Microsoft Defender for Cloud
Cloud and workloads

Drive recommendation remediation by using governance rules

In brief

The page adds clearer section headings and navigation anchors, updates the video link text, and introduces prerequisite and creation guidance.

What Defender admins need to know

Admins can more easily find information about tracking, assignments, due dates, owners, notifications, and conflict resolution.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Drive recommendation remediation by using governance rules

Security teams are responsible for improving their organization's security posture, but team members might not always follow through to implement security recommendations. Security teams can set governance rules to help drive accountability and create a service-level agreement (SLA) around the remediation process.

For an in-depth discussion about why governance rules are helpful, watch Episode 15 - Governance rules in Defender for Cloud ofin the Defender for Cloud in the field video series.

GovernanceHow governance rules work

You can define rules that automatically assign an owner and a due date to address recommendations for specific resources. This feature providesGovernance rules provide resource owners with a clear set of tasks and deadlines to remediate recommendations.

Learn how governanceGovernance rules work in the following sections.support tracking, assignments, due dates, owners, notifications, and conflict resolution.

TrackingTrack remediation progress

Track the progress of remediation tasks by sorting by subscription, recommendation, or owner. You can easily find tasks that need more attention so that you can follow up.

AssignmentsAssign recommendations to owners

Governance rules can identify resources that require remediation according to specific recommendations or severities. The rule assigns an owner and due date to ensure the recommendations are handled. Many governance rules can apply to the same recommendations, so the rule with the highest priority assigns the owner and due date.

DueSet due dates for remediation

The due date for remediation of a recommendation is based on a time frame of 7, 14, 30, or 90 days after the rule triggers the recommendation. For example, if the rule identifies the resource on March 1 and the remediation time frame is 14 days, March 15 is the due date. You can apply a grace period so that resources that need remediation don't affect your Microsoft Secure Score.

OwnersAssign owners to recommendations

You can also set resource owners, which helps you find the right person to handle a recommendation.

When an owner isn't found on a resource, associated resource group, or associated subscription based on the tag, the owner is shown as unspecified.

NotificationsConfigure governance rule notifications

By default, email notifications are sent weekly to resource owners. Emails include a list of on-time and overdue tasks.

By default, the resource owner's manager receives an email that shows overdue recommendations, if the manager's email is found in the organizational Microsoft Entra ID.

ConflictsResolve conflicts between governance rules

Conflicting rules are applied in scope order. For example, rules on a management scope for Azure management groups, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) organizations take effect before rules on scopes, like Azure subscriptions, AWS accounts, or GCP projects.

Prerequisites

Before you define a governance rule, make sure the following prerequisites are met:

  • The Defender Cloud Security Posture Management (Defender CSPM) plan must be enabled.
  • You need Contributor, Security Admin, or Owner permissions on the Azure subscriptions.
  • For AWS accounts and GCP projects, you need Contributor, Security Admin, or Owner permissions on the Defender for Cloud AWS or GCP connectors.

Define a governance rule

To create a governance rule in Microsoft Defender for Cloud, follow these steps:

  1. Sign in to the Azure portal.

  2. Go to Microsoft Defender for Cloud > Management > Environment settings > Governance rules.