Microsoft Defender for Endpoint
Endpoint protection

Configure vulnerability email notifications in Microsoft Defender for Endpoint

In brief

The documentation refreshes notification and RBAC descriptions, clarifies portal links, and separates permission prerequisites for editing and deleting rules from the procedure steps.

What Defender admins need to know

Administrators get clearer guidance on permissions and device-group scope when managing vulnerability notification rules.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Configure vulnerability email notifications in Microsoft Defender for Endpoint

Configure Microsoft Defender for Endpoint to send email notifications to specified recipients for new vulnerability events. This feature enableslets you to identify a group of individualspeople who will immediately beare informed right away and can act on the notifications based on the vulnerability event that triggered the notification rule. Information about vulnerability eventsVulnerability event data comes from Microsoft Defender Vulnerability Management.

If you're using Defender for Business, you can set up vulnerability notifications for specific users only (not roles or groups).

  • Only users with Manage security settings permissions can configure email notifications. If you've chosen to use basic permissions management, users with an appropriate role, such as Security Administrator, can configure email notifications. User roles and permission options
  • Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.

TheEmail notification rules allow you to set the vulnerability events that trigger notifications, and add or remove email notification recipients. New recipients get notified about vulnerabilities after the recipients are added.

If you're using role-based access control (RBAC), recipients only receiveget notifications based on thefor device groups that were configuredset in the correspondingmatching notification rule. Users with the properright permission can only create, edit, or delete notifications that are limited towithin their device group management scope. Only users assigned towith an administratoradmin role, such as Security Administrator, can manage notification rules that are configured for all device groups.

The email notification includes basic information about the vulnerability event. There areThe notification also includes links to filtered views in the Defender Vulnerability Management Security recommendations and Weaknesses pages in the Microsoft Defender portalportal: the Security recommendations page and the Weaknesses page, so you can further investigate.investigate further. For example, you could get a list of all exposed devices or get additional details about the vulnerability.

Create vulnerability email notification rules

Create a notification rule to send an email when there are certain exploit or vulnerability events,events occur, such as a new public exploit. For each rule,You can select multiple event types can be selected.for each rule.

  1. Sign in to the Microsoft Defender portal using an account with the Security Administrator role assigned.

Edit a vulnerability email notification rule

Make sure you have permission to edit the rule before you begin.

  1. From the list of notification rules, select the rule you want to edit.

  2. Select the Edit rule button next to the pencil icon in the flyout. Make sure you have permission to edit or delete the rule.

Delete a vulnerability email notification rule

Make sure you have permission to delete the rule before you begin.

  1. From the list of notification rules, select the rule you want to delete.

  2. Select the Delete button next to the trash can icon in the flyout. Make sure you have permission to edit or delete the rule.

Troubleshoot email notifications for alerts