Azure service for running fast KQL queries across subscriptions to explore and inventory resources, including their change history. Grouping resources and assigning or deploying policy are beyond it.
Read more: Microsoft Learn
In the Ultra Transcenders books
Each book explains Resource Graph in context, with comparison tables and the common traps.
Terms in this definition
- Kerberos armoring
Wraps Kerberos pre-authentication in an encrypted tunnel; Group Policy must enable support on both clients and domain controllers.
- KQL
Kusto Query Language, used read-only to query Azure Data Explorer, Log Analytics and Microsoft Sentinel; log alert rules are written in it too.
- Exclusions
Scopes taken out of a policy assignment; they can only narrow its coverage, never widen it.
Related terms
- Azure Export for Terraform
Also known as aztfexport, this generates Terraform HCL code and state from Azure resources you already have, so they can be managed by Terraform. Point it at a single resource, a whole resource group or the results of a Resource Graph query, and target either azurerm or AzAPI.
- Change Analysis
Records changes to Azure resource properties without an agent; it now appears as change history in Resource Graph.