Azure / Azure/azure-rest-api-specs
Subscription's Recommendations - Inconsistency in response from Assessements - List API of Defendor for cloud
- Dominant language
- TypeSpec
- Stars
- 3.1k
- Forks
- 5.9k
- Avg merge
- 2d 22h
- Merged PRs (30d)
- 444
Description
**Problem Statement:**
While fetching recommendations corresponding to all subscriptions in an account using
GET https://management.azure.com/subscriptions/{subscriptionId}/providers/Microsoft.Security/assessments?api-version=2020-01-01
we are getting different set of recommendations against the same subscription if we hit the API 1-2 days apart and after some time the response goes back to what it was earlier, all this while there has been no change on the account side
Also, the set of recommendations returned corresponding to 2 different subscriptions is also different i.e. some recommendations are missing from the response of Assessment - List API of a subscription.
**Queries:**
Is there any known reason for this behavior, inconsistency in response for same asset
On what criteria does this API, decide to whether to return a recommendation in the response or not
Contributor guide
Research direction
Start with the documented Microsoft.Security assessments List API endpoint and its 2020-01-01 behavior described in the issue. Investigate the response differences across subscriptions and over time using the reported API, then document the confirmed selection criteria or identify the inconsistency with reproducible evidence.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- azure, openapi
- Domain
- api, cloud, security
- Issue type
- Bug
- Difficulty
- 4/5
- Estimated time
- 3-5 days
- Activity status
- Stale
- Clarity
- Needs clarification
- Newbie friendliness
- 25/100