
【免费下载链接】context-hub项目地址https://gitcode.com/gh_mirrors/co/context-hub点击查看免费下载导读本文围绕 Context Hub 仓库中 mgmt-security Python 文档 展开系统讲解azure-mgmt-security7.0.0 的安装、认证、定价计划管理、评估结果查询与安全分数读取等 ARM 管理面自动化能力。读完本文你将能写出可运行的 Python 代码用SecurityCenter客户端完成 Defender for Cloud 的订阅级配置巡检与变更并规避版本相关的常见陷阱。定位管理面 SDK而非数据面扫描工具azure-mgmt-security是面向 Microsoft Defender for Cloud原名 Azure Security Center的 Azure Resource Manager 管理面 SDK。它的核心职责是管理与查询Microsoft.Security资源包括Defender 定价计划pricing plans安全评估assessments与评估元数据安全分数secure score安全联系人security contacts连接器相关资源connector-related resources它本身不会扫描机器也不会为代理agent做上机onboard操作。这是最容易混淆的一点它是管理/查询工具不是扫描执行工具。在 Context Hub 仓库中本文对应的文档被组织为按厂商content/azure/→ 类型docs/→ 入口mgmt-security/→ 语言变体python/的层级结构DOC.md的 frontmatter 声明了languages: python、versions: 7.0.0、source: maintainer这正是 内容指南 规定的多语言文档布局编码 Agent 可通过chub get azure/mgmt-security --lang py直接取用参见 get 命令实现 与 get-api-docs 技能。Golden Rule使用azure-mgmt-security进行针对 Microsoft Defender for Cloud 的 Azure Resource Manager 管理面自动化。将其与azure-identity配对用TokenCredential认证并把订阅 ID 传入SecurityCenter。Microsoft Learn 将SecurityCenter描述为多版本客户端multi-version client一个包对外暴露多个跨不同 API 版本的操作组默认 profile 使用最新的公开 Azure 映射。日常编码使用默认客户端即可除非你有明确理由去固定api_version或profile。安装固定你需要的包版本并同时安装azure-identitypython -m pip install azure-mgmt-security7.0.0 azure-identity常见替代方案uv add azure-mgmt-security7.0.0 azure-identity poetry add azure-mgmt-security7.0.0 azure-identityPyPI 上7.0.0要求的 Python 版本为3.8。azure-identity提供了DefaultAzureCredential、AzureCliCredential等凭据类型完整的认证选型managed identity、service principal、workload identity 等可参考仓库中配套的 Azure Identity Python 文档。认证与环境设置本地开发Azure CLI 登录az login export AZURE_SUBSCRIPTION_ID00000000-0000-0000-0000-000000000000服务主体认证配合 DefaultAzureCredentialexport AZURE_TENANT_ID00000000-0000-0000-0000-000000000000 export AZURE_CLIENT_ID00000000-0000-0000-0000-000000000000 export AZURE_CLIENT_SECRETyour-client-secret基础客户端搭建import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter subscription_id os.environ[AZURE_SUBSCRIPTION_ID] credential DefaultAzureCredential() client SecurityCenter( credentialcredential, subscription_idsubscription_id, ) try: # use client here pass finally: client.close()如果你只想要本地 CLI 认证用AzureCliCredential()代替DefaultAzureCredential()即可。认证要点subscription_id是必填的客户端不会从凭据中推断它认证成功不等于授权成功主体还需要目标资源上的 Azure RBAC 或数据面角色这在 identity 文档 中同样被强调DefaultAzureCredential会按顺序尝试环境凭据、workload identity、managed identity、共享令牌缓存、VS Code、Azure CLI、Azure PowerShell、Azure Developer CLI 等1.25.2中的链顺序详见 identity 文档本地服务主体环境变量可能覆盖 CLI 登录。核心工作流列出 Defender for Cloud 定价计划在修改任何配置之前先用pricings.list()查看当前订阅下已启用的计划import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter client SecurityCenter( credentialDefaultAzureCredential(), subscription_idos.environ[AZURE_SUBSCRIPTION_ID], ) try: for pricing in client.pricings.list(): print(pricing.name) print( tier:, pricing.pricing_tier) print( sub-plan:, pricing.sub_plan) print( free-trial:, pricing.free_trial_remaining_time) finally: client.close()Pricing模型定义了两个定价层级Free与Standard。部分计划还暴露可选的sub_plan字段。启用或修改某个具体 Defender 计划pricings.update()期望使用v2022_03_01操作组对应的版本化Pricing模型import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter from azure.mgmt.security.v2022_03_01.models import Pricing client SecurityCenter( credentialDefaultAzureCredential(), subscription_idos.environ[AZURE_SUBSCRIPTION_ID], ) try: updated client.pricings.update( pricing_nameVirtualMachines, pricingPricing(pricing_tierStandard), ) print(updated.name, updated.pricing_tier) finally: client.close()先用client.pricings.list()发现订阅下合法的pricing_name值不要凭空猜测如果某个 Standard 计划支持多个子计划可以向Pricing(...)传入sub_plan...根据 Learn 参考文档省略sub_plan时应用完整计划当操作组期望版本化模型时务必从匹配的命名空间导入该模型例如client.pricings.update(...)使用azure.mgmt.security.v2022_03_01.models.Pricing。列出评估元数据获取修复指引assessments_metadata.list_by_subscription()用于获取评估类型目录及其内置的修复文本适合在查询具体评估结果前先把评估键映射到用户可见标题与修复说明import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter client SecurityCenter( credentialDefaultAzureCredential(), subscription_idos.environ[AZURE_SUBSCRIPTION_ID], ) try: for item in client.assessments_metadata.list_by_subscription(): props item.properties print(item.name) print( title:, props.display_name) print( severity:, props.severity) print( remediation:, props.remediation_description) finally: client.close()列出订阅范围内的评估结果assessments.list()接受一个 scope 字符串Microsoft Learn 文档化了订阅与管理组subscription 和 management-group两种作用域import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter subscription_id os.environ[AZURE_SUBSCRIPTION_ID] client SecurityCenter( credentialDefaultAzureCredential(), subscription_idsubscription_id, ) try: scope f/subscriptions/{subscription_id} for assessment in client.assessments.list(scopescope): props assessment.properties print(assessment.name) print( title:, props.display_name) print( resource:, props.resource_details.id) finally: client.close()要查看单个评估的更多细节并让服务端附带元数据可以调用get(..., expandmetadata)import os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter client SecurityCenter( credentialDefaultAzureCredential(), subscription_idos.environ[AZURE_SUBSCRIPTION_ID], ) try: vm_id ( /subscriptions/00000000-0000-0000-0000-000000000000/ resourceGroups/example-rg/providers/Microsoft.Compute/virtualMachines/example-vm ) assessment client.assessments.get( resource_idvm_id, assessment_nameassessment-key, expandmetadata, ) print(assessment.properties.display_name) print(assessment.properties.status.code) print(assessment.properties.metadata.remediation_description) finally: client.close()assessment-key来自assessments.list(...)或assessments_metadata.list_by_subscription()的返回结果。读取当前安全分数对于默认 initiativedefault initiativeMicrosoft Learn 建议使用ascScoreimport os from azure.identity import DefaultAzureCredential from azure.mgmt.security import SecurityCenter client SecurityCenter( credentialDefaultAzureCredential(), subscription_idos.environ[AZURE_SUBSCRIPTION_ID], ) try: score client.secure_scores.get(ascScore) print(score.id) print(score.name) finally: client.close()如果你需要当前作用域下每一个initiative 的分数而不只是默认的ascScore视图改用client.secure_scores.list()。配置注意事项subscription_id必填客户端不会从凭据推断对于主权云sovereign clouds保持凭据的 authority 与base_url与目标云对齐对应 identity 文档 中的AZURE_AUTHORITY_HOST与AzureAuthorityHosts.AZURE_GOVERNMENT等设置对一批操作复用同一个客户端实例用完后关闭——该包启用了 HTTP 连接池当操作组期望版本化模型时从匹配命名空间导入模型如azure.mgmt.security.v2022_03_01.models.Pricing。7.0.0 的版本敏感说明PyPI 将7.0.0列为当前稳定版同时存在 2025 年 8 月 25 日发布的预发布版8.0.0b1除非你有意使用预览 surface 变更否则固定7.0.06.0.0新增了APICollectionsOperations与DefenderForStorageOperations6.0.0变更了SecurityContact新增emails与notifications_by_role移除了旧的email与alerts_to_admins参数并删除了SecurityContactsOperations.update自5.0.0起包使用简化异常并移除了CloudError新代码请捕获azure.core.exceptions.HttpResponseError5.0.0的 PyPI 发布说明还表示该包在azure.mgmt.security.aio命名空间下提供稳定的异步支持。常见陷阱把它当作数据面 SDK它其实是针对Microsoft.Security的 ARM 管理客户端忘记设置AZURE_SUBSCRIPTION_ID仅认证不足以构建客户端在版本化操作组上导入错误的模型命名空间update/create 操作尤其容易出错照抄旧版安全联系人示例仍使用email、alerts_to_admins或update(...)的示例与7.0.0不匹配在面向当前 Azure SDK 的代码中捕获旧版CloudError在长时间运行的进程中遗留大量未关闭的短生命周期客户端导致连接资源泄漏。官方来源指引本文内容的版本与行为信息来源于 PyPI 包页与发布历史、Microsoft Learn 的azure-mgmt-securityPython API 参考含SecurityCenter客户端、PricingsOperations、Pricing模型、AssessmentsOperations、AssessmentsMetadataOperations、SecurityAssessmentPropertiesResponse、SecurityAssessmentMetadataPropertiesResponse、SecureScoresOperations、SecurityContactsOperations、SecurityContact模型等页面。在编写新代码前建议以这些权威参考核对当前行为在 Context Hub 中也可以通过chub search azure security/chub get azure/mgmt-security --lang py直接获取本仓库维护的这份文档参见 README 与 CLI 参考。赞分享【免费下载链接】context-hub项目地址https://gitcode.com/gh_mirrors/co/context-hub点击查看免费下载相关推荐探索RegNetY-160.lion_in12k_ft_in1k的核心优势stochastic depth与gradient checkpointing技术解析探索RegNetY 160.lion_in12k_ft_in1k的核心优势stochastic depth与gradient checkpointing技术解Azure Kubernetes Service 管理 SDK for Pythonazure-mgmt-containerservice 40.2.0 实战指南Azure Kubernetes Service 管理 SDK for Python azure mgmt containerservice 40.2.0 实使用 azure-mgmt-cognitiveservices Python SDK 管理 Azure AI Services 与 Azure OpenAI 资源使用 azure mgmt cognitiveservices Python SDK 管理 Azure AI Services 与 Azure OpenAI 资上一篇推荐开源项目Radzen Blazor组件库 - 为你的Blazor应用注入生命力下一篇XiaoMusic智能语音控制的专业级音乐服务器实战教程创作声明:本文部分内容由AI辅助生成(AIGC),仅供参考