Microsoft Security Exposure Management
Vulnerabilities and exposure

Review security recommendations in Microsoft Security Exposure Management

In brief

The article is now labeled as a how-to guide, adds author and AI-use metadata, simplifies its introduction, and reformats the transition tip. It continues to explain that seeing both recommendation formats or Preview-tagged recommendations is expected during the transition.

What Defender admins need to know

Administrators can use the updated guidance to interpret mixed recommendation formats during the transition.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

Review security recommendations

This article describes how to workWork with security recommendations in the new unified recommendations experience in Microsoft Security Exposure Management.

Before you start

  • The old grouped recommendations still appear side by side with the new format for now, but they will eventually be deprecated.
  • These recommendations are marked as Preview. This tag indicates that the recommendation is in an early state and does not affect Secure Score yet.
  • Secure Score currently applies to the parent recommendation only, not to each individual item.

Tip: If you see both formats or recommendations with a Preview tag, this is expected during the transition. The goal is to improve clarity and allow customers to act on specific recommendations more easily.

With the integration of Defender for Cloud in the Defender portal, you can also access enhanced cloud recommendations through the unified interface:

With the integration of Defender for Cloud in the Defender portal, you can also access enhanced cloud recommendations through the unified interface: