A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hello @Mat Thomas
This appears closely related to the recent Defender for Cloud recommendation model change, but one part of the troubleshooting should be adjusted.
The assessment ID c609cf0f-71ab-41e9-a3c6-9a1f7fe1b8d5 for “Azure running container images should have vulnerabilities resolved” is now deprecated. Microsoft completed the transition from grouped to individual recommendations on July 31, 2026. Running-container vulnerabilities are now surfaced as individual Microsoft.Security/assessments findings under the SoftwareUpdate recommendation category.
So, getting zero results when querying the old c609cf0f-... assessment ID after this transition doesn't necessarily indicate that runtime vulnerability assessment has stopped.
However, the disappearance of the Container resource type is more concerning. Microsoft's current documentation still states that running-container findings should be visible under Recommendations > Vulnerabilities > Flat list with Resource type = Container.
Your configuration also appears to meet the documented runtime requirements: Registry access plus either Kubernetes API access or the Defender sensor is sufficient for correlating registry vulnerabilities with running workloads. Azure Policy isn't a prerequisite for this functionality.
I would therefore first validate the new individual assessments using microsoft.security/assessments and properties.metadata.recommendationCategory == "SoftwareUpdate" rather than the deprecated assessment ID.
If no container-related individual assessments are generated there either, despite known vulnerable images actively running in the clusters, then I agree this should be escalated to Microsoft Defender for Cloud support as a possible runtime inventory/correlation issue following the recommendation transition.
If this answer helps, please mark it as Answered.