Agent Foskett Academy • Microsoft Defender for Cloud • Module 2 • Lesson 11

Lesson 11 — Understanding Security Recommendations

Security recommendations explain where cloud resources do not meet expected security controls.

This lesson shows how to read a recommendation, understand its risk context, inspect affected resources and recognise the evidence and guidance needed before deciding what happens next.

A recommendation is not just a warning. It is a structured security assessment that must be understood before it is prioritised, remediated or exempted.
Agent Foskett Understanding Security Recommendations lesson
What you will learn

This lesson explains how to interpret recommendation details before taking action.

Recommendation anatomy
Affected resources
Risk and evidence
Assessment states

Security recommendation lifecycle

Cloud resource is discovered ↓ Security standard or assessment evaluates the resource ↓ Configuration or security condition is checked ↓ Assessment result becomes healthy, unhealthy or not applicable ↓ An unhealthy result appears as a recommendation ↓ Affected resources are listed ↓ Risk, severity and supporting context are displayed ↓ Remediation guidance explains the expected correction ↓ The finding is reviewed by an owner ↓ The resource is remediated, exempted or accepted ↓ Defender for Cloud reassesses the resource ↓ The recommendation status is updated

Recommendation anatomy

FieldWhat it tells youQuestion to ask
Recommendation titleSummarises the security condition that requires attention.What control or weakness is being reported?
Risk level or severityIndicates the expected impact and contextual risk.How serious is the issue in this environment?
Affected resourcesLists the resources currently assessed as unhealthy.Which systems, subscriptions or accounts are involved?
DescriptionExplains the security problem and why it matters.What exposure does this condition create?
Remediation guidanceProvides the actions expected to correct the finding.What configuration or operational change is required?
Assessment metadataIdentifies the assessment, standard, source and technical details.Where did the finding come from and how is it evaluated?
Secure Score impactShows whether the control contributes to Secure Score.Will correction improve measured posture?
Regulatory mappingShows links to standards or compliance controls where available.Does this finding affect governance obligations?

Recommendation review workflow

Open the recommendation ↓ Read the title and description ↓ Confirm the assessment source ↓ Review risk level and severity ↓ Inspect affected resources ↓ Check internet exposure and attack-path context ↓ Review resource criticality and ownership ↓ Read remediation guidance ↓ Confirm whether the finding is current ↓ Check for existing exemptions or compensating controls ↓ Record the recommendation for prioritisation ↓ Move to the appropriate operational workflow

Agent Foskett investigation: “The recommendation wasn’t wrong…”

A storage account appeared in a recommendation ↓ The application team said the finding was a false positive ↓ They believed public access had already been disabled ↓ Agent Foskett opened the affected resource ↓ The account-level setting looked secure ↓ The recommendation still showed the resource as unhealthy ↓ The resource contained a container with anonymous access enabled ↓ The team had checked the storage account ↓ They had not checked the individual container configuration ↓ The recommendation description was reviewed again ↓ The affected component was identified ↓ Anonymous access was removed ↓ The resource was reassessed ↓ The recommendation changed to healthy ↓ The finding had been accurate ↓ The original investigation had stopped too early
The recommendation was not wrong. The investigation had examined the wrong configuration layer.

Key takeaways

  • Security recommendations are generated from assessments against enabled security standards and controls.
  • A recommendation describes a security weakness and identifies affected resources.
  • Healthy, unhealthy and not-applicable states help explain assessment results.
  • Risk level, severity and Secure Score impact are related but are not identical.
  • The resource-level view is essential because the same recommendation can affect very different systems.
  • Remediation guidance explains the expected correction but still requires change planning and validation.
  • Scope, connector health and assessment freshness can affect visible findings.
  • Exemptions change how a finding is handled; they do not automatically remove the technical condition.
  • A recommendation should be understood before it is prioritised or remediated.
  • Closure should be confirmed through reassessment and evidence.

Learning objectives

After completing this lesson, you should be able to explain what a security recommendation is, read its details and investigate affected resources.

What is a security recommendation?

A security recommendation is an actionable finding produced when a resource does not satisfy an enabled security assessment.

Assessment source

Recommendations can be produced by built-in standards, custom standards, Azure Policy-based controls and workload-specific assessments.

Healthy state

A healthy resource currently satisfies the evaluated security condition.

Unhealthy state

An unhealthy resource does not satisfy the evaluated security condition and appears in the recommendation.

Not applicable

A not-applicable result means the assessment does not apply to the resource or its current configuration.

Unknown or unavailable state

Missing data, connector problems, unsupported configurations or incomplete assessment can prevent a definitive result.

Recommendation title

The title should identify the required security outcome rather than be treated as the complete technical explanation.

Recommendation description

The description explains the weakness, expected protection and potential security impact.

Affected resources

The affected-resources list identifies exactly which assets are currently associated with the finding.

Resource-level details

Open individual resources because the cause, ownership, exposure and remediation path can differ.

Risk level

Context-aware risk can consider potential impact, resource exposure, connections and attack-path relationships.

Severity

Severity indicates the seriousness of the security issue but should be interpreted with environmental context.

Secure Score relationship

Some recommendations contribute to Secure Score through security controls; others may not affect the score.

Recommendation category

Categories help group findings into areas such as compute, data, identity, networking, containers and application security.

Cloud environment

Recommendations can cover Azure, AWS, Google Cloud and hybrid resources when the required connectors and assessments are available.

Resource scope

Always confirm the management group, subscription, account, project, resource group and resource represented by the finding.

Assessment ID

The assessment identifier is useful for automation, Azure Resource Graph queries, APIs and technical troubleshooting.

Policy relationship

Many recommendations are connected to security policies and initiatives that define the expected configuration.

Custom recommendations

Custom standards and assessments can create organisation-specific recommendations beyond built-in controls.

Risk factors

Risk factors can include internet exposure, sensitive data, privileged access, known vulnerabilities and attack-path membership.

Attack-path relationship

Recommendations appearing in attack paths can represent steps an attacker could use to reach a valuable target.

Evidence

Evidence can include configuration values, vulnerable components, exposed endpoints or other assessment details.

Remediation guidance

Guidance describes how to correct the condition, but the implementation should follow change control and testing.

Fix option

Some recommendations provide a Fix action for supported resources; availability varies by recommendation and resource.

Manual remediation

When no automated fix exists, follow the recommended configuration steps and validate the result.

Learn more

Supporting documentation can explain prerequisites, limitations, expected impact and platform-specific procedures.

Regulatory mapping

A recommendation may map to one or more compliance standards, controls or security benchmarks.

Ownership

The team that operates the affected resource should be identified before the recommendation enters remediation.

Business context

Resource importance, data sensitivity and operational dependencies are not always visible in the recommendation.

Assessment freshness

A recommendation can remain visible until the assessment runs again and the updated state is processed.

Connector health

Broken or stale cloud connectors can produce incomplete or outdated posture information.

Agent-based assessment

Some recommendations depend on installed agents, extensions or workload telemetry.

Agentless assessment

Other recommendations can be generated from cloud configuration, APIs and agentless scanning.

Resource changes

Deletion, movement, renaming, subscription transfer or connector changes can affect how a recommendation appears.

Filtering

Use filters to narrow recommendations by environment, subscription, resource type, severity, risk, owner or status.

Sorting

Sort findings to support review, but do not assume the first item in the portal is automatically the first operational priority.

Search

Search by recommendation name, resource or technical identifier to locate a specific finding.

Export

Exported recommendation data can support reporting, ticket creation and analysis outside the portal.

Azure Resource Graph

Resource Graph queries can identify recommendation records and affected resources across large environments.

API access

Defender for Cloud and Azure APIs can support automation, reporting and integration with operational systems.

Exemptions overview

An exemption records that a recommendation or resource will not be handled through normal remediation for a defined reason.

Risk accepted

Risk accepted means the organisation knowingly accepts the exposure under approved governance.

Mitigated

Mitigated indicates that another control is believed to reduce the risk even though the recommendation remains technically unmet.

Exemption expiry

Time-limited exemptions force accepted conditions to be reviewed again.

False-positive assumption

Do not label a finding as false positive until the exact assessment logic and affected component have been checked.

Common reading error

A common mistake is reading only the recommendation title and ignoring resource-level evidence.

Another common error

Teams sometimes inspect the parent resource while the unhealthy setting exists on a child object or component.

Recommendation age

Old findings should be checked for assessment freshness, resource lifecycle and connector status.

Validation after change

After a configuration change, confirm the actual setting, service operation and updated recommendation state.

Operational workflow

A recommendation should move through review, ownership, prioritisation, remediation, validation and closure.

Governance reporting

Reports should show recommendation age, owner, affected critical resources, status, exemptions and overdue actions.

What Agent Foskett checked

Agent Foskett checked the recommendation text, affected component, assessment source, actual configuration and reassessment result.

Best practices

  • Read the full recommendation description.
  • Confirm the assessment source.
  • Inspect affected resources individually.
  • Check the exact configuration layer.
  • Review risk and severity in context.
  • Identify the resource owner.
  • Check assessment freshness and connector health.
  • Document exemptions and compensating controls.
  • Validate remediation technically.
  • Confirm the reassessed status before closure.

Continue learning

Next, learn how to combine risk, exposure, attack paths and business importance to decide which recommendations should be addressed first.

What are Microsoft Defender for Cloud security recommendations?

Microsoft Defender for Cloud security recommendations are actionable findings generated when cloud or hybrid resources do not satisfy enabled security assessments, standards or controls.

Understanding Security Recommendations Lesson

This Agent Foskett lesson explains recommendation anatomy, affected resources, healthy and unhealthy states, risk levels, severity, assessment sources, remediation guidance, Secure Score relationships, exemptions and validation.