Microsoft Defender Vulnerability Management
General

Remediate vulnerabilities with Microsoft Defender Vulnerability Management

In brief

The article now uses clearer section titles and wording for Intune security tasks, attention-required options, remediation activities, retention, and tracking entries.

What Defender admins need to know

Administrators can more easily navigate the guidance and understand which remediation activities can be tracked.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Remediate vulnerabilities with Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management allows you to remediate vulnerabilities discovered in your environment through actionable security recommendations. You can create remediation requests that your IT administrator team can use to remediate vulnerabilities using Microsoft Intune.

Request vulnerability remediation

Vulnerability management capabilities bridges the gap between Security and IT administrators through the remediation request workflow. Security admins like you can request for the IT Administrator to remediate a vulnerability from the Recommendation pages to Intune.

To use this capability, enable your Microsoft Intune connections. In the Microsoft Defender portal, navigate to Settings > Endpoints > General > Advanced features. Scroll down and look for Microsoft Intune connection. By default, the toggle is turned off. Turn your Microsoft Intune connection toggle On.

See Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint for details.

RemediationSubmit a remediation request steps

Use the following steps to create a remediation request from a security recommendation.

  1. Fill out the form, including what you are requesting remediation for, whether to open a ticket in Intune, priority, due date, and optional notes. Select Next.

    If you choose the attention required remediation option, you can't select a due date because therethat option doesn's no specific action.t create a remediation action to track.

  2. Review the details of your request then, select Submit. Submitting a remediation request creates a remediation activity item within vulnerability management, which can be used for monitoring the remediation progress for thisthe selected security recommendation. Submitting the remediation request doesn't trigger remediation or apply any changes to devices.

  3. Notify your IT Administrator about the new request and have them log into Intune to approve or reject the request and start a package deployment. If you want to check how the ticket shows up in Intune, See Use Intune to remediate vulnerabilities identified by Microsoft Defender for Endpoint for details.

Track remediation activities

After your organization's cybersecurity weaknesses are identified and mapped to actionable security recommendations, start creating security tasks. You can create tasks through the integration with Microsoft Intune where remediation tickets are created.

Lower your organization's exposure from vulnerabilities and increase your security configuration by remediating the security recommendations.

When you submit a remediation request from the Recommendations page, it kicks off a remediation activity. A security task is created that can be tracked on a Remediation page, and a remediation ticket is created in Microsoft Intune.

If you chose the attention required remediation option, there's no progress bar, ticket status, or due date since therethat option doesn's no actualt create a remediation action wethat can monitor.be monitored.

Once you're in the Remediation page, select the remediation activity that you want to view. You can follow the remediation steps, track progress, view the related recommendation, export to CSV, or mark as complete.

:::image type="content" source="/defender/media/remediation-flyouteolswnew.png" alt-text="Example of the Remediation page, with a selected remediation activity, and that activity's flyout listing the description, IT service and device management tools, and device remediation":::

Use the Completed by column to track remediation ownership

You can view Top remediation activities either on the Overview or Dashboard page, depending on if you're an XDR/MDI Preview customer. For more information, see Microsoft Defender Vulnerability Management and Microsoft Security Exposure Management integration.

Select any ofentry in the entriesTop remediation activities list to go to the Remediation page. You can mark thea remediation activity as completed after the IT admin team remediates the associated security task.

Screenshot of the Top remediation activities card listing remediation activities generated from security recommendations.