Reference · Built-in query pack

Built-in query pack

114 queries ship embedded in the binary from queries/. List the live set (including your custom queries) with azdocs query list, print KQL with azdocs query show <name>, run one ad-hoc with azdocs query run <name>. Override or extend via queries.d/ — see usage/queries.md.

pie title Query pack by category
    "ai" : 2
    "analytics" : 3
    "arc" : 2
    "avd" : 5
    "compliance" : 3
    "compute" : 10
    "cost" : 10
    "databases" : 4
    "governance" : 8
    "identity" : 6
    "integration" : 1
    "inventory" : 5
    "monitoring" : 5
    "networking" : 14
    "operations" : 6
    "resilience" : 8
    "security" : 20
    "storage" : 2

Inventory queries

NameCategoryDescription
all_resourcesinventoryEvery resource with its full properties bag — populates the resources table
subscriptionsinventoryAll subscriptions visible to the credential
resource_groupsinventoryAll resource groups
resource_type_countsinventoryResource counts by type
tag_usageinventoryTag keys in use across the estate with tagged resource counts
virtual_networksnetworkingVNets with address spaces and DNS settings
subnetsnetworkingSubnets expanded from every VNet
vnet_peeringsnetworkingPeerings with state and remote network
network_security_groupsnetworkingNSGs with rule and attachment counts
nsg_rulesnetworkingCustom NSG security rules with direction, priority, and address/port scopes
public_ip_addressesnetworkingPublic IPs and what they’re attached to
load_balancersnetworkingLoad balancers with SKU and rule counts
app_gatewaysnetworkingApp gateways with SKU, WAF mode/ruleset, and listener/pool counts
firewallsnetworkingAzure Firewalls with SKU and policy
bastion_hostsnetworkingBastion hosts with SKU, VNet placement, and public IP
private_endpointsnetworkingPrivate endpoints and their targets
private_dns_zonesnetworkingPrivate DNS zones with record/link counts
private_dns_vnet_linksnetworkingPrivate DNS zone virtual network links with registration status
vpn_er_gatewaysnetworkingVPN/ExpressRoute gateways and circuits
virtual_machinescomputeVMs with size, OS, and power state
vm_extensionscomputeVM extensions with publisher, type, and owning virtual machine
vm_network_configcomputeVMs with their primary NIC, private/public IPs, and subnet
vm_scale_setscomputeScale sets with capacity, orchestration mode, and AKS ownership
managed_diskscomputeDisks with size, SKU, encryption, attachment
aks_clusterscomputeAKS with version, node pools, network plugin, RBAC and Defender posture
app_service_planscomputePlans with SKU and app counts
web_appscomputeApp Services / Function Apps with TLS, FTPS, and network settings
static_web_appscomputeStatic Web Apps with hostname, source repository, and network access
container_appscomputeContainer Apps and environments
storage_accountsstorageStorage accounts with SKU, TLS floor, and network rules
recovery_vaultsstorageRecovery Services and Backup vaults
sql_servers_and_dbsdatabasesSQL servers/dbs with public network access and Entra auth posture
cosmos_accountsdatabasesCosmos accounts with API kind and consistency
postgres_mysql_flexibledatabasesPostgreSQL/MySQL flexible servers with HA and backup posture
redis_cachesdatabasesRedis with SKU and TLS settings
key_vaultsidentityKey vaults with protection and network settings
managed_identitiesidentityUser-assigned managed identities
resources_with_system_identityidentityResources with system-assigned identity
cognitive_servicesaiCognitive Services and Azure OpenAI accounts with network and auth posture
ai_search_servicesaiAzure AI Search services with SKU, replicas, partitions, and network posture
data_factoriesanalyticsData Factory instances with Git integration and network access
synapse_workspacesanalyticsSynapse workspaces with managed VNet and network access settings
synapse_spark_poolsanalyticsSynapse Spark pools with node size, autoscale, and auto-pause configuration
arc_machinesarcAzure Arc-enabled servers with OS, agent, and connectivity status
arc_machine_extensionsarcExtensions installed on Azure Arc-enabled servers
avd_host_poolsavdAzure Virtual Desktop host pools with type, load balancing, and session limits
avd_workspacesavdAzure Virtual Desktop workspaces with application group counts
avd_application_groupsavdAzure Virtual Desktop application groups with their host pool
avd_scaling_plansavdAzure Virtual Desktop scaling plans with schedule and host pool counts
avd_session_hostsavdLikely AVD session hosts: VMs sharing a resource group with a host pool
management_groupsgovernanceManagement group hierarchy (may return no rows when ARG access is scoped to subscriptions only)
logic_app_workflowsintegrationLogic App workflows with state, identity, and integration account
log_analytics_workspacesmonitoringLog Analytics workspaces with SKU, retention, quota, and network access
app_insights_componentsmonitoringApplication Insights components with retention, sampling, and workspace integration

Security findings

NameSeverityDescription
nsg_open_to_internet🔴 highNSG rules allowing inbound from the Internet
storage_public_blob_access🔴 highAnonymous public blob access enabled
sql_public_network_access🔴 highDatabase servers reachable from public networks
public_ip_exposed_resources🔴 highPublic IPs directly on NICs
aks_rbac_disabled🔴 highAKS clusters with Kubernetes RBAC disabled
storage_http_allowed🟠 mediumPlain HTTP accepted by storage accounts
storage_weak_tls🟠 mediumStorage accounts permitting TLS versions below 1.2
disks_unencrypted_or_pmk🟠 mediumDisks with platform-managed keys only
keyvault_no_purge_protection🟠 mediumKey vaults without purge protection
keyvault_public_access🟠 mediumKey vaults reachable from all networks
web_app_https_only_disabled🟠 mediumApp Services not enforcing HTTPS-only traffic
web_app_weak_tls_or_ftps🟠 mediumApp Services allowing weak TLS versions or unencrypted FTP
vms_without_managed_disks🟡 lowVMs on unmanaged (blob) OS disks
aks_public_api_server🟡 lowAKS clusters exposing a public API server with no authorized IP ranges
orphaned_resources🔵 infoUnattached disks, unused public IPs, orphaned NICs
unassociated_nsgs🔵 infoNSGs not associated with any subnet or network interface

Cost, policy, resilience and Defender evidence

The checks below are curated adaptations of Microsoft sources, reviewed on 2026-09-13. They use ARG only; collection stores the evidence in SQLite and every export remains offline. No billing connector, FinOps Hub deployment or remediation permission is required.

NameCategoryKind / severityDescription
advisor_cost_recommendationscostinventoryAzure Advisor cost recommendations with reported savings, currency, period, and affected resource
stopped_allocated_vmscostlowVirtual machines stopped without deallocation
empty_app_service_planscostlowPaid App Service plans with no hosted apps
backendless_load_balancerscostlowStandard load balancers without a configured backend pool
backendless_app_gatewayscostlowApplication gateways without configured backend addresses or NIC IP configurations
orphaned_nat_gatewayscostlowNAT gateways without an associated subnet
empty_sql_elastic_poolscostlowSQL elastic pools with no associated databases
policy_statesgovernanceinventoryAzure Policy evaluations with assignment, initiative, resource, state, and evaluation timestamp
policy_non_compliantgovernancemediumResources with a recorded non-compliant Azure Policy evaluation
policy_exemptionsgovernanceinventoryAzure Policy exemptions including category, assignment, and expiry
policy_exemptions_expiringgovernancelowPolicy exemptions expired or due to expire within 90 days of collection
vms_without_azure_backupresiliencelowVMs without an observed active Azure Backup protected item in the accessible scope
storage_local_redundancyresiliencelowStorage accounts using locally redundant storage
postgres_without_zone_haresiliencelowPostgreSQL flexible servers with HA disabled or restricted to one zone
postgres_without_geo_backupresiliencelowPostgreSQL flexible servers with geo-redundant backup explicitly disabled
defender_compliance_standardscomplianceinventoryDefender regulatory standards with observed state and control counts
defender_compliance_controlscomplianceinventoryDefender regulatory controls with standard, state, and description
defender_compliance_assessmentscomplianceinventoryDefender regulatory assessments with passed, failed, and skipped resource counts

Sources and adaptations

Every new query preserves id and ends with | order by id asc. Policy finding rows retain the policy evidence ID for paging and use resource_id_field to associate the finding with the actual resource. Exemption findings are scope observations, so they do not invent a resource-inventory association. Expiry findings include already-expired exemptions and those due in the next 90 days at collection time. Reports use the snapshot timestamp, never the export date.

Application gateway pools are expanded up to ARG’s 2,000-element maximum; Azure’s documented per-gateway pool limit is lower. Unlike the upstream inner join, the check also retains gateways with zero pools. Empty SQL pools use a case-normalized ARM ID join; a same-named database or pool elsewhere cannot satisfy it. Stopped VM checks exclude deallocated VMs, and empty App Service plan checks exclude the Free tier. Missing PostgreSQL settings are not treated as explicitly disabled settings.

Interpretation and collection coverage

The cost and compliance chapter is shared by PDF, DOCX, Markdown, HTML/site and XLSX exports. It summarises saved service evidence. Full stored records remain in SQLite and the relevant data exports; the print technical reference selects operational settings and summarises repeated findings. Desktop Inventory discovers the new categories from the query pack, and Findings displays the new finding checks.

  • Advisor amounts are estimates, not billed costs. Currency and reported period remain separate; an absent period is unknown, not implicitly monthly. Annual savings are separate, and overlapping recommendations must not be summed as guaranteed savings. Missing amounts or counts make their aggregate unknown.
  • Policy counts are evaluations per assignment and initiative, not unique resources or a tenant-wide compliance percentage. Exemptions and unknown, conflict, error and not-applicable states are not reclassified as passes.
  • Defender counts describe the observed standards and assessments. Resource occurrences can repeat across controls and standards. Unsupported and skipped controls do not establish compliance or certification.
  • No observed active Azure Backup item does not prove no backups exist. Check vault permissions, third-party protection, indexing freshness and restore evidence. Local storage redundancy, same-zone HA and disabled geo-backup may be deliberate workload choices; these are low-severity review observations.
  • Empty, failed, uncollected and inconsistent datasets have distinct collection states. Reader access and ARG visibility constrain all datasets; service configuration or inaccessible scopes can produce no rows. A successful empty query never proves that the estate passed. ARG results truncated without a continuation token fail collection instead of silently losing evidence.

Use the existing category/query selection to limit collection when needed. User queries.d/ overrides still work; changed output columns must retain the semantics expected by summaries. Query changes are reviewed locally, not pulled from upstream during collection or reporting.

Rust-side audits (not KQL)

Run as post-passes during collect because they need configuration or cross-resource context a single query can’t see:

NameSeveritySource
missing_required_tags🟡 lowcollect/audit.rs, driven by [audit] required_tags

Relationship edges are likewise derived in Rust (collect/extractors.rs) rather than queried: the network/compute chain (subnets, peerings, NSG associations, NIC/VM/disk attachment, private endpoints, DNS links, load balancers, application gateways, Bastion, VMSS), platform ties (App Service → plan, SQL VM registration, AKS node pools), monitoring (data collection rules, solutions and App Insights → workspace, alert-rule scopes, Event Grid system topics), plus two generic passes — child resources → their ARM parent, and identity.userAssignedIdentities → the managed identity — see development/architecture.md.

Display metadata

Resource types render with friendly names (e.g. microsoft.desktopvirtualization/hostpools → “AVD Host Pool”) from data/display_names.toml, embedded in the binary (the built-in file; user overrides are separate — see below). Add or override names without recompiling by creating <config dir>/azdocs/display_names.toml with the same "<lowercase arm type>" = "Name" shape — entries merge over the built-ins, the same way queries.d/ overrides queries.

Programmatic locations and resource-specific kinds follow the same data-driven pattern in data/azure_locations.toml and data/azure_kinds.toml. Raw values remain in SQLite; only presentation uses the friendly names. The location file can be refreshed from Microsoft’s public region table with cargo run --example update_azure_locations. Kind mappings are scoped by ARM type because Azure defines them independently for each resource provider. See Azure display metadata for sources, fallbacks, and user override paths.

Operational and access evidence

The pack contains 78 inventory queries and 36 finding queries. The following queries cover operational and access evidence exposed by Microsoft collections. See operational evidence for retention, scope, freshness and source-provenance semantics.

QueryCategoryKindEvidence
policy_assignmentsgovernanceinventoryPolicy assignments, including inherited scope and enforcement settings
policy_definitionsgovernanceinventoryPolicy definitions with effect, mode, parameters and rule
policy_initiativesgovernanceinventoryPolicy initiatives and their definition references
role_assignmentsidentityinventoryAzure RBAC role assignments with principal, role, scope and conditions
role_definitionsidentityinventoryAzure RBAC role definitions with assignable scopes and complete permission blocks
broad_privileged_role_assignmentsidentitymedium findingOwner, User Access Administrator and Role Based Access Control Administrator assignments at subscription or management-group scope
patch_assessmentsoperationsinventoryVM and Arc patch assessments with pending updates, reboot status and observation time
patch_installationsoperationsinventoryVM and Arc update installations with outcomes, patch counts and reboot state
patch_security_updates_pendingoperationsmedium findingMachines with observed pending security or critical updates
patch_installation_failuresoperationsmedium findingRecorded failed VM and Arc patch installation runs
guest_configuration_assignmentsoperationsinventoryGuest configuration baseline evaluations for VM and Arc machines
guest_configuration_non_compliantoperationsmedium findingGuest configuration assignments with an explicit non-compliant result
backup_protected_itemsresilienceinventoryProtected items and backup instances with recovery-point and protection metadata
backup_policiesresilienceinventoryRecovery Services and Data Protection backup policies with their complete schedules and retention
backup_jobsresilienceinventoryBackup and restore job history with original status and provider details
backup_job_failuresresiliencemedium findingBackup and restore jobs with an explicit failed outcome
defender_assessmentssecurityinventoryDefender security assessments with status, severity and affected-resource details
defender_subassessmentssecurityinventoryDefender subassessment evidence with status, resource details and remediation metadata
defender_active_alertssecurityinventoryActive Defender alerts with original severity, timestamps and resource identifiers
defender_secure_score_controlssecurityinventoryDefender secure-score controls with original score and resource counts
resource_healthmonitoringinventoryObserved resource availability states and provider reasons
service_health_eventsmonitoringinventoryActive subscription-scoped service incidents, maintenance and advisories
resource_changesmonitoringinventoryRecent ARM control-plane changes with recorded actor, time and changed properties
unassociated_ddos_planscostlow findingDDoS protection plans with an explicitly empty virtual-network association list
unprovisioned_expressroute_circuitscostlow findingExpressRoute circuits with an observed provider state other than Provisioned
vnet_gateways_without_connectionscostlow findingVPN or ExpressRoute gateways without observed connections or point-to-site configuration

recovery_vaults also retains observed immutability, soft-delete, MUA and network settings. Missing ARG fields remain unknown; the complete returned security settings object is retained for interpretation.

Imported from the azdocs repository during this build.View source on GitHub