Lesson 14 — Governance Rules
Security recommendations only reduce risk when somebody is responsible for acting on them.
This lesson explains how Microsoft Defender for Cloud governance rules assign owners, define due dates, track remediation progress and establish accountability across subscriptions and resource groups.

What you will learn
This lesson explains how governance rules turn recommendations into owned and time-bound work.
Governance rule lifecycle
Governance rule components
| Component | Purpose | Governance effect |
|---|---|---|
| Rule name | Identifies the governance requirement. | Helps teams understand the purpose and responsibility model. |
| Scope | Defines which subscriptions or resource groups are evaluated. | Ensures the rule applies to the intended cloud estate. |
| Recommendation filters | Selects which recommendation types the rule governs. | Allows different ownership and deadlines for different risks. |
| Owner | Assigns accountability to a person or team. | Removes uncertainty about who must act. |
| Remediation timeframe | Defines how long the owner has to address the finding. | Creates measurable due dates and overdue status. |
| Grace period | Provides time before a recommendation becomes overdue. | Balances urgency with operational reality. |
| Priority and context | Links governance to risk and business importance. | Supports realistic service-level expectations. |
| Status tracking | Shows governed, due and overdue work. | Supports reporting, escalation and remediation oversight. |
Designing effective governance rules
- Start with a clear ownership model for subscriptions, resource groups and application teams.
- Use scopes that align with operational responsibility.
- Apply recommendation filters carefully so rules do not create conflicting assignments.
- Set due dates according to risk rather than using one timeframe for every finding.
- Define who reviews overdue recommendations.
- Document how exceptions and compensating controls are handled.
- Review rules when organisational structure or cloud ownership changes.
- Measure whether governed recommendations are actually being remediated faster.
Agent Foskett investigation: “Everyone thought someone else was fixing it…”
Key takeaways
- Governance rules assign responsibility for security recommendations.
- Rules can be scoped to subscriptions and resource groups.
- Recommendation filters allow different governance approaches for different risks.
- Owners should align with real operational responsibility.
- Due dates should reflect risk, exposure and business impact.
- Overdue recommendations need a defined escalation process.
- Exceptions should be documented, approved and time limited.
- Governance rules should be reviewed when ownership or cloud structure changes.
- Reporting should measure accountability as well as recommendation volume.
- Clear ownership turns security findings into completed remediation work.
Learning objectives
After completing this lesson, you should be able to explain governance rules, define rule scope, assign owners and establish remediation deadlines.
Why governance matters
Technical findings often remain unresolved because responsibility and deadlines are unclear.
Governance rules overview
Governance rules help organisations assign and track responsibility for Defender for Cloud recommendations.
Rule scope
A governance rule can target the subscriptions or resource groups managed by a particular team.
Subscription scope
Subscription-level rules are useful when one team owns security remediation across the entire subscription.
Resource group scope
Resource group scope can align governance with application, project or business-unit ownership.
Recommendation filters
Filters determine which recommendations are included in a governance rule.
Severity filters
Severity can help separate urgent recommendations from lower-risk improvement work.
Recommendation type
Different recommendation categories may require different owners and deadlines.
Owner assignment
The owner should be the person or team with authority and capability to complete remediation.
Security team ownership
Security teams may own investigation, oversight or specialist controls, but not every infrastructure change.
Platform team ownership
Platform teams may own shared cloud services, network controls, identity platforms and baseline configuration.
Application team ownership
Application teams often own workload-specific configuration, dependencies and testing.
Business ownership
Business owners may need to accept risk, approve outages or prioritise remediation work.
Due dates
Due dates turn recommendations into measurable commitments.
Risk-based deadlines
Critical exposed findings should receive shorter deadlines than isolated low-impact issues.
Grace periods
A grace period provides time for remediation before a recommendation becomes overdue.
Overdue status
Overdue recommendations indicate that agreed remediation expectations have not been met.
Escalation
Define who is notified when critical or high-risk remediation becomes overdue.
Service-level targets
Governance rules can support service-level targets for different recommendation priorities.
Owner changes
Rules should be updated when teams, applications or subscription ownership change.
Conflicting rules
Overlapping rules can create confusion if ownership and precedence are not designed carefully.
Rule precedence
Understand how multiple rules affect the same recommendation and ensure the intended owner is assigned.
Governed recommendations
A governed recommendation has ownership and a remediation timeframe attached to it.
Ungoverned recommendations
Ungoverned findings may lack accountability and are more likely to remain open.
Tracking progress
Governance reporting should show assigned, due, overdue and completed work.
Security posture reporting
Governance data adds accountability context to Secure Score and recommendation reporting.
Management reporting
Managers need visibility into overdue risks, accountable teams and remediation trends.
Executive reporting
Executives need a concise view of critical exposures, ownership gaps and unresolved overdue work.
Operational dashboards
Operational teams need resource-level detail, due dates, owners and remediation status.
Audit evidence
Governance records can demonstrate that recommendations are assigned, tracked and reviewed.
Exceptions
A formal exception may be appropriate when remediation is not currently possible.
Exception owner
Every exception should have an accountable owner.
Exception expiry
Exceptions should expire or be reviewed rather than remaining permanent.
Compensating controls
Temporary controls can reduce risk while permanent remediation is planned.
Risk acceptance
Risk acceptance should be authorised by someone with appropriate business accountability.
Notifications
Notifications can help owners act before recommendations become overdue.
Workflow integration
Governance can be linked to ticketing, email or operational processes.
Remediation backlog
Governed recommendations should feed a central backlog that teams actively manage.
Prioritisation
Governance rules should support, not replace, risk-based prioritisation.
Resource ownership metadata
Tags, subscription structure and application inventories can help identify the correct owner.
Cloud operating model
Governance rules work best when cloud responsibilities are already defined.
Shared responsibility
Some recommendations require cooperation between security, platform and application teams.
Review frequency
Review governance rules regularly to ensure scopes, owners and deadlines remain accurate.
Metrics
- Percentage of recommendations governed
- Ungoverned critical and high recommendations
- Recommendations due soon
- Overdue recommendations
- Mean time to assign an owner
- Mean time to remediate
- Owner response rate
- Expired exceptions
- Recurring ownership gaps
Mean time to assign
Measure how quickly new recommendations receive an accountable owner.
Mean time to remediate
Measure the time from recommendation creation to validated remediation.
Overdue trend
An increasing overdue trend may indicate unrealistic deadlines, insufficient capacity or weak escalation.
What Agent Foskett checked
Agent Foskett checked recommendation age, scope, ownership, due dates, escalation and governance rule coverage.
Best practices
- Align governance scope with real operational ownership.
- Assign accountable teams rather than generic mailboxes where possible.
- Use risk-based remediation deadlines.
- Avoid conflicting or overlapping rules.
- Review overdue critical findings regularly.
- Document exception and escalation processes.
- Update rules when organisational ownership changes.
- Integrate governance with operational workflows.
- Measure governed coverage and remediation performance.
- Validate that governance improves actual risk reduction.
Related Agent Foskett resources
Continue learning
What are Microsoft Defender for Cloud governance rules?
Microsoft Defender for Cloud governance rules assign owners, define remediation due dates and track accountability for security recommendations across subscriptions and resource groups.
Governance Rules Lesson
This Agent Foskett lesson explains governance rule scope, recommendation filters, owner assignment, due dates, grace periods, overdue status, escalation, exceptions, metrics and operational accountability.
