Disable vulnerability findings for virtual machines
In brief
The page title and heading now explicitly refer to virtual machines, and the guidance uses “recommendation exemptions” terminology. The prerequisite to review vulnerability assessment findings was also reworded and repositioned.
What Defender admins need to know
Administrators can more easily identify the page’s VM scope and the recommended exception-management terminology; no new configuration change is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Disable vulnerability findings for virtual machines in Defender for Cloud
The Defender for Servers plan in Microsoft Defender for Cloud uses Microsoft Defender Vulnerability Management to continuously scan your virtual machines (VMs) and identify vulnerabilities.
- Vulnerability scanning must be enabled.
- To create a rule to ignore findings, you need permissions to edit a policy in Azure Policy.
View vulnerability assessment findings beforeBefore youstart.create a disable rule, review vulnerability assessment findings.
Disable specific findings
@@ -1,15 +1,16 @@ ----title: Disable vulnerability findings+title: Disable vulnerability findings for virtual machines description: Learn how to disable vulnerability security findings for virtual machines in Microsoft Defender for Cloud. ms.topic: how-to-ms.date: 06/09/2026+ms.date: 07/03/2026 ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1013 --- -# Disable vulnerability findings+# Disable vulnerability findings for virtual machines in Defender for Cloud > [!IMPORTANT]-> Disable rules are being deprecated as part of the transition from grouped recommendations to individual recommendations. Use [exemptions](exempt-resource.md) to manage exceptions going forward. For migration guidance, see [Transition from disable rules to exemptions](transition-disable-rules-exemptions.md).+> Disable rules are being deprecated as part of the transition from grouped recommendations to individual recommendations. Use [recommendation exemptions](exempt-resource.md) to manage exceptions going forward. For migration guidance, see [Transition from disable rules to exemptions](transition-disable-rules-exemptions.md). The Defender for Servers plan in Microsoft Defender for Cloud uses [Microsoft Defender Vulnerability Management](auto-deploy-vulnerability-assessment.md) to continuously scan your virtual machines (VMs) and identify vulnerabilities. @@ -28,7 +29,7 @@ You might disable findings for: - [Vulnerability scanning](auto-deploy-vulnerability-assessment.md) must be enabled. - To create a rule to ignore findings, you need permissions to edit a policy in [Azure Policy](/azure/governance/policy/overview#azure-rbac-permissions-in-azure-policy).-- [View vulnerability assessment findings](auto-deploy-vulnerability-assessment.md) before you start.+- Before you create a disable rule, review [vulnerability assessment findings](auto-deploy-vulnerability-assessment.md). ## Disable specific findings 