Container security posture management: Persistent unhealthy assessments on deleted AKS cluster

CVJC-4074 0 Reputation points
2026-09-29T23:48:37.42+00:00

Problem description

I am experiencing an issue where a set of 15 container-level assessments in Microsoft Defender for Cloud remain marked as 'Unhealthy' for an Azure Kubernetes Service (AKS) cluster that has already been deleted. Despite verifying that the cluster and its resource group no longer exist in Azure Resource Manager or Azure Resource Graph, these assessments persist and have not changed since June 3, 2026. I have attempted toggling the 'AgentlessDiscoveryForKubernetes' extension setting and disabling/enabling the Defender for Containers plan, but these actions did not clear the stale assessments. I am seeking guidance on whether these assessments should automatically age out after cluster deletion, how to remove these orphaned records, and if there are server-side procedures to purge such stale entries.

Environment

Azure subscription with Defender CSPM, Defender for Containers plan at subscription scope, previously deleted AKS cluster, container-level agentless Kubernetes posture assessments.

What I've already tried

I verified that the AKS cluster and resource group no longer exist in Azure Resource Manager and Azure Resource Graph. I toggled the 'AgentlessDiscoveryForKubernetes' extension setting on 2026-09-23 and toggled the Defender for Containers plan between Free and Standard on 2026-09-28. After these actions, assessments still showed as 'Unhealthy' since 2026-06-03. I also performed a full assessment read about 24 hours after the last toggle, which confirmed assessments remained in 'Unhealthy' state.

Current status

I am looking for confirmation on whether these assessments should automatically age out after cluster deletion, how to manually purge these orphaned assessment records, and if there are server-side processes or commands to remove such stale entries from Defender for Cloud.

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud
0 comments No comments

1 answer

Sort by: Oldest
  1. JonathanPe 17,510 Reputation points Moderator
    2026-09-30T00:36:22.9933333+00:00

    Hi @CVJC-4074 Based on the behavior you described, this does not appear to be a normal remediation issue on the AKS side since you've already confirmed that the cluster and resource group no longer exist. The remaining findings sound like stale Defender for Cloud assessment records.

    A few relevant points:

    Microsoft Defender for Containers documentation explicitly states that disabling the plan does not delete historical security data stored in Defender for Cloud or associated workspaces.

    Assessment and recommendation updates can take time to refresh, but the documentation only mentions scan/update delays, not indefinite persistence after resource deletion.

    I could not find public documentation describing a customer-accessible command, API, or portal action to manually purge orphaned container posture assessments after an AKS cluster has been deleted.

    Given that:

    The AKS cluster no longer exists.

    The resource is absent from ARM and Resource Graph.

    The findings have remained unchanged since June 2026.

    Re-enabling/disabling the relevant Defender features did not remove them.

    This looks like a candidate for a Microsoft support investigation, as the stale records may need backend cleanup or validation by the Defender for Cloud team. I am not aware of any self-service mechanism to remove those records. The public documentation I found does not describe one.

    My recommendation would be to open a support case under Microsoft Defender for Cloud and provide:

    Subscription ID

    Assessment IDs

    Deleted AKS cluster name

    Deletion date

    Evidence that the resource is absent from ARM/ARG

    Screenshots showing the unchanged assessment timestamps

    If this helps, please mark it as helpful or accepted. It may assist others who encounter stale Defender for Cloud findings after AKS resource deletion.

    Was this answer helpful?

    0 comments No comments

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.