Microsoft Security Exposure Management
Developer and API

Query the enterprise exposure graph in Microsoft Security Exposure Management

In brief

The article’s metadata, introductory wording, and query instructions were updated, including capitalization of Defender portal navigation labels.

What Defender admins need to know

No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Query the enterprise exposure graph

Use the enterprise exposure graph in Microsoft Security Exposure Management to proactively hunt for enterprise exposure threats across endpoints, cloud environments, and hybrid infrastructures in advanced hunting in the Microsoft Defender portal. With the integration of Defender for Cloud in the Defender portal, the exposure graph now includes cloud node types and entities from Azure, AWS, and GCP environments.

This article provides someThe following sections provide examples, tips, and hints for constructing queries in the enterprise exposure graph.

Prerequisites

To query the exposure graph:

  1. In the Microsoft Defender portal, select hunting -Hunting > advancedAdvanced hunting.

  2. In the Query area, type your query. Use the graph schema, functions, and operator tables or the following examples to help you build your query.

  3. Select runRun query.

Graph-oriented query examples