Microsoft Defender for Cloud
Cloud and workloads

Build queries with cloud security explorer

In brief

The documentation now more clearly explains prerequisites, required Azure roles, Defender CSPM expectations, and how to use and share query templates.

What Defender admins need to know

Administrators can more easily verify access requirements and follow the documented query workflows.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Use the cloud security explorer to identify security risks in your cloud environment. Run graph-based queries on the cloud security graph, Defender for Cloud's context engine. Prioritize your security team's concerns while considering your organization's specific context and conventions.

Use the cloud security explorer to query security issues and environment context. Includingcontext, including asset inventory, internet exposure, permissions, and lateral movement between resources across Azure, Amazon Web Services (AWS), and Google Cloud Platform (GCP).

Prerequisites

Before you use cloud security explorer, make sure the following requirements are met:

  • Required roles and permissions: You need one of the following Azure roles to use cloud security explorer:
    • Security Reader

    • Security Admin

    • Reader

      :::image type="content" source="media/how-to-manage-cloud-security/download-csv-report.png" alt-text="Screenshot that shows where the download CSV report button is located on the screen.":::

QueryUse query templates

Query templates are preformattedready-made searches usingthat use common filters. Use one of the existing query templates atTo use a template, scroll to the bottom of the page by selectingand select Open query.

:::image type="content" source="media/how-to-manage-cloud-security/cloud-security-explorer-query-templates.png" alt-text="Screenshot that shows you the location of the query templates." lightbox="media/how-to-manage-cloud-security/cloud-security-explorer-query-templates.png":::

ModifyYou can change any template to search for specific results by changingfit your needs. Update the query and selectingquery, then select Search. to see your results.

Share a query

Use the query link toYou can share aany query with others. After creatingyou create a query, select Share query link. The link is copied to copy it to your clipboard.

:::image type="content" source="media/how-to-manage-cloud-security/cloud-security-explorer-share-query.png" alt-text="Screenshot showing the Share Query Link icon." lightbox="media/how-to-manage-cloud-security/cloud-security-explorer-share-query.png":::