A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Hi @CVJC-4074 Based on the behavior you described, this does not appear to be a normal remediation issue on the AKS side since you've already confirmed that the cluster and resource group no longer exist. The remaining findings sound like stale Defender for Cloud assessment records.
A few relevant points:
Microsoft Defender for Containers documentation explicitly states that disabling the plan does not delete historical security data stored in Defender for Cloud or associated workspaces.
Assessment and recommendation updates can take time to refresh, but the documentation only mentions scan/update delays, not indefinite persistence after resource deletion.
I could not find public documentation describing a customer-accessible command, API, or portal action to manually purge orphaned container posture assessments after an AKS cluster has been deleted.
Given that:
The AKS cluster no longer exists.
The resource is absent from ARM and Resource Graph.
The findings have remained unchanged since June 2026.
Re-enabling/disabling the relevant Defender features did not remove them.
This looks like a candidate for a Microsoft support investigation, as the stale records may need backend cleanup or validation by the Defender for Cloud team. I am not aware of any self-service mechanism to remove those records. The public documentation I found does not describe one.
My recommendation would be to open a support case under Microsoft Defender for Cloud and provide:
Subscription ID
Assessment IDs
Deleted AKS cluster name
Deletion date
Evidence that the resource is absent from ARM/ARG
Screenshots showing the unchanged assessment timestamps
If this helps, please mark it as helpful or accepted. It may assist others who encounter stale Defender for Cloud findings after AKS resource deletion.