Microsoft Defender Vulnerability Management
General

Assess network share configurations in Microsoft Defender Vulnerability Management

In brief

The article now identifies Defender Vulnerability Management as part of Microsoft Security Exposure Management, clarifies licensing requirements, and refreshes the steps and terminology for viewing recommendations, exposed assets, and remediation activity.

What Defender admins need to know

Use the updated product names, navigation paths, and filter labels when locating network share recommendations. No administrator action is required.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Assess network share configurations in Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management is now part of Microsoft Security Exposure Management. For more details, see the following note.

[!INCLUDE mdvm-msem-note]

This article explains how network share configuration assessment in Microsoft Defender Vulnerability Management identifies weak share configurations and surfaces security recommendations you can act on.

Network shares let users access shared files, documents, and media across the network. Because these shares are open to many users, they often have security gaps that attackers can exploit.

When Defender Vulnerability Management finds a weak share setup, it adds a fix to the Security recommendations page. These recommendations help you secure your network shares:

  • Disallow offline access to shares
  • Remove shares from the root folder

Find information about exposed network shares

To view network share recommendations:

  1. In the Microsoft Defender portal, do one of the following:

    • Preview customers using Microsoft Defender XDR and Defender for Identity: Select Exposure management > Recommendations.
    • Existing customers: Select Endpoints > Vulnerability management > Recommendations.
  2. Select Filters, then choose Related component > OS > Shares.

    :::image type="content" alt-text="Options for filtering on network shares" source="/defender/media/defender-vulnerability-management/network-share-filter.png":::

  3. Select Apply.

If vulnerable network shares are detected, they appear in the recommendations list on the Security recommendations page.

:::image type="content" alt-text="Network shares configuration recommendations" source="/defender/media/defender-vulnerability-management/network-share-recommendations.png" lightbox="/defender/media/defender-vulnerability-management/network-share-recommendations.png":::

Select a recommendation to open a flyout pane with details about the weak share setup:

:::image type="content" alt-text="Network shares configuration recommendation details" source="/defender/media/defender-vulnerability-management/network-share-recommendations-details.png":::

Use the Exposed devices and Exposed shares tabs to see which assets are at risk.

Request remediation for the network share configuration

In the recommendation details flyout pane, you can view and submit a remediation request from the Remediation options tab:

:::image type="content" alt-text="Network shares configuration remediation options" source="/defender/media/defender-vulnerability-management/network-share-remediation.png":::

View configuration remediation activities

On the Remediation page, filter by remediation type Configuration change to find the activity item for your network share configuration change.

Related content