Remediate security recommendations in Defender for Cloud
In brief
The article now clarifies that recommendation status may take several minutes to update, specifies the selected recommendation in Fix and script instructions, and updates remediation headings and wording.
What Defender admins need to know
No action is required. Administrators have clearer guidance for using Fix and automated remediation scripts.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Remediate recommendations in Microsoft Defender for Cloud
When you use Microsoft Defender for Cloud to help protect your resources and workloads, they're assessed against built-in and custom security standards enabled in your Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. Based on thosethese security assessments, security recommendations provide practical steps to remediate security issues and improve security posture.
This article describes how to remediate security recommendations in your Defender for Cloud deployment.
Before you attempt to remediate a recommendation, review it in detail. See review security recommendations.
Remediate a recommendation
By default, recommendations are prioritized based on the risk level of the security issue.
In addition to risk level, we recommend that you prioritize the security controls in the default Microsoft cloud security benchmark standard in Defender for Cloud. TheseThe security controls in this standard affect your Microsoft Secure Score.
- Sign in to the Azure portal.
Use the Fix option
To simplify the remediation process, a button labeled Fix might appear in a recommendation. The Fix button helps you quickly remediate a recommendation on multiple resources. If there isn't a Fix button in the selected recommendation, then you can't apply a quick fix, so you must follow the presented remediation steps to address the selected recommendation.
Sign in to the Azure portal.
Follow the rest of the remediation steps.
After remediation finishes, it can take several minutes for the changerecommendation status to take place.update.
Use automated remediation scripts
Security admins can also fix issues at scale with automatic script generation in AWS and GCP CLI script language. When you select Take action > Fix on a recommendation where an automated script is available, the followingan automated remediation script window opens.
:::image type="content" source="./media/implement-security-recommendations/automated-remediation-scripts.png" alt-text="Screenshot that shows recommendations with the automated remediation script." lightbox="./media/implement-security-recommendations/automated-remediation-scripts.png":::
To remediate the selected recommendation, copy and run the script.
Next stepsteps
[!div class="nextstepaction"] Use governance rules in your remediation processes
@@ -2,24 +2,25 @@ title: Remediate security recommendations in Defender for Cloud description: Remediate security recommendations in Defender for Cloud across Azure, AWS, and GCP. Review assessments, apply practical fixes, and improve security posture. ms.topic: how-to-ms.date: 05/28/2026+ms.date: 07/03/2026 ai-usage: ai-assisted+ms.custom: msecd-doc-authoring-1013 #customer intent: As a security professional, I want to understand how to remediate security recommendations in Microsoft Defender for Cloud so that I can improve my security posture. --- # Remediate recommendations in Microsoft Defender for Cloud -When you use Microsoft Defender for Cloud to help protect your resources and workloads, they're assessed against built-in and custom security standards enabled in your Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. Based on those assessments, security recommendations provide practical steps to remediate security issues and improve security posture.+When you use Microsoft Defender for Cloud to help protect your resources and workloads, they're assessed against built-in and custom security standards enabled in your Azure subscriptions, Amazon Web Services (AWS) accounts, and Google Cloud Platform (GCP) projects. Based on these security assessments, security recommendations provide practical steps to remediate security issues and improve security posture. This article describes how to remediate security recommendations in your Defender for Cloud deployment. Before you attempt to remediate a recommendation, review it in detail. See [review security recommendations](review-security-recommendations.md). -## <a name = "remediate-recommendations"></a> Remediate a recommendation+## Remediate a recommendation By default, recommendations are prioritized based on the risk level of the security issue. -In addition to risk level, we recommend that you prioritize the security controls in the default [Microsoft cloud security benchmark](concept-regulatory-compliance.md) standard in Defender for Cloud. These controls affect your [Microsoft Secure Score](secure-score-security-controls.md).+In addition to risk level, we recommend that you prioritize the security controls in the default [Microsoft cloud security benchmark](concept-regulatory-compliance.md) standard in Defender for Cloud. The security controls in this standard affect your [Microsoft Secure Score](secure-score-security-controls.md). 1. Sign in to the [Azure portal](https://portal.azure.com). @@ -37,7 +38,7 @@ In addition to risk level, we recommend that you prioritize the security control ## Use the Fix option -To simplify the remediation process, a button labeled **Fix** might appear in a recommendation. The **Fix** button helps you quickly remediate a recommendation on multiple resources. If there isn't a **Fix** button in the recommendation, then you can't apply a quick fix, so you must follow the presented remediation steps to address the recommendation.+To simplify the remediation process, a button labeled **Fix** might appear in a recommendation. The **Fix** button helps you quickly remediate a recommendation on multiple resources. If there isn't a **Fix** button in the selected recommendation, then you can't apply a quick fix, so you must follow the presented remediation steps to address the selected recommendation. 1. Sign in to the [Azure portal](https://portal.azure.com). @@ -51,17 +52,18 @@ To simplify the remediation process, a button labeled **Fix** might appear in a 1. Follow the rest of the remediation steps. -After remediation finishes, it can take several minutes for the change to take place.+After remediation finishes, it can take several minutes for the recommendation status to update. -## <a name = "use-the-automated-remediation-scripts"></a> Use automated remediation scripts+## Use automated remediation scripts -Security admins can also fix issues at scale with automatic script generation in AWS and GCP CLI script language. When you select **Take action** > **Fix** on a recommendation where an automated script is available, the following window opens.+Security admins can also fix issues at scale with automatic script generation in AWS and GCP CLI script language. When you select **Take action** > **Fix** on a recommendation where an automated script is available, an automated remediation script window opens. :::image type="content" source="./media/implement-security-recommendations/automated-remediation-scripts.png" alt-text="Screenshot that shows recommendations with the automated remediation script." lightbox="./media/implement-security-recommendations/automated-remediation-scripts.png"::: -To remediate the recommendation, copy and run the script.+To remediate the selected recommendation, copy and run the script. -## Next step+<a name="next-step"></a>+## Next steps > [!div class="nextstepaction"] > [Use governance rules in your remediation processes](governance-rules.md) 