Microsoft Security Exposure Management
Vulnerabilities and exposure

What is Microsoft Security Exposure Management?

In brief

The documentation now states that Microsoft Security Exposure Management is available only in Public Cloud and unavailable in national or sovereign clouds, including US Gov and China Gov. It also adds descriptions of the Overview dashboard’s Resolve Now and Monitor Exposure views.

What Defender admins need to know

Admins in sovereign clouds should not expect this capability to be available. No administrator action is stated.

Summaries are generated from the documentation change itself.

Documentation change

The comparison below shows only the changed extract. Use the full-page view for complete context.

What is Microsoft Security Exposure Management?

With the integration of Defender for Cloud in the Defender portal, MSEM now provides comprehensive exposure management across endpoints and cloud environments, aggregating signals from Azure, AWS, and GCP (via Defender for Cloud integration) alongside traditional on-premises signals. This unified exposure graph covers devices, identities, cloud assets, and external attack surfaces, aligning with Gartner's Continuous Threat Exposure Management (CTEM) approach to provide end-to-end visibility and risk management.

Who uses Security Exposure Management?

  • Discover and safeguard critical assets: Security Exposure Management marks predefined assets and assets you customize as critical across all domains including devices, identities, and cloud resources. This enables you to focus and prioritize on those critical assets to ensure security and business continuity.

  • Manage exposure: Security Exposure Management provides tools to manage security exposure, and mitigate exposure risk.

    • The Overview dashboard organizes work around two core actions:
      • Resolve Now — Prioritized, actionable items across Patch, Mitigate, and Fix categories, focused on internet-exposed and business-critical assets.
      • Monitor Exposure — A real-time view of internet-exposed resources (cloud assets, devices, shadow resources) and domain initiative scores across Code, Endpoint, Cloud, Identity, and SaaS.
    • Exposure insights aggregate security posture data, and provide rich context around the security posture state of your asset inventory.
    • Use these insights to prioritize security efforts and investments.
    • Insights include security events, recommendations, metrics, and security initiatives.
    • As you manage exposure risk, attack paths show you how an attacker might breach your attack surface, including hybrid attack paths that span on-premises and cloud contexts.
      • Security Exposure Management generates attack paths based on data collected across assets and workloads from multiple environments. It simulates attack scenarios, and identifies weaknesses that an attacker could exploit across endpoints and cloud resources.