Microsoft Defender for Cloud
Cloud and workloads

Transition from grouped to individual recommendations in Defender for Cloud

In brief

Defender for Cloud has completed the transition from grouped recommendations (sub-assessments) to individual recommendations. Grouped recommendations were deprecated on July 31, 2026; individual recommendations are now the current posture model.

What Defender admins need to know

Update workflows, queries, governance rules, exemptions, and continuous export configurations to use individual recommendations and their applicable categories or replacements.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.


Adopting individual recommendations

Best practice: Start usingUse individual recommendations as your primary model for investigation and remediation. Grouped

Individual recommendations are deprecated on July 31, 2026.

The new individual recommendations are now the best‑practicecurrent posture model in Defender for Cloud. They provide clear benefits:

  • Granular & accurate prioritization – Each finding is scored individually, helping you focus on what reduces risk fastest.

  • Future‑proof – This is the model that will continue to evolve and be fully supported.

What is changingchanged

  • Each finding appears as a separate recommendationrecommendation.
  • Recommendation volume may increasecan be higher because findings are represented individually.
  • Prioritization becomes risk-basedis applied at the individual finding levellevel.

Where to start

After (individual recommendations model):

Each individual recommendation has a list of vulnerability findings. Instead of one aggregated entry per machine, you see individual findings per vulnerable software package, spanning Azure VMs, AKS nodes, EC2 instances, GCP instances, and containers, all within the SoftwareUpdate and ServiceUpgraderecommendation category.categories.

Update your Azure Resource Graph queries

| project DisplayName, Severity, DetectedVersions, FixedVersion, CveId


Key field changes between the two schemas:

| Old field | New field | Note |

---

## Managing the side-by-side experience

During the transition, both recommendation models may appear simultaneously.

**Best practice:** Actively control which model your teams work with to reduce confusion and duplicate effort.

### Keeping views manageable

- Use recommendation tags to filter your experience:
  - **New version** for individual recommendations
  - **Set for deprecation** for grouped recommendations
- Filter views based on the model your team is currently using
- Avoid leaving both models unfiltered unless explicitly required

:::image type="content" source="media/transition-grouped-individual-recommendations/recommendations-tags.png" alt-text="Screenshot of recommendation tags interface showing options for 'New version' and 'Set for deprecation' to filter recommendations." lightbox="media/transition-grouped-individual-recommendations/recommendations-tags.png":::

---

## Investigating and prioritizing at scale

Individual recommendations introduce increased granularity. To help you focus on the issues that matter most and handle the increased granularity of individual recommendations, Defender for Cloud provides several tools and views designed to assist you with effective investigation.

## How to manage the new individual recommendations

With the transition to **individual recommendations**, all Microsoft Defender for Cloud experiences continue to support **Governance rules**, **Continuous export**, and **[Exemptions](transition-disable-rules-exemptions.md)**

Key field changes between the two schemas:

| Old field | New field | Note |


Investigating and prioritizing at scale

Individual recommendations introduce increased granularity. To help you focus on the issues that matter most and handle the increased granularity of individual recommendations, Defender for Cloud provides several tools and views designed to assist you with effective investigation.

How to manage the new individual recommendations

With the transition to individual recommendations complete, Microsoft Defender for Cloud continues to support Governance rules, Continuous export, and Exemptions. The main change is how these actions are scoped.

Individual recommendations are created per software update, secret, or issue type. Because they are generated according to your resources' current state, actions are no longer applied to a single static recommendation. Instead, management actions are now applied at the **recommendation category**category level. ::

:::image type="content" source="media/transition-grouped-individual-recommendations/recommendation-categories.png" alt-text="Screenshot of available recommendation categories." lightbox="media/transition-grouped-individual-recommendations/recommendation-categories.png"::: ##

Classic secure score behavior after the transition

After the transition from grouped recommendations to individual recommendations, some classic secure score controls in the Azure portal can be affected by findings that are now represented through the individual recommendations model.

In some cases, a resource might appear as unhealthy in a secure score control even though the previous grouped recommendation is no longer visible under that control.

When this occurs, the applicable resources have associated security findings that contribute to the posture signal for that area. To investigate the underlying findings, switch to Risk view, which is the recommended view for reviewing and prioritizing findings.

Risk view provides the current, granular recommendation experience and helps you identify the specific findings that should be reviewed or remediated.

This behavior is expected as part of the transition to individual recommendations. The classic secure score in the Azure portal was designed to remain functionally stable through this transition while customers move to the individual recommendations model for investigation and remediation.

Remediate vulnerabilities

Deprecated grouped recommendationWhere to review now
Machines should have vulnerability findings resolved
Deprecated assessment ID: 1195afff-c881-495e-9bc5-1486211ae03f
Open Recommendations and filter by recommendation category SoftwareUpdate.
EC2 instances should have vulnerability findings resolved
Deprecated assessment ID: 77a4a140-e051-481a-84cc-d4bf2109bd65
Open Recommendations and filter by recommendation category SoftwareUpdate.
GCP compute instances should have vulnerability findings resolved
Deprecated assessment ID: 0a03fa35-e381-4e2f-ace6-2b9913db3381
Open Recommendations and filter by recommendation category SoftwareUpdate.
AKS nodes should have vulnerability findings resolved
Deprecated assessment ID: 24a15fbd-cfe4-4dff-b2be-1c367a6b2031
Open Recommendations and filter by recommendation category ServiceUpgrade.
Azure registry container images should have vulnerabilities resolved
Deprecated assessment ID: c0b7cfc6-3172-465a-b378-53c7ff2cc0d5
Open Recommendations and filter by recommendation category SoftwareUpdate.
Container images in Azure registry should have vulnerability findings resolved
Deprecated assessment ID: 33422d8f-ab1e-42be-bc9a-38685bb567b9
Open Recommendations and filter by recommendation category SoftwareUpdate.
Azure running container images should have vulnerabilities resolved
Deprecated assessment ID: c609cf0f-71ab-41e9-a3c6-9a1f7fe1b8d5
Open Recommendations and filter by recommendation category SoftwareUpdate.
AWS running container images should have vulnerability findings resolved
Deprecated assessment ID: 682b2595-d045-4cff-b5aa-46624eb2dd8f
Open Recommendations and filter by recommendation category SoftwareUpdate.
GCP running container images should have vulnerability findings resolved
Deprecated assessment ID: e538731a-80c8-4317-a119-13075e002516
Open Recommendations and filter by recommendation category SoftwareUpdate.
GitHub repositories should have dependency vulnerability scanning findings resolved
Deprecated assessment ID: 945f7b1c-8def-4ab3-a44d-1416060104b3
Open Recommendations and filter by recommendation category SoftwareUpdate.
Azure DevOps repositories should have dependency vulnerability scanning findings resolved
Deprecated assessment ID: 2ea72208-8558-4011-8dcd-d93375a4003d
Open Recommendations and filter by recommendation category SoftwareUpdate.
GitLab projects should have dependency vulnerability scanning findings resolved
Deprecated assessment ID: 1bc53aae-c92e-406b-9693-d46caf3934fa
Open Recommendations and filter by recommendation category SoftwareUpdate.
GitHub repositories should have Shai-Hulud 2.0 compromised packages findings resolved
Deprecated assessment ID: 14c00325-f0ee-4c12-bbaf-4059647d919c
Open Recommendations and filter by recommendation category SoftwareUpdate.
Azure DevOps repositories should have Shai-Hulud 2.0 compromised packages findings resolved
Deprecated assessment ID: 70f5bbd7-c8bd-4b6f-a877-fa46b2719606
Open Recommendations and filter by recommendation category SoftwareUpdate.
GitHub repositories should have code scanning findings resolved
Deprecated assessment ID: 18aa4e75-776a-4296-97f0-fe1cf10d679c
Open Recommendations and filter by recommendation category CodeVulnerabilities.
Azure DevOps repositories should have code scanning findings resolved
Deprecated assessment ID: 99232bb2-9b21-4bbb-8e3c-763673b9923d
Open Recommendations and filter by recommendation category CodeVulnerabilities.
GitLab projects should have code scanning findings resolved
Deprecated assessment ID: cd3e4ff3-b1bc-4a42-b10d-e2f9f99e2991
Open Recommendations and filter by recommendation category CodeVulnerabilities.

Enable access management

The following recommendations were replaced by single new recommendations. Use the new assessment key for future governance, exemption, and export configurations.

Deprecated grouped recommendationWhere to review now
Guest accounts with read permissions on Azure resources should be removed
Deprecated assessment ID: fde1c0c9-0fd2-4ecc-87b5-98956cbc1095
Open Recommendations and search for replacement assessment ID 422107c6-5b9a-46a6-bb1d-26ef1cc52d65.
Guest accounts with write permissions on Azure resources should be removed
Deprecated assessment ID: 0354476c-a12a-4fcc-a79d-f0ab7ffffdbb
Open Recommendations and search for replacement assessment ID 009678ce-adce-4c94-9cc8-cfc2bd0c6a06.
Guest accounts with owner permissions on Azure resources should be removed
Deprecated assessment ID: 20606e75-05c4-48c0-9d97-add6daa2109a
Open Recommendations and search for replacement assessment ID f2864482-b329-4310-8c06-3cf74fe880c5.
Disabled accounts with read and write permissions on Azure resources should be removed
Deprecated assessment ID: 1ff0b4c9-ed56-4de6-be9c-d7ab39645926
Open Recommendations and search for replacement assessment ID 9b4f4dd4-24fc-42ba-9978-2a1cf575d36d.
Disabled accounts with owner permissions on Azure resources should be removed
Deprecated assessment ID: 050ac097-3dda-4d24-ab6d-82568e7a50cf
Open Recommendations and search for replacement assessment ID a4899b81-b689-4e0d-aa29-45983ab8b7fc.

Implement security configuration best practices

Deprecated grouped recommendationWhere to review now
Vulnerabilities in security configuration on your Windows machines should be remediated (powered by Guest Configuration)
Deprecated assessment ID: 8c3d9ad0-3639-4686-9cd2-2b2ab2609bda
Open Recommendations and filter by recommendation category HostMisconfigurations.
Vulnerabilities in security configuration on your Linux machines should be remediated (powered by Guest Configuration)
Deprecated assessment ID: 1f655fb7-63ca-4980-91a3-56dbc2b715c6
Open Recommendations and filter by recommendation category HostMisconfigurations.
SQL databases should have vulnerability findings resolved
Deprecated assessment ID: 82e20e14-edc5-4373-bfc4-f13121257c37
Open Recommendations and review the SQL vulnerability assessment individual recommendations.
SQL servers on machines should have vulnerability findings resolved
Deprecated assessment ID: f97aa83c-9b63-4f9a-99f6-b22c4398f936
Open Recommendations and review the SQL vulnerability assessment individual recommendations.
EDR configuration issues should be resolved on virtual machines
Deprecated assessment ID: dc5357d0-3858-4d17-a1a3-072840bff5be
Open Recommendations and review replacement assessment IDs d44de051-1862-48f8-8476-192aee854699, aafa7d27-01ae-40c6-a56c-1d0ef04b1d71, and 506d18a1-d571-4341-aad5-a7d363c5bbd4.
EDR configuration issues should be resolved on EC2s
Deprecated assessment ID: 695abd03-82bd-4d7f-a94c-140e8a17666c
Open Recommendations and review replacement assessment IDs d44de051-1862-48f8-8476-192aee854699, aafa7d27-01ae-40c6-a56c-1d0ef04b1d71, and 506d18a1-d571-4341-aad5-a7d363c5bbd4.
EDR configuration issues should be resolved on GCP Virtual machines
Deprecated assessment ID: f36a15fb-61a6-428c-b719-6319538ecfbc
Open Recommendations and review replacement assessment IDs d44de051-1862-48f8-8476-192aee854699, aafa7d27-01ae-40c6-a56c-1d0ef04b1d71, and 506d18a1-d571-4341-aad5-a7d363c5bbd4.
GitHub repositories should have API security testing findings resolved
Deprecated assessment ID: 7ad00833-a0f0-47b9-b377-5665bd5d9074
Open Recommendations and filter by recommendation category ApiVulnerabilities.
Azure DevOps repositories should have API security testing findings resolved
Deprecated assessment ID: d42301a5-4d23-4457-97c8-f2f2e9eb979e
Open Recommendations and filter by recommendation category ApiVulnerabilities.
Azure DevOps security posture management findings should be resolved
Deprecated assessment ID: 7b123b34-1f78-4902-abb6-3b813abe9866
Open Recommendations and filter by recommendation category CodeVulnerabilities.
GitHub repositories should have infrastructure as code scanning findings resolved
Deprecated assessment ID: d9be0ff8-3eb0-4348-82f6-c1e735f85983
Open Recommendations and filter by recommendation category IacVulnerabilities.
Azure DevOps repositories should have infrastructure as code scanning findings resolved
Deprecated assessment ID: 6588c4d4-fbbb-4fb8-be45-7c2de7dc1b3b
Open Recommendations and filter by recommendation category IacVulnerabilities.
GitLab projects should have infrastructure as code scanning findings resolved
Deprecated assessment ID: ec1bface-60ff-46b6-b1dc-67171a4882d5
Open Recommendations and filter by recommendation category IacVulnerabilities.
GitHub security posture management findings should be resolved
Deprecated assessment ID: fd104c01-29d0-428d-bb62-2c936addd2cf
Open Recommendations and review the GitHub posture recommendations across the mapped Defender for DevOps categories.

Apply system updates

Deprecated grouped recommendationWhere to review now
System updates should be installed on your machines (powered by Azure Update Manager)
Deprecated assessment ID: e1145ab1-eb4f-43d8-911b-36ddf771d13f
Open Recommendations and filter by recommendation category SystemUpdate.

If one of these secure score controls shows unhealthy resources but the underlying grouped recommendation isn't visible, review the applicable findings in Risk view. The findings are represented through the current individual recommendations model rather than the deprecated grouped recommendation experience.

What you should do now
  • Adopt individual recommendations for investigation and remediation
  • Define a clear internal operating model for the transition period
  • Use filters and tags to limit views to the model your team is actively using
  • Prioritize Critical and High risk individual recommendations in daily operations
  • Use aggregation views to scale remediation and investigation efficiently
  • Review your existing scripts and queries that target sub-assessments and update them using the recommendation transition reference

  • Use individual recommendations as the primary model for investigation and query examplesremediation.
  • Use Risk view to identify and prioritize findings associated with unhealthy resources.
  • Update Azure Resource Graph queries, governance rules, continuous export configurations, and exemption workflows that relied on grouped recommendations or sub-assessments.
  • Use recommendation categories, such as SoftwareUpdate, SystemUpdate, HostMisconfigurations, and ExposedSecrets, where applicable.
  • Expect recommendation volume to increase in this articlesome areas because individual findings provide more actionable detail. This increase doesn't necessarily indicate that risk increased.
  • CompletingUse the recommendation transition reference to identify the current recommendation category or replacement recommendation.
  • Complete your migration from disable rules to exemptions.

Recommendation transition reference

Use this reference to map each deprecated grouped recommendation to its recommendation ID and current recommendation category.category or replacement recommendation. Recommendations are organized by product. This is your reference for:

  • Updating governance rules, exemption rules, and continuous export — these now target a recommendation category instead of a specific recommendation key. Find the category for each recommendation you currently manage, then update your configurations to use that category.
  • Migrating queries — replace grouped recommendation IDs with the microsoft.security/assessments resource type and filter by properties.metadata.recommendationCategory. The recommendation ID column helps you verify you're targeting the right recommendations.

    Your queries will also return more results because recommendation categories span multiple workloads. In the grouped model, a query was scoped to a specific recommendation ID and resource type, for example, Azure VMs only. In the new model, querying the SoftwareUpdate recommendation category returns findings across Azure VMs, EC2 instances, AKS nodes, GCP instances, and containers combined. Adjust your filters accordingly.

Each grouped recommendation transitionstransitioned to one of two end-end states:

  • Replaced by individual recommendations — The grouped recommendation is replaced by individual recommendations generated dynamically per finding. Update governance rules, exemptions, and continuous export to target the Recommendation category instead of the recommendation ID.
  • Replaced by a single new recommendation — The grouped recommendation is replaced by a specific new individual recommendation with a fixed recommendation ID. The recommendation category shows as Unknown. Update your configurations to use the New recommendation ID directly — don't use the category filter for these recommendations.

Microsoft Defender for Servers

The following grouped recommendations transitiontransitioned under Microsoft Defender for Servers.

How to review findings: Remediate machine vulnerabilities

Microsoft Defender for Databases

The following grouped SQL recommendations transitiontransitioned under Microsoft Defender for Databases. After the transition, each SQL vulnerability assessment rule appears as an individual recommendation.recommendation reported on the database resource instead of the server resource. To analyze findings for an Azure SQL database, open the resource in the Azure portal, go to Microsoft Defender for Cloud, and select the specific finding to see the rule description, severity, and remediation guidance. For SQL servers on machines, open the Recommendations page in Defender for Cloud, find the relevant individual recommendation, and follow the same remediation steps.

How to review findings:Learn about remediation approaches and how to review findings.

Deprecated recommendations — the following grouped recommendations are deprecated and don't have a single direct replacement. They are replaced by the new individual SQL vulnerability assessment recommendations now available in Defender for Cloud. For the full list, see SQL vulnerability assessment rules and recommendations mapping.

Microsoft Defender for Containers

The following grouped recommendations transitiontransitioned under Microsoft Defender for Containers. After the transition, container vulnerability findings appear as individual recommendations, with each vulnerable image layer or package surfaced as a separate finding.

How to review findings: View and remediate vulnerabilities for containers running on Kubernetes clusters | View and remediate vulnerability assessment findings for registry images

Microsoft Defender for DevOps

The following grouped recommendations transitiontransitioned under Microsoft Defender for DevOps. After the transition, individual findings for code scanning, dependency vulnerabilities, secrets, infrastructure as code issues, and API security appear in the relevant recommendation categories.

How to review findings: In Defender for Cloud, go to Recommendations and filter by the relevant category: ApiVulnerabilities, SoftwareUpdate, CodeVulnerabilities, IacVulnerabilities, or ExposedSecrets. Select any individual recommendation to view the affected repository, finding details, and remediation steps.