Microsoft Defender Vulnerability Management
General

Create, view, and manage exceptions in Microsoft Defender Vulnerability Management

In brief

The article now includes prerequisites, steps for creating recommendation and CVE exceptions, and guidance that exception durations cannot be extended. It also explains that a new exception is required after expiration.

What Defender admins need to know

Administrators should choose exception durations carefully and follow the updated selection and creation steps.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Prerequisites

Before you create an exception, make sure you meet the following requirements:

Create an exception

To create an exception, first select the recommendation or CVE you want to exclude, then provide the exception details.

Select the recommendation or CVE to exclude

Use the following steps to select the recommendation or CVE for which you want to create an exception.

Recommendation exceptions

To create a recommendation exception, follow these steps:

  1. In the Microsoft Defender portal, do one of the following:
    • If you're a Microsoft Defender XDR + Microsoft Defender for Identity preview customer, select Exposure management > Recommendations, and select Vulnerabilities on the left.
    • If you're an existing customer, select Endpoints > Vulnerability management > Recommendations.

CVE exceptions

To create a CVE exception, follow these steps:

  1. Select a CVE you would like to create an exception for. The CVE might be available either from the Vulnerabilities page or from the Weaknesses page, depending on whether you're an XDR/MDI preview customer. For more information, see Microsoft Defender Vulnerability Management and Microsoft Security Exposure Management integration.
  2. In the CVE details page, select Exception options on the bottom right.

Fill in exception details and apply the exception (recommendation and CVE exceptions)

  1. Fill in the exception justification

    1. Fill in the exception justification and the exception duration.

    2. Select the exception scope: Apply the exception as a global exception or to exceptions by device group.

      When the exception takes effect:

      • For CVE exceptions, the CVE no longer appears in the inventory lists for the selected scope. For recommendation exceptions, the recommendation isn't active until the end of the exception duration. The recommendation state changes to Full exception or to Partial exception (bywhen the exception applies only to specific device group).groups.
      • Threat analytics and alerts related to the excluded recommendation or CVE are suppressed.
      • The recommendation details or CVE details page indicates that the recommendation or CVE has an exception.
      • The organization's exposure score and secure score may be updated to reflect the exception. For more information, see View impact after exceptions are applied and Exposed devices and impact after exceptions.