Lesson 11 — Understanding Security Recommendations
Security recommendations explain where cloud resources do not meet expected security controls.
This lesson shows how to read a recommendation, understand its risk context, inspect affected resources and recognise the evidence and guidance needed before deciding what happens next.

What you will learn
This lesson explains how to interpret recommendation details before taking action.
Security recommendation lifecycle
Recommendation anatomy
| Field | What it tells you | Question to ask |
|---|---|---|
| Recommendation title | Summarises the security condition that requires attention. | What control or weakness is being reported? |
| Risk level or severity | Indicates the expected impact and contextual risk. | How serious is the issue in this environment? |
| Affected resources | Lists the resources currently assessed as unhealthy. | Which systems, subscriptions or accounts are involved? |
| Description | Explains the security problem and why it matters. | What exposure does this condition create? |
| Remediation guidance | Provides the actions expected to correct the finding. | What configuration or operational change is required? |
| Assessment metadata | Identifies the assessment, standard, source and technical details. | Where did the finding come from and how is it evaluated? |
| Secure Score impact | Shows whether the control contributes to Secure Score. | Will correction improve measured posture? |
| Regulatory mapping | Shows links to standards or compliance controls where available. | Does this finding affect governance obligations? |
Recommendation review workflow
Agent Foskett investigation: “The recommendation wasn’t wrong…”
Key takeaways
- Security recommendations are generated from assessments against enabled security standards and controls.
- A recommendation describes a security weakness and identifies affected resources.
- Healthy, unhealthy and not-applicable states help explain assessment results.
- Risk level, severity and Secure Score impact are related but are not identical.
- The resource-level view is essential because the same recommendation can affect very different systems.
- Remediation guidance explains the expected correction but still requires change planning and validation.
- Scope, connector health and assessment freshness can affect visible findings.
- Exemptions change how a finding is handled; they do not automatically remove the technical condition.
- A recommendation should be understood before it is prioritised or remediated.
- Closure should be confirmed through reassessment and evidence.
Learning objectives
After completing this lesson, you should be able to explain what a security recommendation is, read its details and investigate affected resources.
What is a security recommendation?
A security recommendation is an actionable finding produced when a resource does not satisfy an enabled security assessment.
Assessment source
Recommendations can be produced by built-in standards, custom standards, Azure Policy-based controls and workload-specific assessments.
Healthy state
A healthy resource currently satisfies the evaluated security condition.
Unhealthy state
An unhealthy resource does not satisfy the evaluated security condition and appears in the recommendation.
Not applicable
A not-applicable result means the assessment does not apply to the resource or its current configuration.
Unknown or unavailable state
Missing data, connector problems, unsupported configurations or incomplete assessment can prevent a definitive result.
Recommendation title
The title should identify the required security outcome rather than be treated as the complete technical explanation.
Recommendation description
The description explains the weakness, expected protection and potential security impact.
Affected resources
The affected-resources list identifies exactly which assets are currently associated with the finding.
Resource-level details
Open individual resources because the cause, ownership, exposure and remediation path can differ.
Risk level
Context-aware risk can consider potential impact, resource exposure, connections and attack-path relationships.
Severity
Severity indicates the seriousness of the security issue but should be interpreted with environmental context.
Secure Score relationship
Some recommendations contribute to Secure Score through security controls; others may not affect the score.
Recommendation category
Categories help group findings into areas such as compute, data, identity, networking, containers and application security.
Cloud environment
Recommendations can cover Azure, AWS, Google Cloud and hybrid resources when the required connectors and assessments are available.
Resource scope
Always confirm the management group, subscription, account, project, resource group and resource represented by the finding.
Assessment ID
The assessment identifier is useful for automation, Azure Resource Graph queries, APIs and technical troubleshooting.
Policy relationship
Many recommendations are connected to security policies and initiatives that define the expected configuration.
Custom recommendations
Custom standards and assessments can create organisation-specific recommendations beyond built-in controls.
Risk factors
Risk factors can include internet exposure, sensitive data, privileged access, known vulnerabilities and attack-path membership.
Attack-path relationship
Recommendations appearing in attack paths can represent steps an attacker could use to reach a valuable target.
Evidence
Evidence can include configuration values, vulnerable components, exposed endpoints or other assessment details.
Remediation guidance
Guidance describes how to correct the condition, but the implementation should follow change control and testing.
Fix option
Some recommendations provide a Fix action for supported resources; availability varies by recommendation and resource.
Manual remediation
When no automated fix exists, follow the recommended configuration steps and validate the result.
Learn more
Supporting documentation can explain prerequisites, limitations, expected impact and platform-specific procedures.
Regulatory mapping
A recommendation may map to one or more compliance standards, controls or security benchmarks.
Ownership
The team that operates the affected resource should be identified before the recommendation enters remediation.
Business context
Resource importance, data sensitivity and operational dependencies are not always visible in the recommendation.
Assessment freshness
A recommendation can remain visible until the assessment runs again and the updated state is processed.
Connector health
Broken or stale cloud connectors can produce incomplete or outdated posture information.
Agent-based assessment
Some recommendations depend on installed agents, extensions or workload telemetry.
Agentless assessment
Other recommendations can be generated from cloud configuration, APIs and agentless scanning.
Resource changes
Deletion, movement, renaming, subscription transfer or connector changes can affect how a recommendation appears.
Filtering
Use filters to narrow recommendations by environment, subscription, resource type, severity, risk, owner or status.
Sorting
Sort findings to support review, but do not assume the first item in the portal is automatically the first operational priority.
Search
Search by recommendation name, resource or technical identifier to locate a specific finding.
Export
Exported recommendation data can support reporting, ticket creation and analysis outside the portal.
Azure Resource Graph
Resource Graph queries can identify recommendation records and affected resources across large environments.
API access
Defender for Cloud and Azure APIs can support automation, reporting and integration with operational systems.
Exemptions overview
An exemption records that a recommendation or resource will not be handled through normal remediation for a defined reason.
Risk accepted
Risk accepted means the organisation knowingly accepts the exposure under approved governance.
Mitigated
Mitigated indicates that another control is believed to reduce the risk even though the recommendation remains technically unmet.
Exemption expiry
Time-limited exemptions force accepted conditions to be reviewed again.
False-positive assumption
Do not label a finding as false positive until the exact assessment logic and affected component have been checked.
Common reading error
A common mistake is reading only the recommendation title and ignoring resource-level evidence.
Another common error
Teams sometimes inspect the parent resource while the unhealthy setting exists on a child object or component.
Recommendation age
Old findings should be checked for assessment freshness, resource lifecycle and connector status.
Validation after change
After a configuration change, confirm the actual setting, service operation and updated recommendation state.
Operational workflow
A recommendation should move through review, ownership, prioritisation, remediation, validation and closure.
Governance reporting
Reports should show recommendation age, owner, affected critical resources, status, exemptions and overdue actions.
What Agent Foskett checked
Agent Foskett checked the recommendation text, affected component, assessment source, actual configuration and reassessment result.
Best practices
- Read the full recommendation description.
- Confirm the assessment source.
- Inspect affected resources individually.
- Check the exact configuration layer.
- Review risk and severity in context.
- Identify the resource owner.
- Check assessment freshness and connector health.
- Document exemptions and compensating controls.
- Validate remediation technically.
- Confirm the reassessed status before closure.
Related Agent Foskett resources
Continue learning
What are Microsoft Defender for Cloud security recommendations?
Microsoft Defender for Cloud security recommendations are actionable findings generated when cloud or hybrid resources do not satisfy enabled security assessments, standards or controls.
Understanding Security Recommendations Lesson
This Agent Foskett lesson explains recommendation anatomy, affected resources, healthy and unhealthy states, risk levels, severity, assessment sources, remediation guidance, Secure Score relationships, exemptions and validation.
