Microsoft Security Exposure Management
Vulnerabilities and exposure

Exposure insights overview in Microsoft Security Exposure Management

In brief

The overview now focuses on initiative scores and metric basics, linking to separate pages for reviewing initiatives and investigating metrics. Detailed metric, unavailable-metric, versioning, and recommendation-management content was removed from this page.

What Defender admins need to know

Use the linked initiative and metric guidance pages when administering Exposure Insights; no administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Overview - Exposure insights overview

Exposure insights in Microsoft Security Exposure Management continuously aggregate security posture data and insights across workloads and resources, into a single pipeline.

Working with initiatives

You can prioritize which initiatives you want to see on the Overview dashboard. Review the initiative score, and drill down into initiatives to see associated metrics and understand where gaps or risks reside. For step-by-step guidance, see Review security initiatives.

Working with metrics

On the Metrics tab of measure exposure risk for specific asset scopes within an initiative, or in the Metrics section of Exposure Insights, youinitiative. You can review metric properties, filter findings, adjust metric weights, and drill down into recommendations. For details, see the metric state, its effect, and relative importance in an initiative, andInvestigate security initiative metrics.

Working with recommendations to improve the metric. For each metric you can:

Review metrics properties, including:

  • Metric name: The name of the metric.
  • Progress: Shows the improvement of the exposure level for the metric from 0 (high exposure) to 100 (no exposure).
  • State: Shows whether the metric needs attention, the risk was mitigated outside Security Exposure Management and shouldn't affect the initiative score, or was mitigated and the initiative score should be adjusted accordingly.
  • Affected assets: The number of assets within the metric. In most cases, these would be assets that are exposed or that create a risk factor. In other cases, affected assets would be the number of missing Microsoft secure score points to effectively implement recommended controls.
  • Total assets: Total number of assets under the metric scope.
  • Recommendations: Securityconsolidates recommendations associated with the metric.
  • Weight: The relative weight (importance) of the metric within the initiative, and its effect on the initiative score. Shown as High, Medium, and Low. It can also be defined as Risk accepted.
  • 14-day trend: Shows the metric value changes over the last 14 days.
  • Last updated shows the last date the metric was updated.
  • Filter metrics for specific findings.

  • Drill down into metrics to review and fix associated issues.

  • Suggest new metrics to the product team.

  • Customize the weight of a metric so that it has greater or lesser effect in the initiative, based on your business priorities. Editing a metric affects all the initiatives in which the metric is included. Once edited, it might take up to 2 hours for changes to be reflected in the metric value and its related initiatives.

  • Unavailable metrics

    In some cases, metrics display grayed out because the underlying data for the metric doesn't exist. For instance, if a required workload isn't onboarded, or if a secure score metric is set to completed or risk accepted in secure score and Securityfrom multiple sources — Exposure Management can't access the metric data.

    Grayed out metrics aren't considered for score calculation.

    Working with recommendations

    Security Exposure Management ingests security recommendations from multiple sources, including Exposure Management, Microsoft Secure ScoreManagement, Microsoft Secure Score, and Microsoft Defender for Cloud. With the integration of Defender for Cloud in the Defender portal, Microsoft Security Exposure Management consolidates all of these recommendations into a unified Recommendations Catalog accessible in the Defender portal.

    Unified Recommendations Experience

    • New unified Recommendations page: All recommendations from various sources (Secure Score, Defender for Cloud, Defender for Endpoint, etc.) are now consolidated into one catalog view in the Defender portal
    • Organized by attack surface: Recommendations are organized by tabs for different domains - Devices,attack surface domain (Devices, Cloud, Identity, SaaS, Data) and Data
    • Categorized by issue type: Recommendations are separated by type - misconfigurations vs vulnerabilities vs secrets. For example, on the Devices tab, you'll find separate views for Misconfigurations and Vulnerabilities, aligning with different remediation workflows

    Recommendation management

    • You can view recommendations from the Recommendations tab with new filtering options by attack surface tabs and issue types
    • Each recommendation provides remediation steps to fix detected compliance issues
    • Every action taken on a security recommendation helps to reduce exposure and risk, improve security posture, and directly influence its related security initiatives and metrics
    • Use the new filtering capabilities to focus on specific domains (Cloud, Devices, etc.) or issue types (misconfigurations, vulnerabilities, etc.)

    Secure score integration

    Secure score helps organizations to plan and improve overall security posture using the secure score as a tracking metric. With the integration of Defender for Cloud in the Defender portal, Security Exposure Management now presents both traditional Microsoft Secure Score and new Cloud Secure Score side-by-side for comprehensive posture management.

    Unified secure score experience

    • Microsoft Secure Score: A score that covers device, identities, SaaS apps, and data, providing an overall organizational posture metric
    • Cloud Secure Score: A score for Azure, AWS, and GCP resources, providing cloud-specific posture metric
    • Side-by-side visibility: Both scores are now accessible within MSEM, giving a combined view of organizational posture across different domains

    How Security Exposure Management uses Secure Score

    • Security Exposure Management leverages Secure Score more deeply as one of its sources for initiative scores
    • Secure Score has recommended actions for a number of products
    • When you select a recommendation to review, Security Exposure Management allows you to remediate the problem in the specific product, including recommendations that are derived from Secure Score
    • secrets). For recommendations where Secure Score is relevant, the recommendation doesn't display if Secure Score isn't active
    • The unified experience allows you todetails, see how traditional Secure Score improvements affect overall exposure management metrics
    Review security recommendations.

    Monitoring and improving scores

    Reviewing initiative history

    OnTrack score changes over time on the History tab of an initiative, you can:

    • Track the history of changes greater than 2.5% that affect initiative score.
    • Filter for specific time points.
    • Drill down to specific changes.

    :::image type="content" source="media/exposure-insights-overview/initiatives-history.png" alt-text="Screenshot of the Initiative history tab showing the graph and dates of changes." lightbox="media/exposure-insights-overview/initiatives-history.png":::

    When you drill down into a specific change, you can see the percentage effects of metrics in the initiative score, along with the change reason. Reasons include:

    • Property change - A change in the weight of the metric in the score.
    • Value change - A change in the value of the metric in the initiative score.
    • Metric removed - The metric is no longer relevant for that specific initiative. For instance, if a better suggestion is introduced or it becomes irrelevant.
    • Metric depreciated - The metric is removed globally.

    Selecting the metric that changed provides more details about the change. For instance, it might display the new weight of a property change, and the number of affected assets before and after the change. It also offers a dropdown for changes to exposed assets, displaying up to the top 100 assets and indicating whether the asset exposure was added or removed.

    :::image type="content" source="media/exposure-insights-overview/Initiatives-history-updated.png" alt-text="Screenshot of initative history side panel" lightbox="media/exposure-insights-overview/Initiatives-history-updated.png":::

    You can't control the metric or score changes in advance.step-by-step guidance, see Check history.

    Reviewing events

    Events measure thetrack score drop or worsening in thedrops and metric status. Events include:status changes. For details and steps, see Review security events.

    • Metric score drop events: These events are issued with there's a decrease of at least 2% in metric score (exposure grew by 2%) since yesterday.
    • Initiative score drop events: These events are issued when there's a decrease of at least 2% in initiative score since yesterday.
    • New Initiative event: These events are issued when a new initiative is available in MSEM.

    Next steps