Microsoft Defender for Cloud
Cloud and workloads

Remediate security recommendations in Defender for Cloud

In brief

The article now clarifies that recommendation status may take several minutes to update, specifies the selected recommendation in Fix and script instructions, and updates remediation headings and wording.

What Defender admins need to know

No action is required. Administrators have clearer guidance for using Fix and automated remediation scripts.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Remediate recommendations in Microsoft Defender for Cloud

When you use Microsoft Defender for Cloud to help protect your resources and workloads, they're assessed against built-in and custom security standards enabled in your Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. Based on thosethese security assessments, security recommendations provide practical steps to remediate security issues and improve security posture.

This article describes how to remediate security recommendations in your Defender for Cloud deployment.

Before you attempt to remediate a recommendation, review it in detail. See review security recommendations.

Remediate a recommendation

By default, recommendations are prioritized based on the risk level of the security issue.

In addition to risk level, we recommend that you prioritize the security controls in the default Microsoft cloud security benchmark standard in Defender for Cloud. TheseThe security controls in this standard affect your Microsoft Secure Score.

  1. Sign in to the Azure portal.

Use the Fix option

To simplify the remediation process, a button labeled Fix might appear in a recommendation. The Fix button helps you quickly remediate a recommendation on multiple resources. If there isn't a Fix button in the selected recommendation, then you can't apply a quick fix, so you must follow the presented remediation steps to address the selected recommendation.

  1. Sign in to the Azure portal.

  2. Follow the rest of the remediation steps.

After remediation finishes, it can take several minutes for the changerecommendation status to take place.update.

Use automated remediation scripts

Security admins can also fix issues at scale with automatic script generation in AWS and GCP CLI script language. When you select Take action > Fix on a recommendation where an automated script is available, the followingan automated remediation script window opens.

:::image type="content" source="./media/implement-security-recommendations/automated-remediation-scripts.png" alt-text="Screenshot that shows recommendations with the automated remediation script." lightbox="./media/implement-security-recommendations/automated-remediation-scripts.png":::

To remediate the selected recommendation, copy and run the script.

Next stepsteps

[!div class="nextstepaction"] Use governance rules in your remediation processes