Exposure insights overview in Microsoft Security Exposure Management
In brief
The overview now focuses on initiative scores and metric basics, linking to separate pages for reviewing initiatives and investigating metrics. Detailed metric, unavailable-metric, versioning, and recommendation-management content was removed from this page.
What Defender admins need to know
Use the linked initiative and metric guidance pages when administering Exposure Insights; no administrator action is stated.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Overview - Exposure insights overview
Exposure insights in Microsoft Security Exposure Management continuously aggregate security posture data and insights across workloads and resources, into a single pipeline.
Working with initiatives
You can prioritize which initiatives you want to see on the Overview dashboard. Review the initiative score, and drill down into initiatives to see associated metrics and understand where gaps or risks reside. For step-by-step guidance, see Review security initiatives.
Working with metrics
On the Metrics tab of measure exposure risk for specific asset scopes within an initiative, or in the Metrics section of Exposure Insights, youinitiative. You can review metric properties, filter findings, adjust metric weights, and drill down into recommendations. For details, see the metric state, its effect, and relative importance in an initiative, andInvestigate security initiative metrics.
Working with recommendations to improve the metric. For each metric you can:
Review metrics properties, including:
Metric name: The name of the metric.Progress: Shows the improvement of the exposure level for the metric from 0 (high exposure) to 100 (no exposure).State: Shows whether the metric needs attention, the risk was mitigated outsideSecurity Exposure Managementand shouldn't affect the initiative score, or was mitigated and the initiative score should be adjusted accordingly.Affected assets: The number of assets within the metric. In most cases, these would be assets that are exposed or that create a risk factor. In other cases, affected assets would be the number of missing Microsoft secure score points to effectively implement recommended controls.Total assets: Total number of assets under the metric scope.Recommendations: Securityconsolidates recommendationsassociated with the metric.Weight: The relative weight (importance) of the metric within the initiative, and its effect on the initiative score. Shown asHigh,Medium, andLow. It can also be defined asRisk accepted.14-day trend: Shows the metric value changes over the last 14 days.Last updatedshows the last date the metric was updated.
Filter metrics for specific findings.
Drill down into metrics to review and fix associated issues.
Suggest new metrics to the product team.
Customize the weight of a metric so that it has greater or lesser effect in the initiative, based on your business priorities. Editing a metric affects all the initiatives in which the metric is included. Once edited, it might take up to 2 hours for changes to be reflected in the metric value and its related initiatives.
Unavailable metrics
In some cases, metrics display grayed out because the underlying data for the metric doesn't exist. For instance, if a required workload isn't onboarded, or if a secure score metric is set to completed or risk accepted in secure score and Securityfrom multiple sources — Exposure Management can't access the metric data.
Security Exposure Management ingests security recommendations from multiple sources, including Exposure Management, Microsoft Secure ScoreGrayed out metrics aren't considered for score calculation.
Management, Microsoft Secure Score, and Microsoft Defender for Working with recommendations
Cloud. With the integration of Defender for Cloud in the Defender portal, Microsoft Security Exposure Management consolidates all of these recommendations— into a unified Recommendations Catalog accessible in the Defender portal.
Unified Recommendations Experience
New unified Recommendations page: All recommendations from various sources (Secure Score, Defender for Cloud, Defender for Endpoint, etc.) are now consolidated into one catalog view in the Defender portalOrganized by attack surface:Recommendations are organized bytabs for different domains - Devices,attack surface domain (Devices, Cloud, Identity, SaaS, Data) andDataCategorized byissue type: Recommendations are separated by type - misconfigurations vs vulnerabilities vs secrets. For example, on the Devices tab, you'll find separate views for Misconfigurations and Vulnerabilities, aligning with different remediation workflows
Recommendation management
You can view recommendations from theRecommendationstab with new filtering options by attack surface tabs and issue typesEach recommendation provides remediation steps to fix detected compliance issuesEvery action taken on a security recommendation helps to reduce exposure and risk, improve security posture, and directly influence its related security initiatives and metricsUse the new filtering capabilities to focus on specific domains (Cloud, Devices, etc.) or issue types(misconfigurations, vulnerabilities,etc.)
Secure score integration
Secure score helps organizations to plan and improve overall security posture using the secure score as a tracking metric. With the integration of Defender for Cloud in the Defender portal, Security Exposure Management now presents both traditional Microsoft Secure Score and new Cloud Secure Score side-by-side for comprehensive posture management.
Unified secure score experience
Microsoft Secure Score: A score that covers device, identities, SaaS apps, and data, providing an overall organizational posture metricCloud Secure Score: A score for Azure, AWS, and GCP resources, providing cloud-specific posture metricSide-by-side visibility: Both scores are now accessible within MSEM, giving a combined view of organizational posture across different domains
How Security Exposure Management uses Secure Score
Security Exposure Management leverages Secure Score more deeply as one of its sources for initiative scoresSecure Score has recommended actions for a number of productsWhen you select a recommendation to review, Security Exposure Management allows you to remediate the problem in the specific product, including recommendations that are derived from Secure Score- secrets). For
recommendations where Secure Score is relevant, the recommendation doesn't display if Secure Score isn't active The unified experience allows you todetails, seehow traditional Secure Score improvements affect overall exposure management metrics
Monitoring and improving scores
Reviewing initiative history
OnTrack score changes over time on the History tab of an initiative, you can:
Track the history of changes greater than 2.5% that affect initiative score.Filter for specific time points.Drill down to specific changes.
:::image type="content" source="media/exposure-insights-overview/initiatives-history.png" alt-text="Screenshot of the Initiative history tab showing the graph and dates of changes." lightbox="media/exposure-insights-overview/initiatives-history.png":::
When you drill down into a specific change, you can see the percentage effects of metrics in the initiative score, along with the change reason. Reasons include:
Property change- A change in the weight of the metric in the score.Value change- A change in the value of the metric in the initiative score.Metric removed- The metric is no longer relevant for that specificinitiative. Forinstance, if a better suggestion is introduced or it becomes irrelevant.Metric depreciated- The metric is removed globally.
Selecting the metric that changed provides more details about the change. For instance, it might display the new weight of a property change, and the number of affected assets before and after the change. It also offers a dropdown for changes to exposed assets, displaying up to the top 100 assets and indicating whether the asset exposure was added or removed.
:::image type="content" source="media/exposure-insights-overview/Initiatives-history-updated.png" alt-text="Screenshot of initative history side panel" lightbox="media/exposure-insights-overview/Initiatives-history-updated.png":::
You can't control the metric or score changes in advance.step-by-step guidance, see Check history.
Reviewing events
Events measure thetrack score drop or worsening in thedrops and metric status. Events include:status changes. For details and steps, see Review security events.
Metric score drop events: These events are issued with there's a decrease of at least 2% in metric score (exposure grew by 2%) since yesterday.Initiative score drop events: These events are issued when there's a decrease of at least 2% in initiative score since yesterday.New Initiative event: These events are issued when a new initiative is available in MSEM.
Next steps
@@ -1,12 +1,14 @@ ----title: Overview of exposure insights and secure score in Microsoft Security Exposure Management+title: Exposure insights overview in Microsoft Security Exposure Management description: Learn how to get exposure insights into your corporate attack surface with Microsoft Security Exposure Management. ms.topic: overview+ms.author: dlanger+author: dlanger ms.date: 07/30/2025 ms.custom: sfi-image-nochange --- -# Overview - Exposure insights+# Exposure insights overview Exposure insights in [Microsoft Security Exposure Management](microsoft-security-exposure-management.md) continuously aggregate security posture data and insights across workloads and resources, into a single pipeline. @@ -57,74 +59,15 @@ Security Exposure Management provides initiatives that currently include: ## Working with initiatives -You can prioritize which initiatives you want to see on the **Overview** dashboard. Review the initiative score, and drill down into initiatives to see associated metrics and understand where gaps or risks reside.+Review the initiative score, and drill down into initiatives to see associated metrics and understand where gaps or risks reside. For step-by-step guidance, see [Review security initiatives](initiatives.md). ## Working with metrics -On the **Metrics** tab of an initiative, or in the **Metrics** section of **Exposure Insights**, you can see the metric state, its effect, and relative importance in an initiative, and recommendations to improve the metric. For each metric you can:--- Review metrics properties, including:- - **Metric name**: The name of the metric.- - **Progress**: Shows the improvement of the exposure level for the metric from 0 (high exposure) to 100 (no exposure).- - **State**: Shows whether the metric needs attention, the risk was mitigated outside Security Exposure Management and shouldn't affect the initiative score, or was mitigated and the initiative score should be adjusted accordingly.- - **Affected assets**: The number of assets within the metric. In most cases, these would be assets that are exposed or that create a risk factor. In other cases, affected assets would be the number of missing Microsoft secure score points to effectively implement recommended controls.- - **Total assets**: Total number of assets under the metric scope.- - **Recommendations**: Security recommendations associated with the metric.- - **Weight**: The relative weight (importance) of the metric within the initiative, and its effect on the initiative score. Shown as **High**, **Medium**, and **Low**. It can also be defined as **Risk accepted**.- - **14-day trend**: Shows the metric value changes over the last 14 days.- - **Last updated** shows the last date the metric was updated.--- Filter metrics for specific findings.-- Drill down into metrics to review and fix associated issues.-- Suggest new metrics to the product team.-- Customize the weight of a metric so that it has greater or lesser effect in the initiative, based on your business priorities. Editing a metric affects all the initiatives in which the metric is included. Once edited, it might take up to 2 hours for changes to be reflected in the metric value and its related initiatives.--### Unavailable metrics--In some cases, metrics display grayed out because the underlying data for the metric doesn't exist. For instance, if a required workload isn't onboarded, or if a secure score metric is set to completed or risk accepted in secure score and Security Exposure Management can't access the metric data.--Grayed out metrics aren't considered for score calculation.--> [!NOTE]-> The versioning feature in Exposure Management provides proactive notifications to users about upcoming version updates, providing advanced visibility into the expected metric changes and their impact on related initiatives.-> A dedicated side panel offers more details about the update, including the expected date of the change, release notes, and current and new metric values, as well as changes to the related initiatives' scores.-> Users can share feedback about the update directly through the platform.-> The information is dynamic and might vary depending on when it's accessed.+Metrics measure exposure risk for specific asset scopes within an initiative. You can review metric properties, filter findings, adjust metric weights, and drill down into recommendations. For details, see [Investigate security initiative metrics](security-metrics.md). ## Working with recommendations -Security Exposure Management ingests security recommendations from multiple sources, including Exposure Management, [Microsoft Secure Score](/defender-xdr/microsoft-secure-score), and Microsoft Defender for Cloud. With the integration of Defender for Cloud in the Defender portal, Microsoft Security Exposure Management consolidates all of these recommendations into a unified Recommendations Catalog accessible in the Defender portal.--### Unified Recommendations Experience--- **New unified Recommendations page**: All recommendations from various sources (Secure Score, Defender for Cloud, Defender for Endpoint, etc.) are now consolidated into one catalog view in the Defender portal-- **Organized by attack surface**: Recommendations are organized by tabs for different domains - Devices, Cloud, Identity, SaaS, and Data-- **Categorized by issue type**: Recommendations are separated by type - misconfigurations vs vulnerabilities vs secrets. For example, on the Devices tab, you'll find separate views for Misconfigurations and Vulnerabilities, aligning with different remediation workflows--### Recommendation management--- You can view recommendations from the **Recommendations** tab with new filtering options by attack surface tabs and issue types-- Each recommendation provides remediation steps to fix detected compliance issues-- Every action taken on a security recommendation helps to reduce exposure and risk, improve security posture, and directly influence its related security initiatives and metrics-- Use the new filtering capabilities to focus on specific domains (Cloud, Devices, etc.) or issue types (misconfigurations, vulnerabilities, etc.)--### Secure score integration--Secure score helps organizations to plan and improve overall security posture using the secure score as a tracking metric. With the integration of Defender for Cloud in the Defender portal, Security Exposure Management now presents both traditional **Microsoft Secure Score** and new **Cloud Secure Score** side-by-side for comprehensive posture management.--#### Unified secure score experience--- **[Microsoft Secure Score](/defender-xdr/microsoft-secure-score)**: A score that covers device, identities, SaaS apps, and data, providing an overall organizational posture metric-- **[Cloud Secure Score](/azure/defender-for-cloud/secure-score-security-controls?pivots=defender-portal)**: A score for Azure, AWS, and GCP resources, providing cloud-specific posture metric-- **Side-by-side visibility**: Both scores are now accessible within MSEM, giving a combined view of organizational posture across different domains--#### How Security Exposure Management uses Secure Score--- Security Exposure Management leverages Secure Score more deeply as one of its sources for initiative scores-- Secure Score has recommended actions for a [number of products](/defender-xdr/microsoft-secure-score#products-included-in-secure-score)-- When you select a recommendation to review, Security Exposure Management allows you to remediate the problem in the specific product, including recommendations that are derived from Secure Score-- For recommendations where Secure Score is relevant, the recommendation doesn't display if Secure Score isn't active-- The unified experience allows you to see how traditional Secure Score improvements affect overall exposure management metrics+Security Exposure Management consolidates recommendations from multiple sources — Exposure Management, [Microsoft Secure Score](/defender-xdr/microsoft-secure-score), and Microsoft Defender for Cloud — into a unified Recommendations Catalog in the Defender portal. Recommendations are organized by attack surface domain (Devices, Cloud, Identity, SaaS, Data) and issue type (misconfigurations, vulnerabilities, secrets). For details, see [Review security recommendations](security-recommendations.md). ## Monitoring and improving scores @@ -141,35 +84,14 @@ For initiatives with metrics: ## Reviewing initiative history -On the **History** tab of an initiative, you can:--- Track the history of changes greater than 2.5% that affect initiative score.-- Filter for specific time points.-- Drill down to specific changes.--:::image type="content" source="media/exposure-insights-overview/initiatives-history.png" alt-text="Screenshot of the Initiative history tab showing the graph and dates of changes." lightbox="media/exposure-insights-overview/initiatives-history.png":::--When you drill down into a specific change, you can see the percentage effects of metrics in the initiative score, along with the change reason. Reasons include:--- **Property change** - A change in the weight of the metric in the score.-- **Value change** - A change in the value of the metric in the initiative score.-- **Metric removed** - The metric is no longer relevant for that specific initiative. For instance, if a better suggestion is introduced or it becomes irrelevant.-- **Metric depreciated** - The metric is removed globally.--Selecting the metric that changed provides more details about the change. For instance, it might display the new weight of a property change, and the number of affected assets before and after the change. It also offers a dropdown for changes to exposed assets, displaying up to the top 100 assets and indicating whether the asset exposure was added or removed.--:::image type="content" source="media/exposure-insights-overview/Initiatives-history-updated.png" alt-text="Screenshot of initative history side panel" lightbox="media/exposure-insights-overview/Initiatives-history-updated.png":::--You can't control the metric or score changes in advance.+Track score changes over time on the **History** tab of an initiative. For step-by-step guidance, see [Check history](initiatives.md#check-history). ## Reviewing events -Events measure the score drop or worsening in the metric status. Events include:--- **Metric score drop events**: These events are issued with there's a decrease of at least 2% in metric score (exposure grew by 2%) since yesterday.-- **Initiative score drop events**: These events are issued when there's a decrease of at least 2% in initiative score since yesterday.-- **New Initiative event**: These events are issued when a new initiative is available in MSEM.+Events track score drops and metric status changes. For details and steps, see [Review security events](initiatives.md#review-security-events). ## Next steps +- [Review security initiatives](initiatives.md) - [Investigate security initiative metrics](security-metrics.md)+- [Review security recommendations](security-recommendations.md) 