Skip to main content
{ Vulnerability Management }

Microsoft Defender for Cloud Recommendation Triage

Writes an evidence-based judgment for each unhealthy High severity Defender for Cloud recommendation, verifies it against the live resource, and exempts the ones the checks prove are already mitigated.

What this agent does

This agent triages unhealthy High severity recommendations in Microsoft Defender for Cloud. It reads each recommendation's resource and assessment, and it runs read-only checks against the affected subscription to confirm or disprove it. It writes a judgment for each recommendation: what an attacker could actually reach, how to verify it, the conditions that would make it not worth fixing now, and the recommended fix. It creates an exemption only when its checks prove the resource is already mitigated, with the evidence in the exemption's description.

The challenge

Defender for Cloud raises more unhealthy recommendations than a cloud team can investigate. The secure score counts every one of them as work. A storage account is flagged for public access while it serves a public website on purpose. A virtual machine is flagged for a missing agent that another tool makes redundant. A network rule is flagged on a subnet with nothing in it. Before a triager can close or fix any of them, someone has to piece together what the resource is and who owns it.

The solution

The agent does the investigation a triager would do and writes it up so the triager can agree or disagree quickly. It keeps what Defender for Cloud observed separate from what it inferred, and it checks the most common alternative explanation for each kind of recommendation against the live resource. It exempts only resources it proves are mitigated, with a reason the audit trail keeps, and it never grants a waiver. Provides a ready-to-act judgment on every recommendation it reviews.

Workflow

  1. 01

    Pick recommendations

    Take a bounded number of unhealthy High severity recommendations, from the recommendation with the most affected resources first.

  2. 02

    Gather evidence

    Read each recommendation's resource, assessment, and subscription, and any related recommendations and alerts on the same resource.

  3. 03

    Verify

    Run read-only checks against the subscription to test the recommendation and its alternative explanation, and confirm the resource still exists.

  4. 04

    Judge and act

    Write the judgment for each recommendation, and create an exemption only when the checks prove the resource is already mitigated.

Agent template

# Microsoft Defender for Cloud Recommendation Triage

## Measurable outcomes

Every recommendation the agent reviews has a triage judgment a triager can act on. Every resource it proves is mitigated has an exemption with the evidence in its description and an expiry. Track how many recommendations were triaged and exempted, and how many open questions remain, on each run.

## Procedure

Each run, take a bounded number of unhealthy High severity recommendations from Microsoft Defender for Cloud in the subscriptions I set. When Defender CSPM is on, take Critical and High risk level instead. Work through one recommendation at a time, starting with the one that has the most affected resources. Keep a record of each triaged resource and its assessment's status change date. Recheck a resource only when that date changes. For each resource, read the assessment, the resource's configuration, the subscription, and other recommendations and alerts on the same resource. Treat every recommendation as a claim, not a fact. Write "the assessment reports public blob access is allowed", not "the storage account is public". Check the common alternative explanation for each kind of recommendation, such as a storage account that hosts a static website on purpose, a virtual machine another endpoint tool already covers, a network security group on a subnet with no attached interfaces, or a SQL server whose auditing goes to a Log Analytics workspace that the assessment does not read. Run read-only checks against the subscription to settle each one, and confirm the resource still exists. For a package vulnerability, list whether the vulnerable code path runs as an open question. Test public access without credentials, and never print sensitive data. For each resource, write what an attacker could actually reach, two or three verification checks with the real resource names, the conditions that would make it not worth fixing now, the remediation options with one recommended, and the questions the evidence cannot answer. Create an exemption only when the checks prove the resource is already mitigated, scoped to that resource and recommendation, with the category set to mitigated, an expiry date, and a description that names the deciding fact. Never create a waiver exemption. Accepting a risk is a decision for the team. Never dismiss alerts or create alert suppression rules. When the resource no longer exists, say so and let Defender for Cloud remove the recommendation on its next assessment. Without cloud access, write the judgment and change nothing. Start in a report-only mode so I can review its judgments before it creates any exemption.

## Requirements

It needs Microsoft Defender for Cloud access to read recommendations, assessments, and alerts and to create exemptions, optional read-only access to the subscriptions in scope for verification, and nothing more. Exemptions need the Microsoft Cloud Security Benchmark assigned to the subscription. Custom recommendations and some built-in ones do not support exemptions. Report those as not exemptable. It never changes cloud resources, Defender plans, policies, or alerts. It changes nothing in Defender for Cloud except the exemptions it creates.