Microsoft Defender Vulnerability Management shows the security team which devices are exposed and why; Microsoft Intune is usually the tool that fixes them. The bridge between the two is the remediation request, which lands in the Intune admin center as a security task. In this post I'll walk through what the vulnerability management pages give you, what the licence tiers include, and the full loop from a security recommendation to a closed Intune task.
Prerequisites#
- Licensing. Defender for Endpoint Plan 2 includes the core vulnerability management capabilities: device discovery and inventory, vulnerability and configuration assessment, risk-based prioritisation, remediation tracking, continuous monitoring, software inventory and software usage insights. The Defender Vulnerability Management add-on for Plan 2 adds the premium set: security baselines assessment, blocking vulnerable applications, browser extension assessment, digital certificate assessment, network share analysis, and hardware and firmware assessment. The standalone plan gives the full feature set to organisations on Plan 1, Microsoft 365 E3 or another EDR. Microsoft notes it isn't available to Defender for Business customers, and that servers get the premium features through Defender for Servers Plan 2.
- Intune Plan 1, with devices enrolled in Intune and onboarded to Defender for Endpoint.
- The connector, in both directions. In the Microsoft Intune admin center, Tenant administration › Connectors and tokens › Microsoft Defender for Endpoint must show the connection as enabled. In the Microsoft Defender portal, Settings › Endpoints › General › Advanced features › Microsoft Intune connection must be On. Without it, the option to open an Intune ticket simply doesn't appear in the remediation request form.
- Permissions. Security admins need the Defender for Endpoint permissions for remediation handling (and exception handling if they'll create exceptions); the Intune admin needs a role that can manage security tasks, such as Endpoint Security Manager.
How the pieces fit together#
In the Defender portal the pages live under Endpoints › Vulnerability management. Tenants in the Defender XDR and Defender for Identity preview see the same data under Exposure management instead.
- Dashboard. The exposure score reflects the vulnerabilities found on your devices, how likely they are to be breached, how valuable they are and related alerts; lower is better. Microsoft Secure Score for Devices measures the configuration side, so misconfiguration recommendations move this score rather than the exposure score. Devices inactive for 30 days are left out of both.
- Recommendations. The prioritised to-do list. Each entry shows exposed devices, the score impact, the remediation type and whether a public exploit exists.
- Inventories. The software inventory tells you which products and versions exist across the estate and which carry weaknesses. Certificates, browser extensions and firmware appear here with the premium plan.
- Weaknesses. The CVE view: every vulnerability, its severity, exploitability and exposed device count. CVEs Microsoft marks as "won't fix" aren't shown or scored.
- Remediation. Where requests are tracked, with an Exceptions tab for everything you've decided not to fix for now.
Step-by-step: from recommendation to closed task#
Step 1: Request remediation (security admin)#
Open Recommendations, select a recommendation and choose Request remediation in the flyout. The form asks what you're requesting (for example a software update), whether to open a ticket in Intune, a priority, a due date and optional notes. Select Next, review, then Submit. Two details matter: the attention required option creates a note rather than a trackable action, so it has no due date or progress bar; and a single request covers at most 10,000 devices, so very large recommendations need splitting by device group. Submitting changes nothing on devices yet; it creates a remediation activity in Defender and a Pending security task in Intune.
Step 2: Review the task (Intune admin)#
In the Intune admin center, go to Endpoint security › Security tasks (the tasks also surface in the Admin tasks pane). Open a task to see the remediation type, priority, status and the steps Defender recommends. DEVICES lists the vulnerable devices, MANAGED APPS shows affected Intune apps, REQUESTOR lets you email the security admin, and NOTES shows their comments. Select Accept or Reject; either way you can add a note that flows back to the Defender portal and updates the status on both sides.
Step 3: Remediate with Intune#
| Remediation type | Typical Intune action |
|---|---|
| Application (managed app) | Update or supersede the Win32, Store or Enterprise App Catalog app; Intune links you straight to it. |
| Application (unmanaged app) | Intune can only give text instructions. Package the update yourself, or block the app if the vendor has no fix. |
| Configuration | Deploy or adjust an endpoint security policy, for example PUA protection in a Microsoft Defender Antivirus profile, or change a registry value. |
| Operating system update | Use update rings, quality update policies or an expedite policy to ship the fix faster. |
If Intune can't implement a suitable fix, Defender doesn't create a task at all; the request shows as requiring attention instead.
Step 4: Close the loop#
When the fix is deployed, reopen the task and select Complete Task. The status changes in Intune and on the Defender Remediation page, where the security admin watches the exposed device count fall as devices report the new version or setting.
Step 5: Handle what you won't fix with an exception#
For a recommendation that can't or shouldn't be remediated now, open it and select Exception options. Pick a justification and a duration, scope it globally or to specific device groups, and select Confirm and apply. The recommendation moves to Full exception or Partial exception, related alerts and threat analytics are suppressed, and within about an hour the exposed device count and exposure score reflect it. Durations can't be extended; when one expires you create a new exception. The same option exists on a CVE's details page for single-CVE exceptions.
Verify#
- Defender portal: the Remediation page shows the activity with its ticket status and progress; the recommendation's exposed device count and the software inventory version move as devices re-report. Configuration fixes should lift Microsoft Secure Score for Devices.
- Intune: the security task shows Completed, and the app or policy you deployed shows success in its device status report.
- On a device: for a configuration task such as PUA protection, confirm the value Defender actually holds:
Get-MpPreference | Select-Object PUAProtection
# 0 = off, 1 = block, 2 = audit- Trend: Reports › Endpoints › Vulnerable devices shows whether exposed device counts are heading the right way over time.
Tips and gotchas#
- No tasks in Intune? Check the Intune connection toggle in the Defender portal, confirm the devices are onboarded, make sure the request wasn't an attention required one, and allow time for the two services to sync.
- Scores lag. Exposure data depends on devices checking in, so don't judge a fix the same afternoon. Exceptions take up to an hour; inactive devices drop out of the scores entirely.
- Don't flood the Intune team. One request per recommendation and device group, with a realistic due date and a note explaining the business risk, gets acted on. Hundreds of low-priority tickets don't.
- Exceptions are not a backlog. Review the Exceptions tab regularly; when one expires the recommendation quietly becomes active again.
- Security Copilot. If your tenant is licensed for it, the Vulnerability Remediation Agent in Intune reads the same vulnerability data and produces prioritised suggestions with step-by-step Intune guidance. It suggests; it doesn't change devices.