api_collections
Creates, updates, deletes, gets or lists an api_collections resource.
Overview
| Name | api_collections |
| Type | Resource |
| Id | azure.security.api_collections |
Fields
The following fields are returned by SELECT queries:
- get_by_azure_api_management_service
- list_by_azure_api_management_service
- list_by_resource_group
- list_by_subscription
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
baseUrl | string | The base URI for this API collection. All endpoints of this API collection extend this base URI. |
discoveredVia | string | The resource Id of the resource from where this API collection was discovered. |
displayName | string | The display name of the API collection. |
numberOfApiEndpoints | integer | The number of API endpoints discovered in this API collection. |
numberOfApiEndpointsWithSensitiveDataExposed | integer | The number of API endpoints in this API collection which are exposing sensitive data in their requests and/or responses. |
numberOfExternalApiEndpoints | integer | The number of API endpoints in this API collection for which API traffic from the internet was observed. |
numberOfInactiveApiEndpoints | integer | The number of API endpoints in this API collection that have not received any API traffic in the last 30 days. |
numberOfUnauthenticatedApiEndpoints | integer | The number of API endpoints in this API collection that are unauthenticated. |
provisioningState | string | Gets the provisioning state of the API collection. Known values are: "Succeeded", "Creating", "Updating", "Deleting", "Failed", "Canceled", and "InProgress". (Succeeded, Creating, Updating, Deleting, Failed, Canceled, InProgress) |
sensitivityLabel | string | The highest priority sensitivity label from Microsoft Purview in this API collection. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
baseUrl | string | The base URI for this API collection. All endpoints of this API collection extend this base URI. |
discoveredVia | string | The resource Id of the resource from where this API collection was discovered. |
displayName | string | The display name of the API collection. |
numberOfApiEndpoints | integer | The number of API endpoints discovered in this API collection. |
numberOfApiEndpointsWithSensitiveDataExposed | integer | The number of API endpoints in this API collection which are exposing sensitive data in their requests and/or responses. |
numberOfExternalApiEndpoints | integer | The number of API endpoints in this API collection for which API traffic from the internet was observed. |
numberOfInactiveApiEndpoints | integer | The number of API endpoints in this API collection that have not received any API traffic in the last 30 days. |
numberOfUnauthenticatedApiEndpoints | integer | The number of API endpoints in this API collection that are unauthenticated. |
provisioningState | string | Gets the provisioning state of the API collection. Known values are: "Succeeded", "Creating", "Updating", "Deleting", "Failed", "Canceled", and "InProgress". (Succeeded, Creating, Updating, Deleting, Failed, Canceled, InProgress) |
sensitivityLabel | string | The highest priority sensitivity label from Microsoft Purview in this API collection. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
baseUrl | string | The base URI for this API collection. All endpoints of this API collection extend this base URI. |
discoveredVia | string | The resource Id of the resource from where this API collection was discovered. |
displayName | string | The display name of the API collection. |
numberOfApiEndpoints | integer | The number of API endpoints discovered in this API collection. |
numberOfApiEndpointsWithSensitiveDataExposed | integer | The number of API endpoints in this API collection which are exposing sensitive data in their requests and/or responses. |
numberOfExternalApiEndpoints | integer | The number of API endpoints in this API collection for which API traffic from the internet was observed. |
numberOfInactiveApiEndpoints | integer | The number of API endpoints in this API collection that have not received any API traffic in the last 30 days. |
numberOfUnauthenticatedApiEndpoints | integer | The number of API endpoints in this API collection that are unauthenticated. |
provisioningState | string | Gets the provisioning state of the API collection. Known values are: "Succeeded", "Creating", "Updating", "Deleting", "Failed", "Canceled", and "InProgress". (Succeeded, Creating, Updating, Deleting, Failed, Canceled, InProgress) |
sensitivityLabel | string | The highest priority sensitivity label from Microsoft Purview in this API collection. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
| Name | Datatype | Description |
|---|---|---|
id | string | Fully qualified resource ID for the resource. Ex - /subscriptions/{subscriptionId}/resourceGroups/{resourceGroupName}/providers/{resourceProviderNamespace}/{resourceType}/{resourceName}. |
name | string | The name of the resource. |
baseUrl | string | The base URI for this API collection. All endpoints of this API collection extend this base URI. |
discoveredVia | string | The resource Id of the resource from where this API collection was discovered. |
displayName | string | The display name of the API collection. |
numberOfApiEndpoints | integer | The number of API endpoints discovered in this API collection. |
numberOfApiEndpointsWithSensitiveDataExposed | integer | The number of API endpoints in this API collection which are exposing sensitive data in their requests and/or responses. |
numberOfExternalApiEndpoints | integer | The number of API endpoints in this API collection for which API traffic from the internet was observed. |
numberOfInactiveApiEndpoints | integer | The number of API endpoints in this API collection that have not received any API traffic in the last 30 days. |
numberOfUnauthenticatedApiEndpoints | integer | The number of API endpoints in this API collection that are unauthenticated. |
provisioningState | string | Gets the provisioning state of the API collection. Known values are: "Succeeded", "Creating", "Updating", "Deleting", "Failed", "Canceled", and "InProgress". (Succeeded, Creating, Updating, Deleting, Failed, Canceled, InProgress) |
sensitivityLabel | string | The highest priority sensitivity label from Microsoft Purview in this API collection. |
systemData | object | Azure Resource Manager metadata containing createdBy and modifiedBy information. |
type | string | The type of the resource. E.g. "Microsoft.Compute/virtualMachines" or "Microsoft.Storage/storageAccounts". |
Methods
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get_by_azure_api_management_service | select | resource_group_name, service_name, api_id, subscription_id | Gets an onboarded Azure API Management API. Gets an Azure API Management API if it has been onboarded to Microsoft Defender for APIs. If an Azure API Management API is onboarded to Microsoft Defender for APIs, the system will monitor the operations within the Azure API Management API for intrusive behaviors and provide alerts for attacks that have been detected. | |
list_by_azure_api_management_service | select | resource_group_name, service_name, subscription_id | Gets a list of onboarded Azure API Management APIs. Gets a list of Azure API Management APIs that have been onboarded to Microsoft Defender for APIs. If an Azure API Management API is onboarded to Microsoft Defender for APIs, the system will monitor the operations within the Azure API Management API for intrusive behaviors and provide alerts for attacks that have been detected. | |
list_by_resource_group | select | resource_group_name, subscription_id | Gets a list of API collections within a resource group. Gets a list of API collections within a resource group that have been onboarded to Microsoft Defender for APIs. | |
list_by_subscription | select | subscription_id | Gets a list of API collections within a subscription. Gets a list of API collections within a subscription that have been onboarded to Microsoft Defender for APIs. | |
offboard_azure_api_management_api | delete | resource_group_name, service_name, api_id, subscription_id | Offboard an Azure API Management API from Microsoft Defender for APIs. Offboard an Azure API Management API from Microsoft Defender for APIs. The system will stop monitoring the operations within the Azure API Management API for intrusive behaviors. | |
onboard_azure_api_management_api | exec | resource_group_name, service_name, api_id, subscription_id | Onboard an Azure API Management API to Microsoft Defender for APIs. Onboard an Azure API Management API to Microsoft Defender for APIs. The system will start monitoring the operations within the Azure Management API for intrusive behaviors and provide alerts for attacks that have been detected. |
Parameters
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
api_id | string | API revision identifier. Must be unique in the API Management service instance. Non-current revision has ;rev=n as a suffix where n is the revision number. Required. |
resource_group_name | string | The name of the resource group. The name is case insensitive. Required. |
service_name | string | The name of the API Management service. Required. |
subscription_id | string |
SELECT examples
- get_by_azure_api_management_service
- list_by_azure_api_management_service
- list_by_resource_group
- list_by_subscription
Gets an onboarded Azure API Management API. Gets an Azure API Management API if it has been onboarded to Microsoft Defender for APIs. If an Azure API Management API is onboarded to Microsoft Defender for APIs, the system will monitor the operations within the Azure API Management API for intrusive behaviors and provide alerts for attacks that have been detected.
SELECT
id,
name,
baseUrl,
discoveredVia,
displayName,
numberOfApiEndpoints,
numberOfApiEndpointsWithSensitiveDataExposed,
numberOfExternalApiEndpoints,
numberOfInactiveApiEndpoints,
numberOfUnauthenticatedApiEndpoints,
provisioningState,
sensitivityLabel,
systemData,
type
FROM azure.security.api_collections
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND service_name = '{{ service_name }}' -- required
AND api_id = '{{ api_id }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets a list of onboarded Azure API Management APIs. Gets a list of Azure API Management APIs that have been onboarded to Microsoft Defender for APIs. If an Azure API Management API is onboarded to Microsoft Defender for APIs, the system will monitor the operations within the Azure API Management API for intrusive behaviors and provide alerts for attacks that have been detected.
SELECT
id,
name,
baseUrl,
discoveredVia,
displayName,
numberOfApiEndpoints,
numberOfApiEndpointsWithSensitiveDataExposed,
numberOfExternalApiEndpoints,
numberOfInactiveApiEndpoints,
numberOfUnauthenticatedApiEndpoints,
provisioningState,
sensitivityLabel,
systemData,
type
FROM azure.security.api_collections
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND service_name = '{{ service_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets a list of API collections within a resource group. Gets a list of API collections within a resource group that have been onboarded to Microsoft Defender for APIs.
SELECT
id,
name,
baseUrl,
discoveredVia,
displayName,
numberOfApiEndpoints,
numberOfApiEndpointsWithSensitiveDataExposed,
numberOfExternalApiEndpoints,
numberOfInactiveApiEndpoints,
numberOfUnauthenticatedApiEndpoints,
provisioningState,
sensitivityLabel,
systemData,
type
FROM azure.security.api_collections
WHERE resource_group_name = '{{ resource_group_name }}' -- required
AND subscription_id = '{{ subscription_id }}' -- required
;
Gets a list of API collections within a subscription. Gets a list of API collections within a subscription that have been onboarded to Microsoft Defender for APIs.
SELECT
id,
name,
baseUrl,
discoveredVia,
displayName,
numberOfApiEndpoints,
numberOfApiEndpointsWithSensitiveDataExposed,
numberOfExternalApiEndpoints,
numberOfInactiveApiEndpoints,
numberOfUnauthenticatedApiEndpoints,
provisioningState,
sensitivityLabel,
systemData,
type
FROM azure.security.api_collections
WHERE subscription_id = '{{ subscription_id }}' -- required
;
DELETE examples
- offboard_azure_api_management_api
Offboard an Azure API Management API from Microsoft Defender for APIs. Offboard an Azure API Management API from Microsoft Defender for APIs. The system will stop monitoring the operations within the Azure API Management API for intrusive behaviors.
DELETE FROM azure.security.api_collections
WHERE resource_group_name = '{{ resource_group_name }}' --required
AND service_name = '{{ service_name }}' --required
AND api_id = '{{ api_id }}' --required
AND subscription_id = '{{ subscription_id }}' --required
;
Lifecycle Methods
- onboard_azure_api_management_api
Onboard an Azure API Management API to Microsoft Defender for APIs. Onboard an Azure API Management API to Microsoft Defender for APIs. The system will start monitoring the operations within the Azure Management API for intrusive behaviors and provide alerts for attacks that have been detected.
EXEC azure.security.api_collections.onboard_azure_api_management_api
@resource_group_name='{{ resource_group_name }}' --required,
@service_name='{{ service_name }}' --required,
@api_id='{{ api_id }}' --required,
@subscription_id='{{ subscription_id }}' --required
;