARM IDs. No observed evaluation is kept separate from compliance and from unavailable state collection.

AssignmentNameStateResults
/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/baselineProduction baselineEvaluation observed1
/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/not-evaluatedPending initiativeNo evaluation observed0

Machine assessment coverage

Collection: Recorded evidence

Counts use the collected VM and Arc inventory, deduplicated by full ARM ID. No observed assessment may indicate missing service configuration, access or expired evidence; it is not a passed patch check.

TypeStateResources
microsoft.compute/virtualmachinesEvaluation observed1

Evidence age at collection

Collection: Recorded evidence

Ages are evaluated at the snapshot timestamp using the threshold recorded with each query. Future, invalid and missing dates stay separate. Review thresholds are configurable and are not Microsoft retention guarantees.

QueryReview age (hours)StateItems
patch_assessments72Missing or invalid timestamp1

Findings

2 high 1 medium 9 low 1 info

SeverityTitleCategoryCheckResource
high nsg-app: rule allow-ssh allows Internet -> port 22securitynsg_open_to_internet /subscriptions/sub-prod/resourcegroups/rg-network/providers/microsoft.network/networksecuritygroups/nsg-app
high stprodapp01 allows public blob accesssecuritystorage_public_blob_access /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.storage/storageaccounts/stprodapp01
medium web-dev does not enforce HTTPS-only trafficsecurityweb_app_https_only_disabled /subscriptions/sub-dev/resourcegroups/rg-dev/providers/microsoft.web/sites/web-dev
low asp-dev is missing tags: envgovernancemissing_required_tags /subscriptions/sub-dev/resourcegroups/rg-dev/providers/microsoft.web/serverfarms/asp-dev
low id-web-dev is missing tags: envgovernancemissing_required_tags /subscriptions/sub-dev/resourcegroups/rg-dev/providers/microsoft.managedidentity/userassignedidentities/id-web-dev
low pe-sql is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.network/privateendpoints/pe-sql
low pe-sql.nic.4f2a is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.network/networkinterfaces/pe-sql.nic.4f2a
low stprodapp01 is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.storage/storageaccounts/stprodapp01
low vm-app-01-nic is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.network/networkinterfaces/vm-app-01-nic
low vm-app-01-os is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.compute/disks/vm-app-01-os
low vm-app-01-pip is missing tags: envgovernancemissing_required_tags /subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.network/publicipaddresses/vm-app-01-pip
low web-dev is missing tags: envgovernancemissing_required_tags /subscriptions/sub-dev/resourcegroups/rg-dev/providers/microsoft.web/sites/web-dev
info nsg-unused is not associated with any subnet or NICsecurityunassociated_nsgs /subscriptions/sub-prod/resourcegroups/rg-network/providers/microsoft.network/networksecuritygroups/nsg-unused

Governance

50%tag coverage
1distinct keys
9non-compliant
Tag keyResourcesShare of 9 tagged
env9100%
SubscriptionTag coverageStatus
Development0% below threshold
Production60% healthy

9 resources are missing at least one required tag, recorded by the missing_required_tags audit.

Resource groupSubscriptionResourcesNon-compliantMissed tags
rg-appProduction12 6 env
rg-devDevelopment3 3 env

Resources by type

TypeAzure typeCount
Network Interfacemicrosoft.network/networkinterfaces2
Network Security Groupmicrosoft.network/networksecuritygroups2
Virtual Networkmicrosoft.network/virtualnetworks2
Managed Diskmicrosoft.compute/disks1
Virtual Machinemicrosoft.compute/virtualmachines1
AVD Host Poolmicrosoft.desktopvirtualization/hostpools1
Managed Identitymicrosoft.managedidentity/userassignedidentities1
Private Endpointmicrosoft.network/privateendpoints1
Public IP Addressmicrosoft.network/publicipaddresses1
Log Analytics Workspacemicrosoft.operationalinsights/workspaces1
SQL Servermicrosoft.sql/servers1
SQL Databasemicrosoft.sql/servers/databases1
Storage Accountmicrosoft.storage/storageaccounts1
App Service Planmicrosoft.web/serverfarms1
App Service / Function Appmicrosoft.web/sites1

Query provenance

The executed query and request scope are preserved with this snapshot. Source review dates are not upstream release dates.

backup_jobs
KQL SHA-256cb61f0676de911c80ba3e531f5ec6f6ef259cf75db1161ecaec5c106b88ee742
Authorization scopeAtScopeAndBelow
Requested subscriptionssub-prod
Sourceshttps://learn.microsoft.com/en-us/azure/backup/query-backups-using-azure-resource-graph
Source reviewed2026-09-13
// ARG retains up to 14 days of jobs. No jobs is not evidence of successful backups; target IDs may be unavailable on some job types.
recoveryservicesresources
| where type in~ ('microsoft.recoveryservices/vaults/backupjobs', 'microsoft.dataprotection/backupvaults/backupjobs')
| project id, name, type, subscriptionId, resourceGroup,
          resourceId = coalesce(tostring(properties.dataSourceId), tostring(properties.sourceResourceId)),
          friendlyName = coalesce(tostring(properties.entityFriendlyName), tostring(properties.dataSourceName)),
          operation = coalesce(tostring(properties.operation), tostring(properties.operationCategory)),
          status = tostring(properties.status), startedAt = properties.startTime, endedAt = properties.endTime,
          duration = properties.duration, backupInstanceId = tostring(properties.backupInstanceId), properties
| order by id asc
patch_assessments
KQL SHA-2568ef4dc6295f4389a1836e534969793c389f3cf6a721839b1dc4f8c1185716b37
Authorization scopeAtScopeAndBelow
Requested subscriptionssub-prod
Sourceshttps://learn.microsoft.com/en-us/azure/update-manager/query-logs
Source reviewed2026-09-13
// Only summary records: per-patch rows would duplicate the machine totals. ARG assessment history is limited to seven days.
patchassessmentresources
| where type in~ ('microsoft.compute/virtualmachines/patchassessmentresults', 'microsoft.hybridcompute/machines/patchassessmentresults')
| project id, name, subscriptionId, resourceGroup,
          resourceId = tostring(split(tolower(id), '/patchassessmentresults/')[0]),
          assessedAt = properties.lastModifiedDateTime, osType = tostring(properties.osType),
          status = tostring(properties.status), rebootPending = tobool(properties.rebootPending),
          securityUpdates = toint(properties.availablePatchCountByClassification.security),
          criticalUpdates = toint(properties.availablePatchCountByClassification.critical),
          classifications = properties.availablePatchCountByClassification, errorDetails = properties.errorDetails
| order by id asc
policy_assignments
KQL SHA-256b0d05b23d5aa6b47f7dfdd8fff0de86a88a02f0f4252a0c7f0d288a4f5b0dabd
Authorization scopeAtScopeAboveAndBelow
Requested subscriptionssub-prod
Sourceshttps://learn.microsoft.com/en-us/azure/governance/policy/samples/resource-graph-samples
Source reviewed2026-09-13
// Assignments without state rows are still evidence. Do not infer a passed evaluation from this inventory.
policyresources
| where type =~ 'microsoft.authorization/policyassignments'
| project id, name, subscriptionId, scope = tostring(properties.scope), policyDefinitionId = tostring(properties.policyDefinitionId),
          displayName = tostring(properties.displayName), enforcementMode = tostring(properties.enforcementMode),
          notScopes = properties.notScopes, parameters = properties.parameters, metadata = properties.metadata
| order by id asc
resource_changes
KQL SHA-25653f687e9350c4e3bb469c14d3eb0439573fcda49215f91481d4c8d3369fabfaa
Authorization scopeAtScopeAndBelow
Requested subscriptionssub-prod
Sourceshttps://learn.microsoft.com/en-us/azure/governance/resource-graph/changes/get-resource-changes
Source reviewed2026-09-13
// ARG change history lasts 14 days and does not represent a complete activity/data-plane log. Missing actor information stays unknown.
resourcechanges
| project id, name, subscriptionId, resourceGroup, resourceId = tostring(properties.targetResourceId),
          changeType = tostring(properties.changeType), changedAt = properties.changeAttributes.timestamp,
          changedBy = tostring(properties.changeAttributes.changedBy), changedByType = tostring(properties.changeAttributes.changedByType),
          clientType = tostring(properties.changeAttributes.clientType), correlationId = tostring(properties.changeAttributes.correlationId),
          changes = properties.changes
| order by id asc

Avd

avd_host_pools (1)

Azure Virtual Desktop host pools with type, load balancing, and session limits

idnamelocationresourceGroupsubscriptionIdhostPoolTypeloadBalancerTypemaxSessionLimitpreferredAppGroupType
/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.desktopvirtualization/hostpools/hp-prodhp-produksouthrg-appsub-prodPooledBreadthFirst10Desktop

Compliance

defender_compliance_assessments (1)

Defender regulatory assessments with passed, failed, and skipped resource counts

idsubscriptionIdcomplianceStandardcomplianceControlstatepassedResourcesfailedResourcesskippedResources
/defender/assessment-1sub-prodAzure-Security-BenchmarkNS-1Failed122
defender_compliance_controls (1)

Defender regulatory controls with standard, state, and description

idsubscriptionIdcomplianceStandardcomplianceControlstate
/defender/control-1sub-prodAzure-Security-BenchmarkNS-1Unsupported
defender_compliance_standards (1)

Defender regulatory standards with observed state and control counts

idsubscriptionIdcomplianceStandardstatepassedControlsfailedControlsskippedControlsunsupportedControls
/defender/standard-1sub-prodAzure-Security-BenchmarkFailed12213

Cost

advisor_cost_recommendations (1)

Azure Advisor cost recommendations with reported savings, currency, period, and affected resource

idsubscriptionIdresourceIdsolutioncurrencysavingsPeriodsavingsAmountannualSavingsAmount
/advisor/cost-1sub-prod/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.compute/virtualmachines/vm-webReview VM sizingGBPMonth125.5

Governance

policy_assignments (2)

Policy assignments, including inherited scope and enforcement settings

iddisplayNameenforcementMode
/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/baselineProduction baselineDefault
/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/not-evaluatedPending initiativeDoNotEnforce
policy_exemptions (1)

Azure Policy exemptions including category, assignment, and expiry

idnamedisplayNamesubscriptionIdexemptionCategoryexpiresOn
/policy/exemption-1migrationMigration exceptionsub-prodWaiver2099-01-01T00:00:00Z
policy_states (1)

Azure Policy evaluations with assignment, initiative, resource, state, and evaluation timestamp

idsubscriptionIdresourceIdpolicyAssignmentIdpolicyAssignmentNamepolicySetDefinitionIdcomplianceStateevaluatedAt
/policy/state-1sub-prod/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.storage/storageaccounts/stprodapp01/subscriptions/sub-prod/providers/microsoft.authorization/policyassignments/baselinebaseline/providers/microsoft.authorization/policysetdefinitions/security-baselineExempt2026-09-01T12:00:00Z

Inventory

resource_type_counts (2)

Resource counts by type across the estate

typeresourceCount
microsoft.network/virtualnetworks2
microsoft.compute/virtualmachines1

Monitoring

log_analytics_workspaces (1)

Log Analytics workspaces with SKU, retention, quota, and network access

idnamelocationresourceGroupsubscriptionIdskuNameretentionInDayspublicNetworkAccessForIngestionpublicNetworkAccessForQuery
/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.operationalinsights/workspaces/law-prodlaw-produksouthrg-appsub-prodPerGB201830EnabledEnabled
resource_changes (1)

Recent ARM control-plane changes with recorded actor, time and changed properties

idchangeTypechangedByTypechangedByclientType
/changes/change-1UpdateApplicationfixture-deploymentAzure Resource Manager

Networking

virtual_networks (2)

Virtual networks with address spaces and DNS settings

idnamelocationresourceGroupsubscriptionIdaddressPrefixesdnsServerssubnetCount
/subscriptions/sub-prod/resourcegroups/rg-network/providers/microsoft.network/virtualnetworks/vnet-hubvnet-hubuksouthrg-networksub-prod["10.0.0.0/16"][]2
/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.network/virtualnetworks/vnet-appvnet-appuksouthrg-appsub-prod["10.1.0.0/16"][]1

Operations

patch_assessments (1)

VM and Arc patch assessments with pending updates, reboot status and observation time

idresourceIdassessedAtosTypestatussecurityUpdatescriticalUpdates
/patch/assessment-1/subscriptions/sub-prod/resourcegroups/rg-app/providers/microsoft.compute/virtualmachines/vm-app-01LinuxSucceeded2

Resilience

backup_jobs (2)

Backup and restore job history with original status and provider details

idoperationstatus
/backup/job-1BackupCompletedWithWarnings
/backup/job-2RestoreFailed

Subscriptions

Development (sub-dev · 3 resources)

rg-dev — UK West (3)
NameTypeLocationTags
id-web-devManaged IdentityUK West
asp-devApp Service PlanUK West
web-devApp Service / Function AppUK West

Production (sub-prod · 15 resources)

rg-app — UK South (12)
NameTypeLocationTags
vm-app-01-osManaged DiskUK South
vm-app-01Virtual MachineUK South{"env":"prod"}
hp-prodAVD Host PoolUK South{"env":"prod"}
pe-sql.nic.4f2aNetwork InterfaceUK South
vm-app-01-nicNetwork InterfaceUK South
pe-sqlPrivate EndpointUK South
vm-app-01-pipPublic IP AddressUK South
vnet-appVirtual NetworkUK South{"env":"prod"}
law-prodLog Analytics WorkspaceUK South{"env":"prod"}
sql-prodSQL ServerUK South{"env":"prod"}
app-dbSQL DatabaseUK South{"env":"prod"}
stprodapp01Storage AccountUK South
rg-network — UK South (3)
NameTypeLocationTags
nsg-appNetwork Security GroupUK South{"env":"prod"}
nsg-unusedNetwork Security GroupUK South{"env":"prod"}
vnet-hubVirtual NetworkUK South{"env":"prod"}

Website screenshots

Saved website views from this machine. Capture time is separate from the Azure audit time.

web-dev

https://web-dev.azurewebsites.net/ · Not captured

No screenshot saved

Generated by azdocs.