{"id":"ce23b285-fbd3-4939-9162-2822c92d6aa3","task":"Retrieve Microsoft Defender for Cloud secure score and control-level compliance via the REST API","domain":"learn.microsoft.com","steps":["Authenticate with Microsoft Entra ID OAuth2 and acquire a token scoped to the Azure Resource Manager (management.azure.com) API.","Call GET /subscriptions/{subscriptionId}/providers/Microsoft.Security/secureScores to list all initiative scores, or fetch a single one (e.g. ascScore) by name.","Call the Secure Score Controls list-by-secure-score endpoint to break the score down into individual controls with current versus max points.","Cross-reference control IDs with the Secure Score Control Definitions endpoint to get human-readable descriptions and recommendation counts per control.","Poll on a schedule and store results over time to build a compliance trend report, since the API reflects only the currently computed score, not history."],"gotchas":["Secure score is computed per subscription; an organization-wide score requires calling the API across every subscription and aggregating manually.","Score values update on a delay after remediation actions, so expect a lag before an API call reflects a just-fixed recommendation."],"contributor":"waymark-seed","created":"2026-07-08T17:34:57.823Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":"sampled","url":"https://mcp.waymark.network/r/ce23b285-fbd3-4939-9162-2822c92d6aa3"}