Remediate vulnerabilities with Microsoft Defender Vulnerability Management
In brief
The article now uses clearer section titles and wording for Intune security tasks, attention-required options, remediation activities, retention, and tracking entries.
What Defender admins need to know
Administrators can more easily navigate the guidance and understand which remediation activities can be tracked.
Summaries are generated from the documentation change itself.
Documentation change
The comparison below shows only the changed extract. Use the full-page view for complete context.
Remediate vulnerabilities with Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.
Request vulnerability remediation
Vulnerability management capabilities bridges the gap between Security and IT administrators through the remediation request workflow. Security admins like you can request for the IT Administrator to remediate a vulnerability from the Recommendation pages to Intune.
To use this capability, enable your Microsoft Intune connections. In the Microsoft Defender portal, navigate to Settings > Endpoints > General > Advanced features. Scroll down and look for Microsoft Intune connection. By default, the toggle is turned off. Turn your Microsoft Intune connection toggle On.
See Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint for details.
RemediationSubmit a remediation request steps
Use the following steps to create a remediation request from a security recommendation.
Fill out the form, including what you are requesting remediation for, whether to open a ticket in Intune, priority, due date, and optional notes. Select Next.
If you choose the attention required remediation option, you can't select a due date because
therethat option doesn's no specific action.t create a remediation action to track.Review the details of your request then, select Submit. Submitting a remediation request creates a remediation activity item within vulnerability management, which can be used for monitoring the remediation progress for
thisthe selected security recommendation. Submitting the remediation request doesn't trigger remediation or apply any changes to devices.Notify your IT Administrator about the new request and have them log into Intune to approve or reject the request and start a package deployment. If you want to check how the ticket shows up in Intune, See Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint for details.
Track remediation activities
After your organization's cybersecurity weaknesses are identified and mapped to actionable security recommendations, start creating security tasks. You can create tasks through the integration with Microsoft Intune where remediation tickets are created.
Lower your organization's exposure from vulnerabilities and increase your security configuration by remediating the security recommendations.
When you submit a remediation request from the Recommendations page, it kicks off a remediation activity. A security task is created that can be tracked on a Remediation page, and a remediation ticket is created in Microsoft Intune.
If you chose the attention required remediation option, there's no progress bar, ticket status, or due date since therethat option doesn's no actualt create a remediation action wethat can monitor.be monitored.
Once you're in the Remediation page, select the remediation activity that you want to view. You can follow the remediation steps, track progress, view the related recommendation, export to CSV, or mark as complete.
:::image type="content" source="/defender/media/remediation-flyouteolswnew.png" alt-text="Example of the Remediation page, with a selected remediation activity, and that activity's flyout listing the description, IT service and device management tools, and device remediation":::
Use the Completed by column to track remediation ownership
You can view Top remediation activities either on the Overview or Dashboard page, depending on if you're an XDR/MDI Preview customer. For more information, see Microsoft Defender Vulnerability Management and Microsoft Security Exposure Management integration.
Select any ofentry in the entriesTop remediation activities list to go to the Remediation page. You can mark thea remediation activity as completed after the IT admin team remediates the associated security task.

@@ -9,14 +9,14 @@ ms.collection: - m365-security - Tier2 ms.topic: how-to-ms.date: 06/12/2026+ms.date: 07/02/2026 appliesto: - Microsoft Defender Vulnerability Management - Microsoft Defender for Endpoint Plan 2 - Microsoft Defender XDR - Microsoft Defender for Servers Plan 1 & 2 ai-usage: ai-assisted-ms.custom: msecd-doc-authoring-1014+ms.custom: msecd-doc-authoring-1016 --- # Remediate vulnerabilities with Microsoft Defender Vulnerability Management@@ -25,7 +25,8 @@ ms.custom: msecd-doc-authoring-1014 Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable [security recommendations](tvm-security-recommendation.md). You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune. -## Request remediation+<a name="request-remediation"></a>+## Request vulnerability remediation Vulnerability management capabilities bridges the gap between Security and IT administrators through the remediation request workflow. Security admins like you can request for the IT Administrator to remediate a vulnerability from the **Recommendation** pages to Intune. @@ -34,11 +35,12 @@ Vulnerability management capabilities bridges the gap between Security and IT ad To use this capability, enable your Microsoft Intune connections. In the Microsoft Defender portal, navigate to **Settings** \> **Endpoints** \> **General** \> **Advanced features**. Scroll down and look for **Microsoft Intune connection**. By default, the toggle is turned off. Turn your **Microsoft Intune connection** toggle **On**. > [!NOTE]-> If you have the Intune connection enabled, you get an option to create an Intune security task when creating a remediation request. This option doesn't appear if the connection isn't set.+> If you have the Intune connection enabled, you get an option to create an Intune security task when creating a remediation request. The option to create an Intune security task doesn't appear if the connection isn't set. See [Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint](/intune/intune-service/protect/microsoft-defender-manage-vulnerabilities) for details. -### Remediation request steps+<a name="remediation-request-steps"></a>+### Submit a remediation request Use the following steps to create a remediation request from a security recommendation. @@ -50,9 +52,9 @@ Use the following steps to create a remediation request from a security recommen 3. Fill out the form, including what you are requesting remediation for, whether to open a ticket in Intune, priority, due date, and optional notes. Select Next. - If you choose the **attention required** remediation option, you can't select a due date because there's no specific action.+ If you choose the **attention required** remediation option, you can't select a due date because that option doesn't create a remediation action to track. -4. Review the details of your request then, select **Submit**. Submitting a remediation request creates a remediation activity item within vulnerability management, which can be used for monitoring the remediation progress for this recommendation. Submitting the remediation request doesn't trigger remediation or apply any changes to devices.+4. Review the details of your request then, select **Submit**. Submitting a remediation request creates a remediation activity item within vulnerability management, which can be used for monitoring the remediation progress for the selected security recommendation. Submitting the remediation request doesn't trigger remediation or apply any changes to devices. 5. Notify your IT Administrator about the new request and have them log into Intune to approve or reject the request and start a package deployment. If you want to check how the ticket shows up in Intune, See [Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint](/intune/intune-service/protect/microsoft-defender-manage-vulnerabilities) for details. @@ -61,6 +63,8 @@ Use the following steps to create a remediation request from a security recommen > [!NOTE] > If your request involves remediating more than 10,000 devices, we can only send 10,000 devices for remediation to Intune. +## Track remediation activities+ After your organization's cybersecurity weaknesses are identified and mapped to actionable [security recommendations](tvm-security-recommendation.md), start creating security tasks. You can create tasks through the integration with Microsoft Intune where remediation tickets are created. Lower your organization's exposure from vulnerabilities and increase your security configuration by remediating the security recommendations.@@ -69,14 +73,14 @@ Lower your organization's exposure from vulnerabilities and increase your securi When you submit a remediation request from the **Recommendations** page, it kicks off a remediation activity. A security task is created that can be tracked on a **Remediation** page, and a remediation ticket is created in Microsoft Intune. -If you chose the **attention required** remediation option, there's no progress bar, ticket status, or due date since there's no actual action we can monitor.+If you chose the **attention required** remediation option, there's no progress bar, ticket status, or due date since that option doesn't create a remediation action that can be monitored. Once you're in the Remediation page, select the remediation activity that you want to view. You can follow the remediation steps, track progress, view the related recommendation, export to CSV, or mark as complete. :::image type="content" source="/defender/media/remediation-flyouteolswnew.png" alt-text="Example of the Remediation page, with a selected remediation activity, and that activity's flyout listing the description, IT service and device management tools, and device remediation"::: > [!NOTE]-> There's a 180 day retention period for completed remediation activities. To keep the **Remediation** page performing optimally, the remediation activity will be removed six months after the activity is completed.+> There's a 180 day retention period for completed remediation activities. To keep the **Remediation** page performing optimally, completed remediation activities are removed six months after completion. <a name="completed-by-column"></a> ### Use the Completed by column to track remediation ownership@@ -94,7 +98,7 @@ Track who closed the remediation activity with the "Completed by" column on the You can view **Top remediation activities** either on the **Overview** or **Dashboard** page, depending on if you're an XDR/MDI Preview customer. For more information, see [Microsoft Defender Vulnerability Management and Microsoft Security Exposure Management integration](microsoft-defender-vulnerability-management-exposure-management.md). -Select any of the entries to go to the **Remediation** page. You can mark the remediation activity as completed after the IT admin team remediates the task.+Select any entry in the **Top remediation activities** list to go to the **Remediation** page. You can mark a remediation activity as completed after the IT admin team remediates the associated security task.  