Your patching process is probably fine. Now name every certificate and every browser extension in the company.
The product reaches Windows, macOS, Linux, Android, iOS, and network hardware, and it builds four inventories most companies have never attempted: software, digital certificates, hardware and firmware, and browser extensions. It then orders the findings by what attackers are exploiting this week rather than by severity score, which is a materially different list.

- Six platformsPlus network devices
- Four inventoriesSoftware, certificates, hardware, extensions
- CIS and STIGBaseline compliance measured
- Off-networkAgentless scanning without a VPN
Eight capabilities, half of them inventories almost nobody has ever built.
Agentless scanning that works off the network
The built-in agentless scanners keep monitoring and detecting risk even when a device is nowhere near the corporate network. For a distributed American workforce that is not a footnote, it is the whole game, because scanning what happens to be reachable from inside an office misses most of the estate for most of the month.
A digital certificate inventory, which almost nobody has
One central list of every certificate installed anywhere in the company, flagging them before they expire and catching weak signature algorithms along the way. Expired certificates cause more self-inflicted downtime than almost anything else, and the usual defense against it is one person remembering a date. This replaces that person memory with a list.
A browser extension inventory, with permissions and risk
A list of every extension installed across every browser in the company, with the permissions each one holds and a risk level attached. Extensions run inside the browser with access to everything on screen, they get installed with no approval process whatsoever, and in most companies nobody has ever once produced a list of what is out there.
Hardware and firmware, organized so you can act on it
Known hardware and firmware listed by system model, processor, and BIOS, each showing the vendor, how many weaknesses exist, the threat context, and how many of your devices are exposed. Firmware sits beneath the operating system where practically nothing else can see it, and this is what converts that invisible risk into a number a procurement or refresh decision can rest on.
Network share assessment, which finds old mistakes
An assessment of internal file share configuration with recommendations you can act on. Shares pile up over years, permissions get widened for a project in 2021 and never narrowed again, and the eventual result is a folder every employee can read containing something that should never have been anywhere near it. This surfaces that without anybody having to go hunting.
Prioritization by what is actually being exploited
The recommendations follow what is actually being exploited right now, correlate with endpoint detection to identify anything being exploited inside your own environment during a live incident, and weight toward the machines running business-critical applications, holding confidential data, or belonging to people worth targeting. That ordering beats working down a severity list by a considerable margin.
Baseline compliance against CIS and STIG
Baseline profiles you can shape measure compliance against established benchmarks, with both the CIS benchmarks and the Security Technical Implementation Guides supported, and compliance and drift monitored continuously rather than at audit time. Where a policy document commits you to a hardening standard, or where CMMC and NIST 800-171 set configuration expectations, this is what shows whether the commitment is actually being kept.
Remediation you can actually action, including blocking
A remediation task can be created in Microsoft Intune directly from a security recommendation, vulnerable applications can be blocked for specific device groups, alternate mitigations such as configuration changes are surfaced where patching is not possible, and remediation status is tracked in real time. The blocking capability is the one that matters where a patch does not exist yet.
Three different things, and organizations frequently buy the wrong one.
Working out which of these your situation actually needs usually saves real money, so here is the distinction stated plainly.
- An assessment is a snapshot. It produces a report of what is exposed today across whatever was in scope, with a remediation list attached. Choose it when you need an independent view, a specific answer for an auditor, or coverage of systems that are not Microsoft-managed endpoints.
- A penetration test is a person trying to chain findings together into a genuine compromise, followed by a written account of how far they got. It answers whether your defenses survive a skilled attacker, which is an entirely different question from what is unpatched, and it is what cyber carriers, SOC 2 auditors, and enterprise customers almost always mean when they ask for testing.
- This product runs continuously, lives inside the endpoint estate, and does several things neither of the others attempt: certificate and extension inventories, firmware assessment, baseline compliance monitoring, and prioritization informed by live exploitation. It is a program you run rather than an engagement you buy.
- The combination that works: this product for continuous coverage of the endpoints, an assessment where you need independent breadth beyond what it can see, and a penetration test whenever somebody outside is asking whether you can be broken into. Each leaves a gap the other two fill.
Four things that turn a list of vulnerabilities into fewer of them.
We start with what attackers are using today, not with the highest score
Prioritization tracks what is being exploited right now and correlates against endpoint detection to catch anything under active exploitation inside your own environment. That ordering beats working down a severity list by a wide margin, and it is the difference between a program that reduces risk in weeks and one that grinds through a backlog indefinitely.
We start with the inventories nobody has
Certificates, extensions, and firmware. These produce concrete findings nobody argues with, many of them need no patching capacity at all to act on, and they prove the value inside a fortnight. A certificate caught six weeks before expiry has prevented an outage, and that is a far easier conversation to have with a finance director than a CVE count.
We connect remediation to how you actually deploy
A remediation task can be raised in Intune straight from a recommendation, which closes the handover gap between security finding something and IT doing something about it. Where no patch exists we block the application for specific device groups and apply whatever alternate mitigation the product surfaces, rather than leaving the item open forever with no action against it.
We tell you when an assessment or a pen test is the better buy
This covers the endpoint estate continuously and does it well. It does not substitute for an independent assessment of systems it cannot see, and it does not substitute for a penetration test when somebody is asking whether you can genuinely be broken into. You will get told which one your situation actually needs rather than whichever one this page happens to be about.
Six US situations where continuous vulnerability management earns its place.
A distributed workforce whose laptops rarely see the office network
Network scanning sees a laptop only when it happens to be plugged in, which in a hybrid company might be twice a month. Agentless scanning that keeps monitoring a device while it sits in somebody kitchen is the only version of this that produces an accurate picture, and it is the single largest coverage improvement available to most American companies.
A regulated firm with a hardening standard to evidence
Where a policy commits you to a CIS benchmark or a STIG, baseline assessment measures whether you actually meet it and catches drift as it happens. That turns a sentence in a policy document into evidence, which is exactly what a SOC 2 audit, a CMMC assessment, an FTC Safeguards review, or an insurance questionnaire is really asking you to produce.
Hardware old enough that firmware has started to matter
The hardware and firmware assessment breaks down by system model, processor, and BIOS, showing the vendor, the weaknesses, the threat context, and how many of your machines are exposed. For a company running a long refresh cycle, that turns firmware from a vague unease into a procurement conversation with figures attached to it.
A professional services firm with certificates everywhere
Client portals, internal applications, code signing, and device certificates all accumulate, and expiry is usually discovered by an outage on a Sunday. A central inventory that identifies certificates before they lapse, and flags weak signature algorithms while it is looking, removes one of the most common causes of self-inflicted downtime there is.
A distributed retail or multi-site estate
Machines spread across many sites, little or no local IT, and equipment rarely sitting on a network anybody scans. Continuous agentless assessment, plus authenticated scanning for unmanaged Windows devices, gives you central visibility of an estate that would otherwise only be looked at when somebody drives out there.
An organization where staff install what they like in the browser
Which describes most companies, because extension installation is almost never controlled. The extension inventory, with its permission detail and risk levels, regularly produces the single most alarming finding of the entire deployment, and it is one of the few you can act on within the same week.
What organizations actually know about their vulnerabilities.
| Feature | Vulnerability managed | Patching only | Ad hoc |
|---|---|---|---|
Operating systems patched on a schedule | Yes | Yes | Sometimes |
Third-party software inventory maintained | Yes | Partly | No |
Certificate expiry known in advance | Yes | No | No |
Browser extensions inventoried | Yes | No | No |
Firmware and BIOS assessed | Yes | No | No |
Network share configuration assessed | Yes | No | No |
Baseline compliance monitored against CIS or STIG | Yes | No | No |
Priority driven by active exploitation | Yes | No | No |
Devices covered while off the corporate network | Yes | Partly | No |
Could evidence a vulnerability program to an insurer | Yes | Partly | No |
Four inventories, and why each one ruins somebody afternoon.
Inventory
Software applications
- The finding it typically produces
- Versions still running that everyone believed had been retired, with the install and uninstall history behind them
Inventory
Digital certificates
- The finding it typically produces
- Certificates expiring soon, and certificates using weak signature algorithms
Inventory
Hardware and firmware
- The finding it typically produces
- BIOS and firmware carrying known weaknesses, grouped by model so a refresh decision has numbers attached
Inventory
Browser extensions
- The finding it typically produces
- Extensions holding permissions no approver would ever have signed off
Inventory
Network shares
- The finding it typically produces
- Permissions opened up for a project years ago and never closed again
Inventory
Security baselines
- The finding it typically produces
- How far you have drifted from the CIS or STIG standard your own policy claims you hold
Inventory
Unmanaged Windows devices
- The finding it typically produces
- Machines nobody was scanning, reachable through authenticated scan
Five steps, with a visible result in the first two weeks.
- 1
Confirm entitlement and coverage
We check what your licensing already includes against the tenant itself rather than assuming, then agree scope: Windows, macOS, Linux, Android, iOS, network devices, and whether authenticated scanning is needed for unmanaged Windows machines. A free trial exists where entitlement has to be established before anything else.
- 2
Enable and take the inventories
Software, certificates, hardware and firmware, and browser extensions, with the network share assessment alongside them. This is where the early findings come from, the concrete ones nobody argues about, and it goes first deliberately, because it proves the value before anyone has had to patch a single machine.
- 3
Establish the baseline standard
Baseline profiles measured against CIS or STIG benchmarks, aligned to whatever your policy genuinely commits you to rather than to a default. Then continuous monitoring of compliance and drift, which is the part that turns a one-off hardening exercise into something that remains true six months later.
- 4
Connect remediation to Intune and agree the queue
Remediation tasks raised in Intune straight from the recommendations, application blocking configured for device groups where no patch exists, and a written rule that anything under active exploitation jumps the normal queue. Without that last rule the prioritization intelligence changes absolutely nothing.
- 5
Set the rhythm and track the trend
New findings reviewed on a set rhythm, remediation progress tracked as it happens, and reporting built around the trend rather than the raw number. APIs are available where you would rather have the data in your own dashboard beside everything else.
What organizations ask about Defender Vulnerability Management.
Fifteen questions worth answering first.
Coverage
- Is Defender for Endpoint already deployed?This builds on the same estate.
- Do you have macOS or Linux in scope?Both are in scope, and both are almost always further behind than Windows.
- Are mobile devices included?Android and iOS are covered.
- Are there unmanaged Windows devices?Authenticated scan reaches them with credentials.
- Do you have network devices to assess?They are in the stated coverage.
What you would find
- Do you have a certificate inventory today?Almost nobody does, and expiry causes outages.
- Do you know what browser extensions are installed?They run with access to everything the user sees.
- Have you ever assessed firmware and BIOS versions?Invisible to most other tooling.
- When were network share permissions last reviewed?The answer is usually never.
- Does your policy claim CIS or STIG compliance?Baseline assessment shows whether it is true.
Would anything be fixed
- Who owns patching, and do they have capacity?Findings without a fixer are a report.
- Do you use Intune for deployment?Remediation tasks can be created directly in it.
- Can you block an application if no patch exists?Supported per device group.
- Is there a maintenance window that actually happens?The most common real constraint.
- Would exploited-in-the-wild items jump the queue?That is what the prioritization is for.
The pages around this one.
Cybersecurity audit and compliance
The point-in-time, independent assessment across systems this product cannot see, and the evidence pack it produces.
Defender for Endpoint
The endpoint platform underneath this, with the plan comparison and what each tier genuinely provides.
Microsoft Intune
Where the remediation tasks land: device management, patching and the deployment pipeline that closes findings.
Ask for a list of every certificate in your organization and see who can produce one.
That question, and its equivalent about browser extensions, establishes the gap faster than any vulnerability count ever will. Both inventories arrive inside the first two weeks of a deployment, and neither one requires anybody to patch a single machine.
Related Services
Explore more solutions that work great with this service
Microsoft Defender for Endpoint Services
EDR plan selection, onboarding and zero-gap AV migration
Learn moreMicrosoft Intune
Device management and endpoint security
Learn moreMicrosoft Security Services
The Microsoft security stack deployed and managed end to end
Learn moreMicrosoft Defender XDR Services
One incident queue across endpoint, email and identity
Learn moreMicrosoft Defender for Servers
Defender for Servers engagements for US organizations: estate
Learn more