A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @Ekta Jitendra Singh
This is most likely a reporting/query issue rather than a vulnerability-scanning issue, since the findings are already visible under the VM recommendations.
The Vulnerability Assessment Findings workbook does not normally depend on a Sentinel connector or Log Analytics ingestion. Microsoft states that most Defender for Cloud workbooks query Azure Resource Graph, and the VA workbook aggregates Defender for Cloud vulnerability findings.
One important recent change is that Microsoft completed the migration from grouped vulnerability recommendations/subassessments to individual recommendations on July 31, 2026. Machine vulnerabilities are now returned as microsoft.security/assessments with recommendation category SoftwareUpdate, rather than through the old grouped/subassessment model.
You can validate the underlying data directly in Azure Resource Graph with:
securityresources
| where type == "microsoft.security/assessments"
| where properties.resourceDetails.ResourceType =~ "microsoft.compute/virtualmachines"
| where properties.metadata.recommendationCategory == "SoftwareUpdate"
Microsoft currently documents this as the supported query for VM vulnerability findings.
If this returns the expected vulnerabilities but the workbook remains empty, check whether you're using an older saved/customized workbook that still references the deprecated subassessment schema. If you're using the latest built-in gallery workbook and it is still empty while ARG returns data, I would raise this with Microsoft Defender for Cloud support as a workbook/template synchronization issue.
If this answer helps, please mark it as Answered.