Microsoft Defender Vulnerability Management
General

Exceptions in Microsoft Defender Vulnerability Management

In brief

The page now uses clearer wording for recommendation and CVE exception scope, explains how exceptions affect portal counts and impact values, and updates the related-content heading.

What Defender admins need to know

Administrators can use the revised guidance when managing exceptions and reviewing portal data. No configuration change is specified.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Exceptions in Microsoft Defender Vulnerability Management

[!INCLUDE Prerelease information]

Microsoft Defender Vulnerability Management provideslets you create exceptions to help you control what type of data is relevant to your organization and to selectively exclude specific data from your remediation efforts. Use exceptions to filter out data that isn't relevant to your organization.

Exceptions providehelp you get more accurate risk reporting and prioritization, especiallyreports. They also improve priority rankings when you have alternateother mitigations, accepted risk, or a remediation plan in place.

This article describes how to create, view, and manage Defender Vulnerability Management exceptions.

Microsoft Defender Vulnerability Management supports two types of exceptions:

  • Security recommendation exceptions: Exclude specific security recommendations from analysis in your environment.analysis. You create this exception at the security recommendation level, whichlevel. It applies to all underlying CVEs associated withCommon Vulnerabilities and Exposures (CVEs) linked to that recommendation.

    :::image type="content" alt-text="Screenshot highlighting Exception options in a Recommendation pane." source="media/tvm-exception-overview/exception-button-small.png" lightbox="media/tvm-exception-overview/exception-button-small.png":::

  • CVE exceptions: Exclude specific Common Vulnerabilities and Exposures (CVEs) from analysis in your environment.analysis. You create a CVE exception from the Weaknesses page for a specific CVE.

    :::image type="content" alt-text="Screenshot showing how to create a CVE exception." source="media/tvm-exception-overview/cve-exception-create.png" lightbox="media/tvm-exception-overview/cve-exception-create.png":::

Exposed devices and impact after exceptions

The following sections explain how exceptions affectExceptions change the exposed device counts and impact values forshown in the portal. The tabs below describe how recommendation exceptions and CVE exception views.exceptions each affect these values.

Recommendation exceptions

You canTo view exposure and impact informationdata for recommendation exceptions inexceptions, go to the Recommendations page, whenpage. Select the Exposed devices (after exceptions) and Impact (after exceptions) columns are selected.columns.

:::image type="content" source="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png" alt-text="Screenshot of the Recommendations page with the Exposed devices (after exceptions) and Impact (after exceptions) columns selected." lightbox="/defender/media/defender-vulnerability-management/tvm-after-exceptions-table.png":::


Related topicsarticles

For more information, see the following related topics: