Assess network share configurations in Microsoft Defender Vulnerability Management
In brief
The article now identifies Defender Vulnerability Management as part of Microsoft Security Exposure Management, clarifies licensing requirements, and refreshes the steps and terminology for viewing recommendations, exposed assets, and remediation activity.
What Defender admins need to know
Use the updated product names, navigation paths, and filter labels when locating network share recommendations. No administrator action is required.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Assess network share configurations in Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management is now part of Microsoft Security Exposure Management. For more details, see the following note.
[!INCLUDE mdvm-msem-note]
This article explains how network share configuration assessment in Microsoft Defender Vulnerability Management identifies weak share configurations and surfaces security recommendations you can act on.
Network shares let users access shared files, documents, and media across the network. Because these shares are open to many users, they often have security gaps that attackers can exploit.
When Defender Vulnerability Management finds a weak share setup, it adds a fix to the Security recommendations page. These recommendations help you secure your network shares:
- Disallow offline access to shares
- Remove shares from the root folder
Find information about exposed network shares
To view network share recommendations:
In the Microsoft Defender portal, do one of the following:
- Preview customers using Microsoft Defender XDR and Defender for Identity: Select Exposure management > Recommendations.
- Existing customers: Select Endpoints > Vulnerability management > Recommendations.
Select Filters, then choose Related component > OS > Shares.
:::image type="content" alt-text="Options for filtering on network shares" source="/defender/media/defender-vulnerability-management/network-share-filter.png":::
Select Apply.
If vulnerable network shares are detected, they appear in the recommendations list on the Security recommendations page.
:::image type="content" alt-text="Network shares configuration recommendations" source="/defender/media/defender-vulnerability-management/network-share-recommendations.png" lightbox="/defender/media/defender-vulnerability-management/network-share-recommendations.png":::
Select a recommendation to open a flyout pane with details about the weak share setup:
:::image type="content" alt-text="Network shares configuration recommendation details" source="/defender/media/defender-vulnerability-management/network-share-recommendations-details.png":::
Use the Exposed devices and Exposed shares tabs to see which assets are at risk.
Request remediation for the network share configuration
In the recommendation details flyout pane, you can view and submit a remediation request from the Remediation options tab:
:::image type="content" alt-text="Network shares configuration remediation options" source="/defender/media/defender-vulnerability-management/network-share-remediation.png":::
View configuration remediation activities
On the Remediation page, filter by remediation type Configuration change to find the activity item for your network share configuration change.
Related content
@@ -9,25 +9,29 @@ ms.collection: - m365-security - Tier2 ms.topic: how-to-ms.date: 06/12/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender Vulnerability Management - Microsoft Defender XDR - Microsoft Defender for Servers Plan 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Assess network share configurations in Microsoft Defender Vulnerability Management +Microsoft Defender Vulnerability Management is now part of Microsoft Security Exposure Management. For more details, see the following note.+ [!INCLUDE [mdvm-msem-note](../includes/mdvm-msem-note.md)] > [!NOTE]-> To use network share configuration assessment, you'll require Microsoft Defender Vulnerability Management Standalone or if you're already a Microsoft Defender for Endpoint Plan 2 customer, the Defender Vulnerability Management add-on.+> To use this feature, you need either Microsoft Defender Vulnerability Management Standalone or the Defender Vulnerability Management add-on for Microsoft Defender for Endpoint Plan 2.++This article explains how network share configuration assessment in Microsoft Defender Vulnerability Management identifies weak share configurations and surfaces security recommendations you can act on. -The ability to share files and folders over a network allows users to provide access to resources like files, documents, and media to other people on the network. As network shares can be easily accessed by network users, some common weaknesses exist that can cause network shares to be vulnerable.+Network shares let users access shared files, documents, and media across the network. Because these shares are open to many users, they often have security gaps that attackers can exploit. -When vulnerable network share configurations are identified, they're mapped to actionable security recommendations in the Security recommendations page. The following recommendations can help protect against vulnerabilities in network shares that could be exploited by attackers:+When Defender Vulnerability Management finds a weak share setup, it adds a fix to the **Security recommendations** page. These recommendations help you secure your network shares: - Disallow offline access to shares - Remove shares from the root folder@@ -39,36 +43,36 @@ When vulnerable network share configurations are identified, they're mapped to a ## Find information about exposed network shares -To see security recommendations addressing network share configurations:+To view network share recommendations: 1. In the Microsoft Defender portal, do one of the following:- - If you're a **Microsoft Defender XDR + Microsoft Defender for Identity** preview customer, select **Exposure management** > **Recommendations**.- - If you're an existing customer, select **Endpoints** > **Vulnerability management** > **Recommendations**.-1. Select **Filters** and choose **Related component** > **OS > Shares**.+ - **Preview customers** using Microsoft Defender XDR and Defender for Identity: Select **Exposure management** > **Recommendations**.+ - **Existing customers**: Select **Endpoints** > **Vulnerability management** > **Recommendations**.+1. Select **Filters**, then choose **Related component** > **OS > Shares**. :::image type="content" alt-text="Options for filtering on network shares" source="/defender/media/defender-vulnerability-management/network-share-filter.png"::: 1. Select **Apply**. -If there are network shares with vulnerabilities to address, they'll appear in the list of recommendations.+If vulnerable network shares are detected, they appear in the recommendations list on the **Security recommendations** page. :::image type="content" alt-text="Network shares configuration recommendations" source="/defender/media/defender-vulnerability-management/network-share-recommendations.png" lightbox="/defender/media/defender-vulnerability-management/network-share-recommendations.png"::: -Select a recommendation to see a flyout pane with information on the vulnerable network share configuration:+Select a recommendation to open a flyout pane with details about the weak share setup: :::image type="content" alt-text="Network shares configuration recommendation details" source="/defender/media/defender-vulnerability-management/network-share-recommendations-details.png"::: -Explore the **Exposed devices** and **Exposed shares** tabs for details of the exposed entities in your organization.+Use the **Exposed devices** and **Exposed shares** tabs to see which assets are at risk. ## Request remediation for the network share configuration -You can view and submit a remediation request from the remediation options tab:+In the recommendation details flyout pane, you can view and submit a remediation request from the **Remediation options** tab: :::image type="content" alt-text="Network shares configuration remediation options" source="/defender/media/defender-vulnerability-management/network-share-remediation.png"::: ## View configuration remediation activities -In the **Remediation** page, filter by the remediation type, "configuration change" to see the activity item related to the network share configuration change.+On the **Remediation** page, filter by remediation type **Configuration change** to find the activity item for your network share configuration change. <a name="related-articles"></a> ## Related content 