Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 14

Lesson 14 — Governance Rules

Security recommendations only reduce risk when somebody is responsible for acting on them.

This lesson explains how Microsoft Defender for Cloud governance rules assign owners, define due dates, track remediation progress and establish accountability across subscriptions and resource groups.

A recommendation without an owner is usually a recommendation that never gets fixed.
Agent Foskett Governance Rules lesson
What you will learn

This lesson explains how governance rules turn recommendations into owned and time-bound work.

Owner assignment
Due dates
Rule scope
Accountability

Governance rule lifecycle

Security recommendation appears ↓ Governance rule evaluates the finding ↓ Scope and recommendation filters are matched ↓ An owner is assigned ↓ A remediation due date is calculated ↓ The recommendation becomes governed ↓ The owner investigates and remediates ↓ Progress is tracked ↓ Overdue work is identified ↓ The recommendation is reassessed ↓ Closure is validated ↓ Governance reporting confirms accountability

Governance rule components

ComponentPurposeGovernance effect
Rule nameIdentifies the governance requirement.Helps teams understand the purpose and responsibility model.
ScopeDefines which subscriptions or resource groups are evaluated.Ensures the rule applies to the intended cloud estate.
Recommendation filtersSelects which recommendation types the rule governs.Allows different ownership and deadlines for different risks.
OwnerAssigns accountability to a person or team.Removes uncertainty about who must act.
Remediation timeframeDefines how long the owner has to address the finding.Creates measurable due dates and overdue status.
Grace periodProvides time before a recommendation becomes overdue.Balances urgency with operational reality.
Priority and contextLinks governance to risk and business importance.Supports realistic service-level expectations.
Status trackingShows governed, due and overdue work.Supports reporting, escalation and remediation oversight.

Designing effective governance rules

  • Start with a clear ownership model for subscriptions, resource groups and application teams.
  • Use scopes that align with operational responsibility.
  • Apply recommendation filters carefully so rules do not create conflicting assignments.
  • Set due dates according to risk rather than using one timeframe for every finding.
  • Define who reviews overdue recommendations.
  • Document how exceptions and compensating controls are handled.
  • Review rules when organisational structure or cloud ownership changes.
  • Measure whether governed recommendations are actually being remediated faster.

Agent Foskett investigation: “Everyone thought someone else was fixing it…”

Defender for Cloud identified a critical recommendation ↓ The finding affected an internet-facing production resource ↓ The security team assumed Infrastructure owned the fix ↓ Infrastructure assumed the application team owned it ↓ The application team assumed Security would handle it ↓ No owner was formally assigned ↓ The recommendation remained open ↓ Weeks became months ↓ The recommendation aged without escalation ↓ An audit asked who was accountable ↓ Nobody could provide an answer ↓ Agent Foskett reviewed the governance configuration ↓ There was no governance rule for the affected scope ↓ A rule was created ↓ The application owner was assigned ↓ A risk-based due date was set ↓ The recommendation was remediated ↓ The issue had never been technical ↓ It had been an accountability failure
Everyone knew the recommendation existed, but nobody owned the outcome.

Key takeaways

  • Governance rules assign responsibility for security recommendations.
  • Rules can be scoped to subscriptions and resource groups.
  • Recommendation filters allow different governance approaches for different risks.
  • Owners should align with real operational responsibility.
  • Due dates should reflect risk, exposure and business impact.
  • Overdue recommendations need a defined escalation process.
  • Exceptions should be documented, approved and time limited.
  • Governance rules should be reviewed when ownership or cloud structure changes.
  • Reporting should measure accountability as well as recommendation volume.
  • Clear ownership turns security findings into completed remediation work.

Learning objectives

After completing this lesson, you should be able to explain governance rules, define rule scope, assign owners and establish remediation deadlines.

Why governance matters

Technical findings often remain unresolved because responsibility and deadlines are unclear.

Governance rules overview

Governance rules help organisations assign and track responsibility for Defender for Cloud recommendations.

Rule scope

A governance rule can target the subscriptions or resource groups managed by a particular team.

Subscription scope

Subscription-level rules are useful when one team owns security remediation across the entire subscription.

Resource group scope

Resource group scope can align governance with application, project or business-unit ownership.

Recommendation filters

Filters determine which recommendations are included in a governance rule.

Severity filters

Severity can help separate urgent recommendations from lower-risk improvement work.

Recommendation type

Different recommendation categories may require different owners and deadlines.

Owner assignment

The owner should be the person or team with authority and capability to complete remediation.

Security team ownership

Security teams may own investigation, oversight or specialist controls, but not every infrastructure change.

Platform team ownership

Platform teams may own shared cloud services, network controls, identity platforms and baseline configuration.

Application team ownership

Application teams often own workload-specific configuration, dependencies and testing.

Business ownership

Business owners may need to accept risk, approve outages or prioritise remediation work.

Due dates

Due dates turn recommendations into measurable commitments.

Risk-based deadlines

Critical exposed findings should receive shorter deadlines than isolated low-impact issues.

Grace periods

A grace period provides time for remediation before a recommendation becomes overdue.

Overdue status

Overdue recommendations indicate that agreed remediation expectations have not been met.

Escalation

Define who is notified when critical or high-risk remediation becomes overdue.

Service-level targets

Governance rules can support service-level targets for different recommendation priorities.

Owner changes

Rules should be updated when teams, applications or subscription ownership change.

Conflicting rules

Overlapping rules can create confusion if ownership and precedence are not designed carefully.

Rule precedence

Understand how multiple rules affect the same recommendation and ensure the intended owner is assigned.

Governed recommendations

A governed recommendation has ownership and a remediation timeframe attached to it.

Ungoverned recommendations

Ungoverned findings may lack accountability and are more likely to remain open.

Tracking progress

Governance reporting should show assigned, due, overdue and completed work.

Security posture reporting

Governance data adds accountability context to Secure Score and recommendation reporting.

Management reporting

Managers need visibility into overdue risks, accountable teams and remediation trends.

Executive reporting

Executives need a concise view of critical exposures, ownership gaps and unresolved overdue work.

Operational dashboards

Operational teams need resource-level detail, due dates, owners and remediation status.

Audit evidence

Governance records can demonstrate that recommendations are assigned, tracked and reviewed.

Exceptions

A formal exception may be appropriate when remediation is not currently possible.

Exception owner

Every exception should have an accountable owner.

Exception expiry

Exceptions should expire or be reviewed rather than remaining permanent.

Compensating controls

Temporary controls can reduce risk while permanent remediation is planned.

Risk acceptance

Risk acceptance should be authorised by someone with appropriate business accountability.

Notifications

Notifications can help owners act before recommendations become overdue.

Workflow integration

Governance can be linked to ticketing, email or operational processes.

Remediation backlog

Governed recommendations should feed a central backlog that teams actively manage.

Prioritisation

Governance rules should support, not replace, risk-based prioritisation.

Resource ownership metadata

Tags, subscription structure and application inventories can help identify the correct owner.

Cloud operating model

Governance rules work best when cloud responsibilities are already defined.

Shared responsibility

Some recommendations require cooperation between security, platform and application teams.

Review frequency

Review governance rules regularly to ensure scopes, owners and deadlines remain accurate.

Metrics

  • Percentage of recommendations governed
  • Ungoverned critical and high recommendations
  • Recommendations due soon
  • Overdue recommendations
  • Mean time to assign an owner
  • Mean time to remediate
  • Owner response rate
  • Expired exceptions
  • Recurring ownership gaps

Mean time to assign

Measure how quickly new recommendations receive an accountable owner.

Mean time to remediate

Measure the time from recommendation creation to validated remediation.

Overdue trend

An increasing overdue trend may indicate unrealistic deadlines, insufficient capacity or weak escalation.

What Agent Foskett checked

Agent Foskett checked recommendation age, scope, ownership, due dates, escalation and governance rule coverage.

Best practices

  • Align governance scope with real operational ownership.
  • Assign accountable teams rather than generic mailboxes where possible.
  • Use risk-based remediation deadlines.
  • Avoid conflicting or overlapping rules.
  • Review overdue critical findings regularly.
  • Document exception and escalation processes.
  • Update rules when organisational ownership changes.
  • Integrate governance with operational workflows.
  • Measure governed coverage and remediation performance.
  • Validate that governance improves actual risk reduction.

Continue learning

Next, learn how exemption rules document approved exceptions and temporarily exclude recommendations from posture calculations.

What are Microsoft Defender for Cloud governance rules?

Microsoft Defender for Cloud governance rules assign owners, define remediation due dates and track accountability for security recommendations across subscriptions and resource groups.

Governance Rules Lesson

This Agent Foskett lesson explains governance rule scope, recommendation filters, owner assignment, due dates, grace periods, overdue status, escalation, exceptions, metrics and operational accountability.