Exceptions in Microsoft Defender Vulnerability Management
In brief
The page now uses clearer wording for recommendation and CVE exception scope, explains how exceptions affect portal counts and impact values, and updates the related-content heading.
What Defender admins need to know
Administrators can use the revised guidance when managing exceptions and reviewing portal data. No configuration change is specified.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Exceptions in Microsoft Defender Vulnerability Management
[!INCLUDE Prerelease information]
Microsoft Defender Vulnerability Management provideslets you create exceptions to help you control what type of data is relevant to your organization and to selectively exclude specific data from your remediation efforts. Use exceptions to filter out data that isn't relevant to your organization.
Exceptions providehelp you get more accurate risk reporting and prioritization, especiallyreports. They also improve priority rankings when you have alternateother mitigations, accepted risk, or a remediation plan in place.
This article describes how to create, view, and manage Defender Vulnerability Management exceptions.
Microsoft Defender Vulnerability Management supports two types of exceptions:
Security recommendation exceptions: Exclude specific security recommendations from
analysis in your environment.analysis. You create this exception at thesecurityrecommendationlevel, whichlevel. It applies to allunderlying CVEs associated withCommon Vulnerabilities and Exposures (CVEs) linked to that recommendation.:::image type="content" alt-text="Screenshot highlighting Exception options in a Recommendation pane." source="media/tvm-exception-overview/exception-button-small.png" lightbox="media/tvm-exception-overview/exception-button-small.png":::
CVE exceptions: Exclude specific Common Vulnerabilities and Exposures (CVEs) from
analysis in your environment.analysis. You create a CVE exception from the Weaknesses page for a specific CVE.:::image type="content" alt-text="Screenshot showing how to create a CVE exception." source="media/tvm-exception-overview/cve-exception-create.png" lightbox="media/tvm-exception-overview/cve-exception-create.png":::
Exposed devices and impact after exceptions
The following sections explain how exceptions affectExceptions change the exposed device counts and impact values forshown in the portal. The tabs below describe how recommendation exceptions and CVE exception views.exceptions each affect these values.
Recommendation exceptions
You canTo view exposure and impact informationdata for recommendation exceptions inexceptions, go to the Recommendations page, whenpage. Select the Exposed devices (after exceptions) and Impact (after exceptions) columns are selected.columns.
:::image type="content" source="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png" alt-text="Screenshot of the Recommendations page with the Exposed devices (after exceptions) and Impact (after exceptions) columns selected." lightbox="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png":::
Related topicsarticles
For more information, see the following related topics:
@@ -9,14 +9,14 @@ ms.collection: - m365-security - Tier1 ms.topic: how-to-ms.date: 06/12/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender Vulnerability Management - Microsoft Defender for Endpoint Plan 2 - Microsoft Defender XDR - Microsoft Defender for Servers Plan 1 & 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Exceptions in Microsoft Defender Vulnerability Management@@ -25,9 +25,9 @@ ms.custom: msecd-doc-authoring-1014 [!INCLUDE [Prerelease information](../includes/prerelease.md)] -Microsoft Defender Vulnerability Management provides exceptions to help you control what type of data is relevant to your organization and to selectively exclude specific data from your remediation efforts.+Microsoft Defender Vulnerability Management lets you create exceptions to exclude specific data from your remediation efforts. Use exceptions to filter out data that isn't relevant to your organization. -Exceptions provide more accurate risk reporting and prioritization, especially when you have alternate mitigations, accepted risk, or a remediation plan in place.+Exceptions help you get more accurate risk reports. They also improve priority rankings when you have other mitigations, accepted risk, or a remediation plan in place. This article describes how to create, view, and manage Defender Vulnerability Management exceptions. @@ -38,11 +38,11 @@ This article describes how to create, view, and manage Defender Vulnerability Ma Microsoft Defender Vulnerability Management supports two types of exceptions: -- **Security recommendation exceptions**: Exclude specific security recommendations from analysis in your environment. You create this exception at the security recommendation level, which applies to all underlying CVEs associated with that recommendation.+- **Security recommendation exceptions**: Exclude specific security recommendations from analysis. You create this exception at the recommendation level. It applies to all Common Vulnerabilities and Exposures (CVEs) linked to that recommendation. :::image type="content" alt-text="Screenshot highlighting Exception options in a Recommendation pane." source="media/tvm-exception-overview/exception-button-small.png" lightbox="media/tvm-exception-overview/exception-button-small.png"::: -- **CVE exceptions**: Exclude specific Common Vulnerabilities and Exposures (CVEs) from analysis in your environment. You create a CVE exception from the **Weaknesses** page for a specific CVE.+- **CVE exceptions**: Exclude specific Common Vulnerabilities and Exposures (CVEs) from analysis. You create a CVE exception from the **Weaknesses** page for a specific CVE. :::image type="content" alt-text="Screenshot showing how to create a CVE exception." source="media/tvm-exception-overview/cve-exception-create.png" lightbox="media/tvm-exception-overview/cve-exception-create.png"::: @@ -91,11 +91,11 @@ The following justifications are available for exceptions: ## Exposed devices and impact after exceptions -The following sections explain how exceptions affect exposed device counts and impact values for recommendation and CVE exception views.+Exceptions change the exposed device counts and impact values shown in the portal. The tabs below describe how recommendation exceptions and CVE exceptions each affect these values. ### [Recommendation exceptions](#tab/recommendation-exclusions) -You can view exposure and impact information for recommendation exceptions in the **Recommendations** page, when the **Exposed devices (after exceptions)** and **Impact (after exceptions)** columns are selected.+To view exposure and impact data for recommendation exceptions, go to the **Recommendations** page. Select the **Exposed devices (after exceptions)** and **Impact (after exceptions)** columns. :::image type="content" source="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png" alt-text="Screenshot of the Recommendations page with the Exposed devices (after exceptions) and Impact (after exceptions) columns selected." lightbox="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png"::: @@ -122,9 +122,8 @@ The impact (after exceptions) shows remaining impact to exposure score or secure --- -## Related topics--For more information, see the following related topics:+<a name="related-topics"></a>+## Related articles - [Remediate vulnerabilities](tvm-remediation.md) - [Security recommendations](tvm-security-recommendation.md) 