Configure vulnerability email notifications in Microsoft Defender for Endpoint
In brief
The documentation refreshes notification and RBAC descriptions, clarifies portal links, and separates permission prerequisites for editing and deleting rules from the procedure steps.
What Defender admins need to know
Administrators get clearer guidance on permissions and device-group scope when managing vulnerability notification rules.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Configure vulnerability email notifications in Microsoft Defender for Endpoint
Configure Microsoft Defender for Endpoint to send email notifications to specified recipients for new vulnerability events. This feature enableslets you to identify a group of individualspeople who will immediately beare informed right away and can act on the notifications based on the vulnerability event that triggered the notification rule. Information about vulnerability eventsVulnerability event data comes from Microsoft Defender Vulnerability Management.
If you're using Defender for Business, you can set up vulnerability notifications for specific users only (not roles or groups).
- Only users with
Manage security settingspermissions can configure email notifications. If you've chosen to use basic permissions management, users with an appropriate role, such as Security Administrator, can configure email notifications. User roles and permission options- Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.
TheEmail notification rules allow you to set the vulnerability events that trigger notifications, and add or remove email notification recipients. New recipients get notified about vulnerabilities after the recipients are added.
If you're using role-based access control (RBAC), recipients only receiveget notifications based on thefor device groups that were configuredset in the correspondingmatching notification rule. Users with the properright permission can only create, edit, or delete notifications that are limited towithin their device group management scope. Only users assigned towith an administratoradmin role, such as Security Administrator, can manage notification rules that are configured for all device groups.
The email notification includes basic information about the vulnerability event. There areThe notification also includes links to filtered views in the Defender Vulnerability Management Security recommendations and Weaknesses pages in the Microsoft Defender portalportal: the Security recommendations page and the Weaknesses page, so you can further investigate.investigate further. For example, you could get a list of all exposed devices or get additional details about the vulnerability.
Create vulnerability email notification rules
Create a notification rule to send an email when there are certain exploit or vulnerability events,events occur, such as a new public exploit. For each rule,You can select multiple event types can be selected.for each rule.
- Sign in to the Microsoft Defender portal using an account with the Security Administrator role assigned.
Edit a vulnerability email notification rule
Make sure you have permission to edit the rule before you begin.
From the list of notification rules, select the rule you want to edit.
Select the Edit rule button next to the pencil icon in the flyout.
Make sure you have permission to edit or delete the rule.
Delete a vulnerability email notification rule
Make sure you have permission to delete the rule before you begin.
From the list of notification rules, select the rule you want to delete.
Select the Delete button next to the trash can icon in the flyout.
Make sure you have permission to edit or delete the rule.
Troubleshoot email notifications for alerts
@@ -9,18 +9,18 @@ ms.collection: - m365-security - tier2 ms.topic: how-to-ms.date: 06/17/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender for Endpoint Plan 1 - Microsoft Defender for Endpoint Plan 2 - Microsoft Defender for Business-ms.custom: sfi-ga-nochange, msecd-doc-authoring-1014+ms.custom: sfi-ga-nochange, msecd-doc-authoring-1016 ai-usage: ai-assisted --- # Configure vulnerability email notifications in Microsoft Defender for Endpoint -Configure Microsoft Defender for Endpoint to send email notifications to specified recipients for new vulnerability events. This feature enables you to identify a group of individuals who will immediately be informed and can act on the notifications based on the vulnerability event that triggered the rule. Information about vulnerability events comes from [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management).+Configure Microsoft Defender for Endpoint to send email notifications to specified recipients for new vulnerability events. This feature lets you identify a group of people who are informed right away and can act based on the event that triggered the notification rule. Vulnerability event data comes from [Microsoft Defender Vulnerability Management](/defender-vulnerability-management/defender-vulnerability-management). If you're using [Defender for Business](/defender-business/mdb-overview), you can set up vulnerability notifications for specific users only (not roles or groups). @@ -28,11 +28,11 @@ If you're using [Defender for Business](/defender-business/mdb-overview), you ca > - Only users with `Manage security settings` permissions can configure email notifications. If you've chosen to use basic permissions management, users with an appropriate role, such as Security Administrator, can configure email notifications. [User roles and permission options](user-roles.md) > - Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2. -The notification rules allow you to set the vulnerability events that trigger notifications, and add or remove email notification recipients. New recipients get notified about vulnerabilities after the recipients are added.+Email notification rules allow you to set the vulnerability events that trigger notifications, and add or remove email notification recipients. New recipients get notified about vulnerabilities after the recipients are added. -If you're using role-based access control (RBAC), recipients only receive notifications based on the device groups that were configured in the corresponding notification rule. Users with the proper permission can only create, edit, or delete notifications that are limited to their device group management scope. Only users assigned to an administrator role, such as Security Administrator, can manage notification rules that are configured for all device groups.+If you're using role-based access control (RBAC), recipients only get notifications for device groups set in the matching notification rule. Users with the right permission can only create, edit, or delete notifications within their device group scope. Only users with an admin role, such as Security Administrator, can manage rules for all device groups. -The email notification includes basic information about the vulnerability event. There are also links to filtered views in the Defender Vulnerability Management [Security recommendations](api/ti-indicator.md) and [Weaknesses](/defender-vulnerability-management/tvm-weaknesses) pages in the Microsoft Defender portal so you can further investigate. For example, you could get a list of all exposed devices or get additional details about the vulnerability.+The email notification includes basic information about the vulnerability event. The notification also includes links to filtered views in the Microsoft Defender portal: the [Security recommendations](api/ti-indicator.md) page and the [Weaknesses](/defender-vulnerability-management/tvm-weaknesses) page, so you can investigate further. For example, you could get a list of all exposed devices or get additional details about the vulnerability. > [!IMPORTANT] > Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.@@ -40,7 +40,7 @@ The email notification includes basic information about the vulnerability event. <a name="create-rules-for-alert-notifications"></a> ## Create vulnerability email notification rules -Create a notification rule to send an email when there are certain exploit or vulnerability events, such as a new public exploit. For each rule, multiple event types can be selected.+Create a rule to send an email when certain exploit or vulnerability events occur, such as a new public exploit. You can select multiple event types for each rule. 1. Sign in to the [Microsoft Defender portal](https://go.microsoft.com/fwlink/p/?linkid=2077139) using an account with the Security Administrator role assigned. @@ -74,16 +74,20 @@ Create a notification rule to send an email when there are certain exploit or vu <a name="edit-a-notification-rule"></a> ## Edit a vulnerability email notification rule +Make sure you have permission to edit the rule before you begin.+ 1. From the list of notification rules, select the rule you want to edit. -1. Select the **Edit rule** button next to the pencil icon in the flyout. Make sure you have permission to edit or delete the rule.+1. Select the **Edit rule** button next to the pencil icon in the flyout. <a name="delete-notification-rule"></a> ## Delete a vulnerability email notification rule +Make sure you have permission to delete the rule before you begin.+ 1. From the list of notification rules, select the rule you want to delete. -1. Select the **Delete** button next to the trash can icon in the flyout. Make sure you have permission to edit or delete the rule.+1. Select the **Delete** button next to the trash can icon in the flyout. ## Troubleshoot email notifications for alerts 