Lesson 20 — Threat and Vulnerability Management
Microsoft Defender Vulnerability Management provides continuous visibility into vulnerable software, exposed devices, weaknesses and remediation priorities across the endpoint environment.
Rather than treating every CVE as equally urgent, the platform combines technical severity with threat insights, device exposure, affected assets and organisational context.
This lesson explains how to interpret the exposure score, investigate vulnerable software, review weaknesses and turn vulnerability data into practical remediation work.

What you will learn
This lesson explains how vulnerability data becomes a prioritised endpoint remediation programme.
Learning objectives
After completing this lesson, you should be able to interpret and act on Microsoft Defender Vulnerability Management data.
- Explain the purpose of Defender Vulnerability Management.
- Interpret endpoint exposure score and device exposure.
- Investigate vulnerable software and CVEs.
- Prioritise remediation using threat and business context.
- Track and validate remediation activity.
The problem this solves
Traditional vulnerability reports can produce thousands of findings without showing which ones present the greatest immediate risk.
Defender Vulnerability Management connects weaknesses to real devices, installed software, active threats and exposure so teams can focus on the remediation that reduces risk most effectively.
What is Microsoft Defender Vulnerability Management?
Microsoft Defender Vulnerability Management continuously discovers software, identifies known weaknesses, assesses configuration risk and helps security teams prioritise remediation.
In the Microsoft Defender portal, vulnerability information is available under Exposure management and includes overview insights, software inventory, vulnerabilities, recommendations, remediation activities and exposed devices.
A vulnerability becomes more urgent when it is exploitable, present on important devices and connected to active threat intelligence.
Exposure score
The endpoint exposure score reflects how vulnerable the organisation's devices are to cybersecurity threats.
A lower exposure score indicates less vulnerability. The score helps teams measure risk reduction over time and communicate the effect of remediation work.
Exposure score is not a grade
The score is a prioritisation and trend indicator, not a complete statement that the environment is safe or unsafe.
Review the findings behind the score, affected assets and threat context rather than focusing only on the number.
Exposure score compared with Secure Score
| Measure | Primary focus | Interpretation |
|---|---|---|
| Endpoint exposure score | How vulnerable endpoints are based on weaknesses, software and exposure. | Lower is better because it represents reduced vulnerability. |
| Microsoft Secure Score | Progress against recommended security configurations and controls. | Higher generally indicates more recommended controls have been implemented. |
Software inventory
The software inventory lists software discovered across the network and includes vendor, version, weaknesses, associated threats, exposed devices and impact on exposure.
This shows where vulnerable software exists and how widely it is deployed.
Why inventory accuracy matters
Vulnerability management depends on knowing which software and versions are actually present.
Unsupported applications, duplicate versions, abandoned software and unmanaged devices can all increase exposure.
Investigating vulnerable software
- Open the software inventory.
- Identify software with significant weaknesses or threat insights.
- Review affected versions and exposed devices.
- Check whether the software is business-critical.
- Review available updates or mitigations.
- Assess the expected effect on exposure score.
- Create or assign remediation work.
- Validate that affected device counts decrease.
Vulnerabilities and CVEs
The Vulnerabilities page lists CVEs affecting devices in the organisation.
Analysts can review severity, CVSS information, affected software, exposed devices, breach insights and threat intelligence.
CVSS is only one signal
A high CVSS score can indicate serious technical impact, but it does not automatically make that CVE the highest priority.
Exploit availability, active exploitation, device criticality, internet exposure and prevalence change the practical risk.
Threat-informed prioritisation
| Factor | Why it matters |
|---|---|
| Active exploitation | A vulnerability being exploited in the wild may require immediate action. |
| Exploit availability | Public exploit code can lower the barrier for attackers. |
| Device criticality | A weakness on a domain controller, privileged workstation or production server carries greater business risk. |
| Exposure | Internet-facing or highly connected devices can be easier to target. |
| Prevalence | A vulnerability affecting many devices creates broad organisational risk. |
| Available mitigation | A practical update, configuration change or workaround can accelerate risk reduction. |
Device exposure level
Device exposure helps identify endpoints with a greater concentration of vulnerabilities, weak configurations or security risk.
High-exposure devices should be reviewed alongside business importance, internet reachability, user privilege and active incidents.
Critical assets
Not every device has equal business value.
Production servers, identity systems, privileged workstations and operational assets should receive additional prioritisation.
Security recommendations
Security recommendations translate vulnerability and configuration findings into practical improvement actions.
Recommendations can include affected devices, expected exposure reduction, related weaknesses, threat context and remediation guidance.
Remediation activities
Remediation activities help track work from identification through implementation and validation.
Tasks should have an owner, due date, affected device scope, deployment method and exception path.
Exceptions
An exception does not remove the underlying vulnerability.
It records an approved decision to defer or accept the risk and should include justification, scope, owner, review date and compensating controls.
Recommended remediation workflow
Vulnerability management is complete only when the change is deployed and the platform confirms that exposure has reduced.
Patch testing
Urgency does not remove the need for safe deployment.
Use test devices, pilot rings, rollback procedures and application validation, especially for critical servers and specialised systems.
When no patch exists
Some weaknesses require temporary mitigation.
Options may include disabling a feature, restricting network access, isolating systems, applying ASR rules or increasing monitoring.
Example prioritisation decision
| Finding | Initial severity | Practical priority |
|---|---|---|
| Critical CVE on one isolated laboratory device | Critical | Important, but may follow immediate exposed risks. |
| High-severity actively exploited CVE on 120 internet-connected devices | High | Immediate priority because exploitation, exposure and prevalence combine. |
| Medium weakness on a privileged identity server | Medium | May be elevated because the affected asset is critical. |
Advanced Hunting support
Advanced Hunting tables can help investigate software inventory, vulnerabilities and device risk at scale.
Use hunting to identify affected device groups, correlate vulnerability data with incidents and verify whether exposed systems show suspicious activity.
Vulnerability does not equal compromise
A vulnerable device has a weakness that could be exploited.
It does not automatically mean exploitation occurred. Use alerts, timeline activity, hunting and identity evidence to investigate compromise.
Example investigation workflow
The dashboard identifies the weakness. The analyst determines which devices create the real risk.
Measure outcomes
- Reduced exposed-device count.
- Lower endpoint exposure score.
- Fewer unsupported software versions.
- Closed remediation activities.
- Reduced time to remediate high-risk findings.
Ongoing programme
- Review top vulnerable software regularly.
- Track newly exploited vulnerabilities.
- Monitor exceptions and overdue remediation.
- Remove unused and unsupported software.
- Report risk trends to technical and business owners.
Common mistakes
| Mistake | Why it creates risk | Better practice |
|---|---|---|
| Prioritising only by CVSS | Active exploitation, exposure and device criticality are ignored. | Use severity together with threat and business context. |
| Closing work when a patch is approved | The update may not have reached all affected devices. | Validate deployment and confirm exposed-device counts decrease. |
| Ignoring unsupported software | Unsupported products may remain permanently vulnerable. | Remove, replace or isolate software that cannot be secured. |
| Using permanent exceptions | Accepted risks can remain forgotten while conditions change. | Assign owners, review dates and compensating controls. |
Key takeaways
- Defender Vulnerability Management continuously discovers and assesses endpoint weaknesses.
- The endpoint exposure score helps measure organisational vulnerability; lower is better.
- Software inventory links vulnerable versions to real devices and threats.
- CVSS should be combined with exploitation, exposure, prevalence and asset criticality.
- Recommendations must become assigned, tracked and validated remediation work.
- Success is measured by reduced exposure, not by the number of reports produced.
Related Agent Foskett resources
Continue learning
Microsoft Defender Vulnerability Management
Microsoft Defender Vulnerability Management discovers vulnerable software, known CVEs, exposed devices and security weaknesses, then combines threat and exposure context to support risk-based remediation.
Module 4 Endpoint Hardening — Threat and Vulnerability Management Lesson 20
This Agent Foskett Defender for Endpoint Academy lesson explains endpoint exposure score, software inventory, vulnerabilities, recommendations, remediation activities and validation.
