Microsoft Defender for Cloud
Cloud and workloads

Review security recommendations in Microsoft Defender for Cloud

In brief

The article now names the recommendation category tabs and explicitly labels the flat list, per-asset, and title views. It also refreshes transition wording, metadata, and related explanations.

What Defender admins need to know

Administrators can more easily identify recommendation views and navigate recommendations during the transition between grouped and individual formats.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


title: Review Security Recommendationssecurity recommendations in Microsoft Defender for Cloud description: Learn how to review security recommendations in Microsoft Defender for Cloud to improve the security posture of your environments. ms.topic: how-to ms.date: 06/30/07/03/2026 ms.custom: sfi-image-nochangenochange, msecd-doc-authoring-1013 zone_pivot_groups: defender-portal-experience #customer intent: As a security analyst, I want to learn how to review security recommendations in Microsoft Defender for Cloud so that I can improve the security posture of my environments. ai-usage: ai-assisted

  • These recommendations are marked as Preview. This tag indicates that the recommendation is in an early state and doesn't affect Secure Score yet.
  • Secure Score currently applies to the parent recommendation only, not to each individual item.

If you seeSeeing both formats or recommendations with a Preview tag, this conditiontag is expected during the transition. The goal isThis transition aims to improve clarity and allow you to act on specific recommendations more easily. For more information, see Transition from grouped to individual recommendations.

Prerequisites

  • Vulnerabilities: Software vulnerabilities requiring patches.
  • Exposed Secrets: Credentials and secrets that might be compromised.

These categoryThe All recommendations, Misconfigurations, Vulnerabilities, and Exposed Secrets tabs can help you focus your view by security category so that you can choose to see everything at once or drill down into specific areas.

Flat list view

The flat list view displays a list of all recommendations organized by individual assets, ordered by risk level. Each row represents a single recommendation affecting a specific resource.

:::image type="content" source="media/review-security-recommendations/review-by-findings.png" alt-text="Screenshot of Azure portal Flat list view showing a list of critical storage account recommendations by resource." lightbox="media/review-security-recommendations/review-by-findings.png":::

Resource views

In addition to Group by title, the Azure portal supports Group by resource. Grouping by resource places all findings for the same asset in one place, which is helpful when a single owner is responsible for an asset and should receive all of its findings together.

:::image type="content" source="media/review-security-recommendations/review-by-resource.png" alt-text="Screenshot of Azure security portal grouped by resource, showing critical findings, risk levels, recommendations, and owner columns." lightbox="media/review-security-recommendations/review-by-resource.png":::

Recommendation title view

The recommendation title view aggregates recommendations by title, showing a consolidated list ordered by risk level. Each row represents all instances of a particular recommendation across your environment.

  1. Sign in to the Azure portal.

Recommendation per asset view

ThisThe recommendation per asset view displays a list of all recommendations organized by individual assets, ordered by risk level. Each row represents a single recommendation affecting a specific resource.

When you select a recommendation row, a side panel opens displaying:

Recommendation title view

ThisThe recommendation title view aggregates recommendations by title, showing a consolidated list ordered by risk level. Each row represents all instances of a particular recommendation across your environment.

When you select an aggregated recommendation row, a side panel opens displaying:

Recommendation per resource view

In addition to Group by title, the portal supports Group by resource. This groupsGrouping by resource places all findings for the same asset in one place, which is helpful when a single owner is responsible for an asset and should receive all of its findings together.

:::image type="content" source="media/review-security-recommendations/defender-portal-recommendation-side-pane.png" alt-text="Screenshot of recommendations side pane." lightbox="media/review-security-recommendations/defender-portal-recommendation-side-pane.png":::

::: zone pivot="azure-portal"

You can interact with recommendations in multiple ways. If an option isn't available, that option isn't relevant to the selected recommendation.

  1. Sign in to the Azure portal.

  2. Remediate the recommendation.

::: zone-end

::: zone pivot="defender-portal"

  1. Review the results.

::: zone-end