Lesson 21 — Security Recommendations
Microsoft Defender security recommendations convert vulnerability, software and configuration findings into practical actions that can reduce endpoint exposure.
Each recommendation can be reviewed alongside affected devices, related weaknesses, threat context, remediation guidance and expected impact on organisational risk.
This lesson explains how to prioritise recommendations, assign remediation work, manage exceptions and confirm that the change actually reduced exposure.

What you will learn
This lesson explains how to move from recommendation to controlled remediation and measurable risk reduction.
Learning objectives
After completing this lesson, you should be able to use security recommendations as part of a structured endpoint improvement programme.
- Explain how recommendations are generated.
- Interpret affected devices and exposure impact.
- Prioritise work using technical and business risk.
- Assign, track and govern remediation.
- Validate that exposure has reduced.
The problem this solves
Security teams often know that weaknesses exist but struggle to decide what to fix first, who owns the work and whether the change was successful.
Security recommendations connect findings to actionable remediation and provide evidence that the environment improved after the change.
What are security recommendations?
Security recommendations are prioritised improvement actions based on vulnerable software, missing updates, insecure configurations and other endpoint exposure findings.
They provide a structured path from discovery to remediation by showing affected devices, related weaknesses, implementation guidance and expected exposure reduction.
Recommendations organise the work. Analysts still need to understand the devices, owners and operational consequences behind each item.
Recommendation components
- Recommendation title and description.
- Affected software or configuration.
- Related vulnerabilities and weaknesses.
- Affected and exposed devices.
- Threat and breach insights.
- Remediation guidance and impact.
Why priorities differ
Two recommendations with similar technical severity can require very different response times.
Active exploitation, internet exposure, privileged users, critical assets and broad prevalence can all increase practical urgency.
How to prioritise recommendations
| Priority factor | Question to ask |
|---|---|
| Threat intelligence | Is the weakness actively exploited or linked to known campaigns? |
| Exposure impact | How much organisational risk could be reduced by completing the recommendation? |
| Affected devices | How many devices are affected, and are they internet-facing or highly connected? |
| Asset criticality | Does the recommendation affect identity systems, production servers or privileged workstations? |
| Operational feasibility | Can the change be deployed quickly and safely, or does it require testing and downtime? |
Affected devices
The affected-device list shows where the recommendation applies.
Review device role, operating system, ownership, criticality, exposure level and recent alert history before selecting a deployment order.
Exposure reduction
Recommendations can show the potential effect on endpoint exposure.
Use this as one decision signal, but confirm that the recommended action is relevant, supportable and aligned with business priorities.
Example recommendation assessment
Common remediation actions
- Deploy operating-system updates.
- Update or replace applications.
- Remove unsupported software.
- Change security configuration.
- Disable an unsafe feature.
- Apply a compensating control.
Business impact
Not every recommendation should be enforced immediately across every device.
Consider downtime, application compatibility, specialised systems, user impact, rollback options and required change approvals.
From recommendation to remediation
Ownership
Security teams often identify and prioritise the issue, but another team may implement the fix.
Desktop engineering, infrastructure, application owners, network teams and change management may all have a role.
Due dates and service levels
Remediation timelines should reflect practical risk.
Actively exploited weaknesses on exposed critical assets require faster service levels than low-impact findings on isolated test devices.
Exception management
| Exception requirement | What should be recorded |
|---|---|
| Reason | Why the recommendation cannot be implemented now. |
| Scope | The exact devices, software or configuration covered. |
| Compensating controls | Isolation, restricted access, monitoring or other risk reduction. |
| Owner | The person accountable for reviewing the accepted risk. |
| Review date | When the exception must be reconsidered or expire. |
Testing and deployment rings
Use representative test devices before broad deployment.
Expand through technical pilots, business pilots and production rings while monitoring application health, user impact and Defender exposure data.
Rollback planning
Security changes can affect business applications and specialised endpoints.
Document how to reverse the update or configuration change if testing reveals unacceptable impact.
How to validate completion
- Confirm the update or configuration reached the intended devices.
- Review the recommendation's affected-device count.
- Confirm related weaknesses no longer appear on remediated devices.
- Check that exposure score moved in the expected direction.
- Review failed, offline and excluded devices.
- Confirm business applications continue operating normally.
- Document evidence before closing the remediation task.
Recommendation status
A recommendation may remain visible while devices are offline, excluded or waiting for telemetry refresh.
Investigate the remaining device population rather than assuming the platform is incorrect.
Incomplete remediation
A deployment reported as successful by a management tool may still leave devices exposed.
Use Defender's observed endpoint state to confirm the actual security outcome.
Example remediation workflow
The recommendation tells you what should change. Validation proves that it actually changed.
Reporting progress
- High-risk recommendations opened and closed.
- Average remediation time.
- Overdue recommendations.
- Devices remaining exposed.
- Exceptions approaching review date.
Continuous improvement
- Review top recommendations regularly.
- Identify recurring deployment failures.
- Remove obsolete exceptions.
- Improve software ownership records.
- Use trends to guide security investment.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Treating every recommendation equally | High-risk exposed assets may wait behind low-impact work. | Prioritise using threat, exposure and business context. |
| Closing a task after approval | The actual endpoint state may remain unchanged. | Validate deployment and observed risk reduction. |
| Ignoring application owners | Changes can disrupt critical services or fail testing. | Include technical and business owners early. |
| Allowing exceptions to remain forever | Accepted risk becomes invisible and unmanaged. | Use owners, review dates and compensating controls. |
Key takeaways
- Security recommendations turn exposure findings into practical remediation actions.
- Priority should combine technical severity, threat intelligence, device exposure and business importance.
- Affected devices and operational impact must be reviewed before deployment.
- Remediation needs ownership, due dates, testing and exception governance.
- Completion must be validated through the observed endpoint state.
- Module 4 is complete when prevention, exposure and remediation work together.
Related Agent Foskett resources
Module 4 complete
Microsoft Defender Security Recommendations
Microsoft Defender security recommendations prioritise endpoint remediation using vulnerabilities, affected devices, threat intelligence, exposure impact and configuration findings.
Module 4 Endpoint Hardening — Security Recommendations Lesson 21
This Agent Foskett Defender for Endpoint Academy lesson explains recommendation priority, remediation ownership, exceptions, deployment validation and measurable exposure reduction.
