Edit

Exceptions in Microsoft Defender Vulnerability Management

Note

The Vulnerability Management section in the Microsoft Defender portal is now located under Exposure management. With this change, you can now consume and manage security exposure data and vulnerability data in a unified location, to enhance your existing Vulnerability Management features. Learn more.

These changes are relevant for Preview customers (Microsoft Defender XDR + Microsoft Defender for Identity preview option).

Important

Some information in this article relates to a prereleased product which may be substantially modified before it's commercially released. Microsoft makes no warranties, expressed or implied, with respect to the information provided here.

Microsoft Defender Vulnerability Management lets you create exceptions to exclude specific data from your remediation efforts. Use exceptions to filter out data that isn't relevant to your organization.

Exceptions help you get more accurate risk reports. They also improve priority rankings when you have other mitigations, accepted risk, or a remediation plan in place.

This article describes how to create, view, and manage Defender Vulnerability Management exceptions.

Tip

Did you know you can try all the features in Microsoft Defender Vulnerability Management for free? Find out how to sign up for a free trial.

Types of exceptions

Microsoft Defender Vulnerability Management supports two types of exceptions:

  • Security recommendation exceptions: Exclude specific security recommendations from analysis. You create this exception at the recommendation level. It applies to all Common Vulnerabilities and Exposures (CVEs) linked to that recommendation.

    Screenshot highlighting Exception options in a Recommendation pane.

  • CVE exceptions: Exclude specific Common Vulnerabilities and Exposures (CVEs) from analysis. You create a CVE exception from the Weaknesses page for a specific CVE.

    Screenshot showing how to create a CVE exception.

Exception by device group

You can apply an exception to all current device groups or to specific device groups. Future device groups aren't included in the exception. Device groups that already have an exception aren't displayed in the list.

After you create the exception:

  • For recommendation exceptions, if you select specific device groups, the recommendation state changes from active to partial exception. The state changes to full exception if you select all the device groups.
  • For CVE exceptions, the CVE no longer appears in the inventory lists for the selected scope.

Screenshot of the exception settings with the device group dropdown used to scope the exception to specific device groups.

Global exceptions

If you have Security Administrator permission or a custom role that includes the exceptions handling permission, you can create and cancel a global exception. This exception affects all current and future device groups in your organization, and only users with similar permissions can change the global exception.

Important

While the Global Administrator permission also allows you to create and cancel global exceptions, Microsoft recommends that you use roles with the fewest permissions. Using lower accounts with lower permissions helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.

After you create the exception:

  • For recommendation exceptions, the recommendation state changes from active to full exception.
  • For CVE exceptions, the CVE no longer appears in the inventory lists for the entire organization.

Screenshot of the exception settings with the option to apply the exception globally to all device groups.

Some things to keep in mind:

  • If a recommendation is under global exception, newly created exceptions for device groups are suspended until the global exception has expired or been canceled. After the global exception expires or is canceled, the new device group exceptions go into effect until they expire.
  • If a recommendation already has exceptions for specific device groups and a global exception is created, then the device group exception is suspended until it expires or the global exception is canceled before it expires.
  • While global exceptions affect the overall exposure and impact, the Recommendations page doesn't show recommendations to which global exceptions are applied.

Justification options for exceptions

The following justifications are available for exceptions:

  • Third party control: A third party product or software already addresses this recommendation.
  • Alternate mitigation: An internal tool already addresses this recommendation.
  • Risk accepted: Poses low risk and/or implementing the recommendation is too expensive.
  • Planned remediation (grace): Already planned but is awaiting execution or authorization.
  • CVE with no patch (CVE exceptions only): No patch is available from the vendor.
  • False positive (CVE exceptions only): The CVE doesn't apply to your environment.

Exposed devices and impact after exceptions

Exceptions change the exposed device counts and impact values shown in the portal. The tabs below describe how recommendation exceptions and CVE exceptions each affect these values.

To view exposure and impact data for recommendation exceptions, go to the Recommendations page. Select the Exposed devices (after exceptions) and Impact (after exceptions) columns.

Screenshot of the Recommendations page with the Exposed devices (after exceptions) and Impact (after exceptions) columns selected.

The following table describes how exceptions impact what you see in the Microsoft Defender portal.

Important

While both device group and global exceptions affect the overall exposure and impact, the Recommendations > Misconfigurations page doesn't show recommendations to which global exceptions are applied.

Area Location in UI Description
Exposed devices (after exceptions) and Impact (after exceptions) columns Recommendations page > recommendations list When you apply an exception, these columns reflect the remaining devices and impact after the exception scope is applied.
Exposed devices column Recommendations page > recommendations list This column might still display the total exposed devices (before the exception) even when an exception exists. Use Exposed devices (after exceptions) and Impact (after exceptions) to understand your scoped exposure.
Device inventory > Security recommendations tab Device inventory > device page > Security Recommendations tab. By default, this tab only displays recommendations that aren't excluded for that specific device. To view recommendations that are currently excluded, use the Status filter.
Recommendations flyout pane Select a recommendation to open the flyout pane The Exposed devices field under Details and the list of devices in the Exposed devices tab reflect the total exposed devices before the exception is applied (devices not related to the exception).
Impact column Recommendations page > recommendations list Only specific justifications reduce the score impact (for example, Third party control and Alternate mitigation). Other justifications might not affect the exposure score and the secure score.