Skip to content

Commit 655f254

Browse files
committed
MDVM/MSEM integration updates - Batch 1: Core pages and related images
1 parent 5094084 commit 655f254

30 files changed

+300
-186
lines changed

defender-vulnerability-management/defender-vulnerability-management.md

Lines changed: 19 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -27,10 +27,6 @@ Reducing cyber risk requires comprehensive risk-based vulnerability management t
2727

2828
Defender Vulnerability Management delivers asset visibility, intelligent assessments, and built-in remediation tools for Windows, macOS, Linux, Android, iOS, and network devices. Using Microsoft threat intelligence, breach likelihood predictions, business contexts, and devices assessments, Defender Vulnerability Management rapidly and continuously prioritizes the biggest vulnerabilities on your most critical assets and provides security recommendations to mitigate risk.
2929

30-
Watch the following video to learn more about Defender Vulnerability Management.
31-
32-
> [!VIDEO https://learn-video.azurefd.net/vod/player?id=4ee839c5-4ccb-4cc9-9945-ae8228e35121]
33-
3430
> [!TIP]
3531
> Did you know you can try all the features in Microsoft Defender Vulnerability Management for free? Find out how to [sign up for a free trial](defender-vulnerability-management-trial.md).
3632
@@ -74,7 +70,23 @@ Enable security administrators and IT administrators to collaborate and seamless
7470
- **Alternate mitigations** - Gain insights on other mitigations, such as configuration changes that can reduce risk associated with software vulnerabilities.
7571
- **Real-time remediation status** - Real-time monitoring of the status and progress of remediation activities across the organization.
7672

77-
## Navigation pane
73+
## Vulnerability management experience in Microsoft Defender portal
74+
75+
# [Preview customers](#tab/preview-customers)
76+
77+
[!INCLUDE [mdvm-msem-section](../includes/mdvm-msem-section.md)]
78+
79+
|Area|Description|
80+
|---|---|
81+
| [**Exposure management > Vulnerability management > Overview**](tvm-dashboard-insights.md) |Get a high-level view of your organization's vulnerability information, including the endpoints exposure score, top recommendations, events, vulnerable software, remediation activities, and more. |
82+
|[**Exposure management > Recommendations**](tvm-security-recommendation.md)|See all Microsoft security recommendations in a single, streamlined experience. The **Vulnerabilities** section lists security recommendations and related threat information, where you can dive into recommendations related to specific vulnerabilities. |
83+
|[**Exposure management > Vulnerability management > Remediation**](tvm-remediation.md)|See remediation activities you've created and recommendation exceptions.|
84+
|[**Exposure management > Vulnerability management > Inventories**](tvm-software-inventory.md)|Discover and assess all your organization's assets in a single view.|
85+
|[**Exposure management > Vulnerability management > Vulnerabilities**](tvm-weaknesses.md)|See the list of common vulnerabilities and exposures (CVEs) in your organization.|
86+
|[**Exposure management > Vulnerability management > Overview > Top impactful events**](threat-and-vuln-mgt-event-timeline.md)|View events that may impact your organization's risk. You can also access the event timeline from the **Recommendations > Score history** section.|
87+
|[**Exposure management > Vulnerability management > Baseline assessments**](tvm-security-baselines.md)|Monitor security baseline compliance and identify changes in real-time.|
88+
89+
# [Existing customers](#tab/existing-customers)
7890

7991
|Area|Description|
8092
|---|---|
@@ -86,6 +98,8 @@ Enable security administrators and IT administrators to collaborate and seamless
8698
|[**Event timeline**](threat-and-vuln-mgt-event-timeline.md)|View events that may impact your organization's risk.|
8799
|[**Baselines assessment**](tvm-security-baselines.md)|Monitor security baseline compliance and identify changes in real-time.|
88100

101+
---
102+
89103
## APIs
90104

91105
Run vulnerability management related API calls to automate vulnerability management workflows. To get started, see [Supported Microsoft Defender for Endpoint APIs](/defender-endpoint/api/exposed-apis-list).

defender-vulnerability-management/device-restart-status.md

Lines changed: 13 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -3,29 +3,29 @@ title: Device restart status
33
description: Learn about the device restart status tag in Microsoft Defender Vulnerability Management
44
ms.service: defender-vuln-mgmt
55
ms.pagetype: security
6-
ms.author: deniseb
7-
author: denisebmsft
6+
ms.author: lwainstein
7+
author: limwainstein
88
ms.localizationpriority: medium
9-
manager: deniseb
9+
manager: bagol
1010
audience: ITPro
1111
ms.collection:
1212
- m365-security
1313
- tier1
1414
ms.topic: concept-article
1515
search.appverid: met150
16-
ms.date: 03/04/2022
16+
ms.date: 11/25/2025
17+
appliesto:
18+
- Microsoft Defender Vulnerability Management
19+
- Microsoft Defender for Endpoint Plan 2
20+
- Microsoft Defender XDR
21+
- Microsoft Defender for Servers Plan 1 & 2
1722
---
1823

1924
# Device restart status
2025

2126
[!INCLUDE [mdvm-msem-note](../includes/mdvm-msem-note.md)]
2227

23-
**Applies to:**
24-
25-
- [Microsoft Defender Vulnerability Management](defender-vulnerability-management.md)
26-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
27-
- [Microsoft Defender XDR](/defender-xdr)
28-
- [Microsoft Defender for Servers Plan 1 & 2](/azure/defender-for-cloud/plan-defender-for-servers-select-plan)
28+
Security recommendations can help reduce your overall vulnerability exposure and your exposure score. A robust update process is key when it comes to addressing these recommendations in your organization. If an update hasn't completed for some devices due to a pending restart, the effect of addressing the security recommendation isn't reflected in your exposure score.
2929

3030
Security recommendations in Defender Vulnerability Management can help reduce your overall vulnerability exposure and your exposure score. A robust update process is key when it comes to addressing these recommendations in your organization. If an update hasn't completed for some devices due to a pending restart, the effect of addressing the security recommendation isn't reflected in your exposure score.
3131

@@ -41,15 +41,15 @@ The **Pending restart** tag helps you identify devices in this state so you can
4141

4242
The device restart status is visible in the following experiences in the Microsoft Defender portal.
4343

44-
### Security recommendations page
44+
### Recommendations page
4545

46-
On the security recommendations pages, filter by the **Pending restart** tag to only see security recommendations with devices pending a restart.
46+
On the **Recommendations** page, filter by the **Pending restart** tag to only see security recommendations with devices pending a restart.
4747

4848
:::image type="content" alt-text="pending restart tag in the security recommendations page." source="/defender/media/defender-vulnerability-management/pending-restart.png" lightbox="/defender/media/defender-vulnerability-management/pending-restart.png":::
4949

5050
### Software page
5151

52-
On the software page filter by, the **Pending restart** tag to see missing KBs with devices that are pending a restart:
52+
On the software page filter by the **Pending restart** tag to see missing KBs with devices that are pending a restart:
5353

5454
:::image type="content" alt-text="pending restart tag in the software page." source="/defender/media/defender-vulnerability-management/pending-restart-KB.png" lightbox="/defender/media/defender-vulnerability-management/pending-restart-KB.png":::
5555

-45.7 KB
Loading
-48.4 KB
Loading
-298 KB
Loading
-238 KB
Loading
-87.3 KB
Loading
-117 KB
Loading
-59.3 KB
Loading

defender-vulnerability-management/threat-and-vuln-mgt-event-timeline.md

Lines changed: 50 additions & 18 deletions
Original file line numberDiff line numberDiff line change
@@ -2,8 +2,8 @@
22
title: Event timeline
33
description: Event timeline is a risk news feed that helps you interpret how risk is introduced into the organization, and which mitigations happened to reduce it.
44
ms.service: defender-vuln-mgmt
5-
ms.author: deniseb
6-
author: denisebmsft
5+
ms.author: lwainstein
6+
author: limwainstein
77
ms.localizationpriority: medium
88
manager: deniseb
99
audience: ITPro
@@ -12,21 +12,18 @@ ms.collection:
1212
- Tier1
1313
ms.topic: concept-article
1414
search.appverid: met150
15-
ms.date: 03/04/2022
15+
ms.date: 11/25/2025
16+
appliesto:
17+
- Microsoft Defender Vulnerability Management
18+
- Microsoft Defender for Endpoint Plan 2
19+
- Microsoft Defender XDR
20+
- Microsoft Defender for Servers Plan 1 & 2
1621
---
1722

1823
# Event timeline
1924

2025
[!INCLUDE [mdvm-msem-note](../includes/mdvm-msem-note.md)]
2126

22-
23-
**Applies to:**
24-
25-
- [Microsoft Defender Vulnerability Management](defender-vulnerability-management.md)
26-
- [Microsoft Defender for Endpoint Plan 2](/defender-endpoint/microsoft-defender-endpoint)
27-
- [Microsoft Defender XDR](/defender-xdr)
28-
- [Microsoft Defender for Servers Plan 1 & 2](/azure/defender-for-cloud/plan-defender-for-servers-select-plan)
29-
3027
Event timeline is a risk news feed that helps you interpret how risk is introduced into the organization through new vulnerabilities or exploits. You can view events that may impact your organization's risk. For example, you can find new vulnerabilities that were introduced, vulnerabilities that became exploitable, exploit that was added to an exploit kit, and more.
3128

3229
Event timeline also tells the story of your [exposure score](tvm-exposure-score.md) and [Microsoft Secure Score for Devices](tvm-microsoft-secure-score-devices.md) so you can determine the cause of large changes. Events can impact your devices or your score for devices. Reduce you exposure by addressing what needs to be remediated based on the prioritized [security recommendations](tvm-security-recommendation.md).
@@ -36,22 +33,55 @@ Event timeline also tells the story of your [exposure score](tvm-exposure-score.
3633
3734
## Navigate to the Event timeline page
3835

39-
There are three entry points from the [Microsoft Defender Vulnerability Management dashboard](tvm-dashboard-insights.md):
36+
# [Preview customers](#tab/preview-customers)
37+
38+
[!INCLUDE [mdvm-msem-section](../includes/mdvm-msem-section.md)]
39+
40+
There are two entry points to the event timeline:
41+
42+
- **Exposure management** > **Vulnerability management** > **Overview** page: In the **Top impactful events** card, select **View all events** at the bottom of the table.
43+
- The card displays the three most impactful events in the last 7 days. Impactful events indicate whether the event affects a large number of devices, or if it's a critical vulnerability.
44+
- **Exposure management** > **Recommendations** page: In the **Score history** card, select **View all events** at the bottom of the graph.
45+
46+
# [Existing customers](#tab/existing-customers)
47+
48+
There are three entry points from the **Endpoints** > **Vulnerability management** > **Dashboard** page to the event timeline:
4049

4150
- **Organization exposure score card**: Hover over the event dots in the "Exposure Score over time" graph and select "See all events from this day." The events represent software vulnerabilities.
4251
- **Microsoft Secure Score for Devices**: Hover over the event dots in the "Your score for devices over time" graph and select "See all events from this day." The events represent new configuration assessments.
4352
- **Top events card**: Select "Show more" at the bottom of the top events table. The card displays the three most impactful events in the last 7 days. Impactful events can include if the event affects a large number of devices, or if it is a critical vulnerability.
4453

54+
---
55+
4556
### Exposure score and Microsoft Secure Score for Devices graphs
4657

47-
In the Defender Vulnerability Management dashboard, hover over the Exposure score graph to view top software vulnerability events from that day that impacted your devices. Hover over the Microsoft Secure Score for Devices graph to view new security configuration assessments that affect your score.
58+
# [Preview customers](#tab/preview-customers-secure-score)
59+
60+
[!INCLUDE [mdvm-msem-section](../includes/mdvm-msem-section.md)]
4861

49-
If there are no events that affect your devices or your score for devices, then none will be shown.
62+
In the Exposure management **Overview** page, hover over the **Score history** card under **Vulnerability management** to view top software vulnerability events from that day that impacted your devices.
5063

51-
![Exposure score hover.](/defender/media/defender-vulnerability-management/tvm-event-timeline-device-hover360.png)
52-
![Microsoft Secure Score for Devices hover.](/defender/media/defender-vulnerability-management/tvm-event-timeline-device-hover360.png)
64+
Selecting **Show all events from this day** takes you to the Event timeline page with a custom date range for that day.
5365

54-
### Drill down to events from that day
66+
:::image type="content" source="/defender/media/defender-vulnerability-management/score-history-timeline.png" alt-text="Score history card.":::
67+
68+
To change the date range, select the **Date events occurred** filter above the table, and in the **Filter** flyout pane, select a different date under **Date event occurred**.
69+
70+
![Event timeline selected custom date range.](/defender/media/defender-vulnerability-management/event-timeline-drilldown.png)
71+
72+
In the Exposure management **Recommendations** page, hover over the **Score history** graph to view new security configuration assessments that affect your score.
73+
74+
If there are no events that affect your devices or your score for devices, no events are displayed.
75+
76+
# [Existing customers](#tab/existing-customers-secure-score)
77+
78+
In the Defender Vulnerability Management dashboard, hover over the **Exposure score** graph to view top software vulnerability events from that day that impacted your devices.
79+
80+
Hover over the **Microsoft Secure Score for Devices** graph to view new security configuration assessments that affect your score.
81+
82+
If there are no events that affect your devices or your score for devices, no events are displayed.
83+
84+
![Exposure score hover.](/defender/media/defender-vulnerability-management/tvm-event-timeline-device-hover360.png)
5585

5686
Selecting **Show all events from this day** takes you to the Event timeline page with a custom date range for that day.
5787

@@ -61,9 +91,11 @@ Select **Custom range** to change the date range to another custom one, or a pre
6191

6292
![Event timeline date range options.](/defender/media/defender-vulnerability-management/tvm-event-timeline-dates.png)
6393

94+
---
95+
6496
## Event timeline overview
6597

66-
On the Event timeline page, you can view the all the necessary info related to an event.
98+
On the **Event timeline** page, you can view the all the necessary info related to an event.
6799

68100
Features:
69101

0 commit comments

Comments
 (0)