We value your privacy

We use cookies to analyze site traffic and improve your experience. You can accept all cookies or reject non-essential ones. See our Privacy Policy for details.

GR IT SERVICES
  • Contact
Get a quote
  1. Microsoft Security
  2. Defender Vulnerability Management
Microsoft Defender Vulnerability Management

Your patching process is probably fine. Now name every certificate and every browser extension in the company.

The product reaches Windows, macOS, Linux, Android, iOS, and network hardware, and it builds four inventories most companies have never attempted: software, digital certificates, hardware and firmware, and browser extensions. It then orders the findings by what attackers are exploiting this week rather than by severity score, which is a materially different list.

Book a vulnerability posture reviewSee what it inventories
Microsoft Defender Vulnerability Management for US organizations
  • Six platformsPlus network devices
  • Four inventoriesSoftware, certificates, hardware, extensions
  • CIS and STIGBaseline compliance measured
  • Off-networkAgentless scanning without a VPN
What it covers

Eight capabilities, half of them inventories almost nobody has ever built.

Microsoft positions it as asset visibility, intelligent assessment, and built-in remediation across Windows, macOS, Linux, Android, iOS, and network devices, with threat intelligence, breach likelihood predictions, and business context driving the prioritization continuously rather than at scan time.

Agentless scanning that works off the network

The built-in agentless scanners keep monitoring and detecting risk even when a device is nowhere near the corporate network. For a distributed American workforce that is not a footnote, it is the whole game, because scanning what happens to be reachable from inside an office misses most of the estate for most of the month.

A digital certificate inventory, which almost nobody has

One central list of every certificate installed anywhere in the company, flagging them before they expire and catching weak signature algorithms along the way. Expired certificates cause more self-inflicted downtime than almost anything else, and the usual defense against it is one person remembering a date. This replaces that person memory with a list.

A browser extension inventory, with permissions and risk

A list of every extension installed across every browser in the company, with the permissions each one holds and a risk level attached. Extensions run inside the browser with access to everything on screen, they get installed with no approval process whatsoever, and in most companies nobody has ever once produced a list of what is out there.

Hardware and firmware, organized so you can act on it

Known hardware and firmware listed by system model, processor, and BIOS, each showing the vendor, how many weaknesses exist, the threat context, and how many of your devices are exposed. Firmware sits beneath the operating system where practically nothing else can see it, and this is what converts that invisible risk into a number a procurement or refresh decision can rest on.

Network share assessment, which finds old mistakes

An assessment of internal file share configuration with recommendations you can act on. Shares pile up over years, permissions get widened for a project in 2021 and never narrowed again, and the eventual result is a folder every employee can read containing something that should never have been anywhere near it. This surfaces that without anybody having to go hunting.

Prioritization by what is actually being exploited

The recommendations follow what is actually being exploited right now, correlate with endpoint detection to identify anything being exploited inside your own environment during a live incident, and weight toward the machines running business-critical applications, holding confidential data, or belonging to people worth targeting. That ordering beats working down a severity list by a considerable margin.

Baseline compliance against CIS and STIG

Baseline profiles you can shape measure compliance against established benchmarks, with both the CIS benchmarks and the Security Technical Implementation Guides supported, and compliance and drift monitored continuously rather than at audit time. Where a policy document commits you to a hardening standard, or where CMMC and NIST 800-171 set configuration expectations, this is what shows whether the commitment is actually being kept.

Remediation you can actually action, including blocking

A remediation task can be created in Microsoft Intune directly from a security recommendation, vulnerable applications can be blocked for specific device groups, alternate mitigations such as configuration changes are surfaced where patching is not possible, and remediation status is tracked in real time. The blocking capability is the one that matters where a patch does not exist yet.

How this differs from an assessment or a penetration test

Three different things, and organizations frequently buy the wrong one.

Working out which of these your situation actually needs usually saves real money, so here is the distinction stated plainly.

  • An assessment is a snapshot. It produces a report of what is exposed today across whatever was in scope, with a remediation list attached. Choose it when you need an independent view, a specific answer for an auditor, or coverage of systems that are not Microsoft-managed endpoints.
  • A penetration test is a person trying to chain findings together into a genuine compromise, followed by a written account of how far they got. It answers whether your defenses survive a skilled attacker, which is an entirely different question from what is unpatched, and it is what cyber carriers, SOC 2 auditors, and enterprise customers almost always mean when they ask for testing.
  • This product runs continuously, lives inside the endpoint estate, and does several things neither of the others attempt: certificate and extension inventories, firmware assessment, baseline compliance monitoring, and prioritization informed by live exploitation. It is a program you run rather than an engagement you buy.
  • The combination that works: this product for continuous coverage of the endpoints, an assessment where you need independent breadth beyond what it can see, and a penetration test whenever somebody outside is asking whether you can be broken into. Each leaves a gap the other two fill.
Ask which of the three fits your situation
How we approach it

Four things that turn a list of vulnerabilities into fewer of them.

Everyone who switches this on receives an alarming number on the first day. What happens after that is determined entirely by how the program was designed, and not at all by the product.

We start with what attackers are using today, not with the highest score

Prioritization tracks what is being exploited right now and correlates against endpoint detection to catch anything under active exploitation inside your own environment. That ordering beats working down a severity list by a wide margin, and it is the difference between a program that reduces risk in weeks and one that grinds through a backlog indefinitely.

We start with the inventories nobody has

Certificates, extensions, and firmware. These produce concrete findings nobody argues with, many of them need no patching capacity at all to act on, and they prove the value inside a fortnight. A certificate caught six weeks before expiry has prevented an outage, and that is a far easier conversation to have with a finance director than a CVE count.

We connect remediation to how you actually deploy

A remediation task can be raised in Intune straight from a recommendation, which closes the handover gap between security finding something and IT doing something about it. Where no patch exists we block the application for specific device groups and apply whatever alternate mitigation the product surfaces, rather than leaving the item open forever with no action against it.

We tell you when an assessment or a pen test is the better buy

This covers the endpoint estate continuously and does it well. It does not substitute for an independent assessment of systems it cannot see, and it does not substitute for a penetration test when somebody is asking whether you can genuinely be broken into. You will get told which one your situation actually needs rather than whichever one this page happens to be about.

Where this matters most

Six US situations where continuous vulnerability management earns its place.

What links these is an estate too varied or too mobile for a scheduled scan of the office network to describe with any accuracy.

A distributed workforce whose laptops rarely see the office network

Network scanning sees a laptop only when it happens to be plugged in, which in a hybrid company might be twice a month. Agentless scanning that keeps monitoring a device while it sits in somebody kitchen is the only version of this that produces an accurate picture, and it is the single largest coverage improvement available to most American companies.

A regulated firm with a hardening standard to evidence

Where a policy commits you to a CIS benchmark or a STIG, baseline assessment measures whether you actually meet it and catches drift as it happens. That turns a sentence in a policy document into evidence, which is exactly what a SOC 2 audit, a CMMC assessment, an FTC Safeguards review, or an insurance questionnaire is really asking you to produce.

Hardware old enough that firmware has started to matter

The hardware and firmware assessment breaks down by system model, processor, and BIOS, showing the vendor, the weaknesses, the threat context, and how many of your machines are exposed. For a company running a long refresh cycle, that turns firmware from a vague unease into a procurement conversation with figures attached to it.

A professional services firm with certificates everywhere

Client portals, internal applications, code signing, and device certificates all accumulate, and expiry is usually discovered by an outage on a Sunday. A central inventory that identifies certificates before they lapse, and flags weak signature algorithms while it is looking, removes one of the most common causes of self-inflicted downtime there is.

A distributed retail or multi-site estate

Machines spread across many sites, little or no local IT, and equipment rarely sitting on a network anybody scans. Continuous agentless assessment, plus authenticated scanning for unmanaged Windows devices, gives you central visibility of an estate that would otherwise only be looked at when somebody drives out there.

An organization where staff install what they like in the browser

Which describes most companies, because extension installation is almost never controlled. The extension inventory, with its permission detail and risk levels, regularly produces the single most alarming finding of the entire deployment, and it is one of the few you can act on within the same week.

Three positions

What organizations actually know about their vulnerabilities.

The middle column, patching operating systems on a schedule and stopping there, describes a competently run IT function that still leaves four of the six categories below entirely untouched.
Operating systems patched on a schedule
Vulnerability managedYes
Patching onlyYes
Ad hocSometimes
Third-party software inventory maintained
Vulnerability managedYes
Patching onlyPartly
Ad hocNo
Certificate expiry known in advance
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Browser extensions inventoried
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Firmware and BIOS assessed
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Network share configuration assessed
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Baseline compliance monitored against CIS or STIG
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Priority driven by active exploitation
Vulnerability managedYes
Patching onlyNo
Ad hocNo
Devices covered while off the corporate network
Vulnerability managedYes
Patching onlyPartly
Ad hocNo
Could evidence a vulnerability program to an insurer
Vulnerability managedYes
Patching onlyPartly
Ad hocNo
Feature
Vulnerability managed
Patching only
Ad hoc
Operating systems patched on a schedule
YesYesSometimes
Third-party software inventory maintained
YesPartlyNo
Certificate expiry known in advance
YesNoNo
Browser extensions inventoried
YesNoNo
Firmware and BIOS assessed
YesNoNo
Network share configuration assessed
YesNoNo
Baseline compliance monitored against CIS or STIG
YesNoNo
Priority driven by active exploitation
YesNoNo
Devices covered while off the corporate network
YesPartlyNo
Could evidence a vulnerability program to an insurer
YesPartlyNo
The four inventories

Four inventories, and why each one ruins somebody afternoon.

Everyone anticipates the software list. It is the other three where companies discover things nobody knew existed.

Inventory

Software applications

The finding it typically produces
Versions still running that everyone believed had been retired, with the install and uninstall history behind them

Inventory

Digital certificates

The finding it typically produces
Certificates expiring soon, and certificates using weak signature algorithms

Inventory

Hardware and firmware

The finding it typically produces
BIOS and firmware carrying known weaknesses, grouped by model so a refresh decision has numbers attached

Inventory

Browser extensions

The finding it typically produces
Extensions holding permissions no approver would ever have signed off

Inventory

Network shares

The finding it typically produces
Permissions opened up for a project years ago and never closed again

Inventory

Security baselines

The finding it typically produces
How far you have drifted from the CIS or STIG standard your own policy claims you hold

Inventory

Unmanaged Windows devices

The finding it typically produces
Machines nobody was scanning, reachable through authenticated scan
InventoryThe finding it typically produces
Software applicationsVersions still running that everyone believed had been retired, with the install and uninstall history behind them
Digital certificatesCertificates expiring soon, and certificates using weak signature algorithms
Hardware and firmwareBIOS and firmware carrying known weaknesses, grouped by model so a refresh decision has numbers attached
Browser extensionsExtensions holding permissions no approver would ever have signed off
Network sharesPermissions opened up for a project years ago and never closed again
Security baselinesHow far you have drifted from the CIS or STIG standard your own policy claims you hold
Unmanaged Windows devicesMachines nobody was scanning, reachable through authenticated scan
How a deployment runs

Five steps, with a visible result in the first two weeks.

Three to six weeks typically. Switching it on is quick where Defender for Endpoint is already in place. Designing the program around it is what takes the time, and it is also what determines whether any of it works.
  1. 1

    Confirm entitlement and coverage

    We check what your licensing already includes against the tenant itself rather than assuming, then agree scope: Windows, macOS, Linux, Android, iOS, network devices, and whether authenticated scanning is needed for unmanaged Windows machines. A free trial exists where entitlement has to be established before anything else.

  2. 2

    Enable and take the inventories

    Software, certificates, hardware and firmware, and browser extensions, with the network share assessment alongside them. This is where the early findings come from, the concrete ones nobody argues about, and it goes first deliberately, because it proves the value before anyone has had to patch a single machine.

  3. 3

    Establish the baseline standard

    Baseline profiles measured against CIS or STIG benchmarks, aligned to whatever your policy genuinely commits you to rather than to a default. Then continuous monitoring of compliance and drift, which is the part that turns a one-off hardening exercise into something that remains true six months later.

  4. 4

    Connect remediation to Intune and agree the queue

    Remediation tasks raised in Intune straight from the recommendations, application blocking configured for device groups where no patch exists, and a written rule that anything under active exploitation jumps the normal queue. Without that last rule the prioritization intelligence changes absolutely nothing.

  5. 5

    Set the rhythm and track the trend

    New findings reviewed on a set rhythm, remediation progress tracked as it happens, and reporting built around the trend rather than the raw number. APIs are available where you would rather have the data in your own dashboard beside everything else.

Straight answers

What organizations ask about Defender Vulnerability Management.

Patching handles known software updates. This handles software vulnerabilities plus four categories no patching process touches at all: digital certificates, browser extensions, hardware and firmware, and file share configuration. It also measures baseline compliance against benchmarks like CIS and STIG, and orders the work by what is genuinely being exploited rather than by score.

Windows, macOS, Linux, Android, iOS, and network devices. The non-Windows coverage matters far more than most people expect, because Mac and Linux estates in American companies are patched less consistently than Windows, are frequently excluded from the main patching process entirely, and hold exploitable vulnerabilities just as readily.

Yes, and it is one of the more consequential things about it. The built-in agentless scanners keep monitoring and detecting risk while a device sits entirely outside the corporate network. For a hybrid company, network-based scanning produces a picture assembled from whichever machines happened to be plugged in when the scan ran, which is not really a picture of anything.

Every extension installed across every browser in the company, each with its permissions and a risk level attached. Extensions run inside the browser with access to whatever is on the screen, they are installed with no approval process in nearly every company, and in our experience this one inventory produces the most immediately alarming finding of the entire deployment.

Two reasons. First expiry, because a lapsed certificate is one of the most common causes of self-inflicted downtime and the usual control against it is one person remembering a date. Second weak signature algorithms, which the assessment detects, because certificates issued years ago against standards that were fine then are frequently still in service now. A central inventory is what turns both from a Sunday surprise into a scheduled task.

It lists known hardware and firmware by system model, processor, and BIOS, showing the vendor, the number of weaknesses, the threat context, and how many of your devices are exposed to each. It will not patch firmware for you. What it does is make firmware risk visible and countable, which is what lets a refresh or update decision rest on evidence rather than on a general feeling that the machines are getting old.

Three things drive it. Recommendations track vulnerabilities under active exploitation and emerging threats carrying the highest risk. Vulnerability data is correlated against endpoint detection to identify anything being exploited during a live incident inside your own environment. And the weighting favors exposed devices running business-critical applications, holding confidential data, or belonging to people worth targeting.

Two routes, both supported. The vulnerable application can be blocked for specific device groups, which is the strongest response available when no fix exists anywhere. And the product surfaces alternate mitigations, typically configuration changes that reduce the risk without removing the software. Between them, an unpatchable finding no longer has to sit open forever with nothing recorded against it.

A remediation task can be created in Intune directly from a specific recommendation, and this is the integration that matters more than any other, because it closes the handover gap between somebody finding a problem and somebody else fixing it. Status and progress are then visible continuously, so the security team can see what actually happened instead of sending an email asking.

No, and anyone who tells you otherwise is selling you something. A penetration test is a person chaining findings into a real compromise and writing up how far they got. This tells you what is exposed. Those are genuinely different questions, and when a cyber carrier, a SOC 2 auditor, or an enterprise customer asks for testing, they nearly always mean the penetration test.

You build baseline profiles measuring compliance against established benchmarks, with both the CIS benchmarks and the Security Technical Implementation Guides supported. Compliance and any change to it are monitored continuously. Where your security policy commits to a hardening standard, or a CMMC or NIST 800-171 program expects configuration discipline, this is what tells you whether the commitment is genuinely being met, which is usually a far more useful question than how many CVEs are open.

Entitlement gets confirmed against your actual tenant rather than asserted on a web page, because it varies by subscription and by add-on. A free trial exists, which means finding out what you have and seeing what it turns up does not require a purchase decision first. Where Defender for Endpoint is already deployed, a portion of this capability is frequently sitting there unused already. Commercially we scope per engagement, driven by estate size, which platforms are in scope, and whether you want the remediation program run continuously or built and handed over. What costs nothing is the first conversation, in which you find out whether your licensing already covers this and whether an independent assessment would be a better use of the same money.
Before deploying

Fifteen questions worth answering first.

The first set is about coverage. The second is about what you would actually find. The third is about whether anything gets fixed, which is where most vulnerability programs quietly die.

Coverage

  • Is Defender for Endpoint already deployed?
    This builds on the same estate.
  • Do you have macOS or Linux in scope?
    Both are in scope, and both are almost always further behind than Windows.
  • Are mobile devices included?
    Android and iOS are covered.
  • Are there unmanaged Windows devices?
    Authenticated scan reaches them with credentials.
  • Do you have network devices to assess?
    They are in the stated coverage.

What you would find

  • Do you have a certificate inventory today?
    Almost nobody does, and expiry causes outages.
  • Do you know what browser extensions are installed?
    They run with access to everything the user sees.
  • Have you ever assessed firmware and BIOS versions?
    Invisible to most other tooling.
  • When were network share permissions last reviewed?
    The answer is usually never.
  • Does your policy claim CIS or STIG compliance?
    Baseline assessment shows whether it is true.

Would anything be fixed

  • Who owns patching, and do they have capacity?
    Findings without a fixer are a report.
  • Do you use Intune for deployment?
    Remediation tasks can be created directly in it.
  • Can you block an application if no patch exists?
    Supported per device group.
  • Is there a maintenance window that actually happens?
    The most common real constraint.
  • Would exploited-in-the-wild items jump the queue?
    That is what the prioritization is for.
Related reading

The pages around this one.

Cybersecurity audit and compliance

The point-in-time, independent assessment across systems this product cannot see, and the evidence pack it produces.

Learn more

Defender for Endpoint

The endpoint platform underneath this, with the plan comparison and what each tier genuinely provides.

Learn more

Microsoft Intune

Where the remediation tasks land: device management, patching and the deployment pipeline that closes findings.

Learn more
Next step

Ask for a list of every certificate in your organization and see who can produce one.

That question, and its equivalent about browser extensions, establishes the gap faster than any vulnerability count ever will. Both inventories arrive inside the first two weeks of a deployment, and neither one requires anybody to patch a single machine.

Book a vulnerability posture reviewSee the Microsoft security stack

Related Services

Explore more solutions that work great with this service

Microsoft Defender for Endpoint Services

EDR plan selection, onboarding and zero-gap AV migration

Learn more

Microsoft Intune

Device management and endpoint security

Learn more

Microsoft Security Services

The Microsoft security stack deployed and managed end to end

Learn more

Microsoft Defender XDR Services

One incident queue across endpoint, email and identity

Learn more

Microsoft Defender for Servers

Defender for Servers engagements for US organizations: estate

Learn more
GR IT SERVICES

IT services for US businesses,
delivering enterprise-grade solutions
remotely, coast to coast.

Microsoft CSP PartnerApple Jamf PartnerCISGuard

Microsoft 365

  • Microsoft 365 Administration
  • M365 Reporting & Auditing
  • Microsoft 365 Licensing
  • Microsoft Copilot
  • Microsoft 365 Apps
  • Windows 365 Cloud PC
  • Microsoft SharePoint
  • Outlook & Exchange

Security

  • Microsoft Defender
  • Microsoft Purview
  • Microsoft Intune
  • Microsoft Entra
  • Compliance Manager
  • Cybersecurity Audits
  • Copilot for Security
  • Microsoft Sentinel
  • Microsoft Priva

Infrastructure

  • Google Workspace
  • Cloud Migration Services
  • Data Analytics & BI
  • Active Directory
  • Server Management
  • Apple Business
  • Apple Jamf Pro
  • IP Telephone
  • Data Backup
  • Website Development

IT Services

  • Managed IT Services
  • IT Support USA
  • IT AMC USA
  • New Office IT Setup
  • IT Relocation
  • Remote IT Support
  • On-Call IT Support
  • Startup IT Business Kit
  • Disaster Recovery & BC

Company

  • About Us
  • Careers
  • Contact
  • Blog

Contact

  • hello@gritservices.io
  • gritservices.io

© 2026 GR IT Services. All rights reserved.

Privacy PolicyTerms of UseCookie PolicyCCPA/CPRA