CVE Management
Vulnerabilities found by Microsoft Defender are rolled up here one row per CVE, with the devices and tenants each one affects, so you can work a vulnerability across your customer base instead of tenant by tenant. Against each CVE you can record an exception with a reason and an expiry, marking it as handled so it stops competing for attention.
Action Buttons
Table Details
Cve Id
The CVE identifier. Each row is one CVE.
Tenant Count
How many tenants the CVE was found in.
Devices
How many affected devices were counted across those tenants.
Vulnerability Severity Level
Microsoft's severity rating for the vulnerability.
Exploitability Level
Microsoft's assessment of how exploitable the vulnerability is.
Has Exception
Whether an exception has been recorded against this CVE. Drives whether Remove Exception is available.
Affected Devices
The devices the CVE was found on. Expand the cell to see the full list.
Affected Tenants
The tenants the CVE was found in. Expand the cell to see the full list.
An exception is recorded in CIPP only. Nothing is written back to Microsoft Defender, so the vulnerability still appears in the Defender portal exactly as before. Exceptions change what CIPP shows you, not what Microsoft reports.
Table Actions
Add Exception
Records an exception against the selected CVE. Prompts for an Exception Type of Risk Accepted, Compensating Control, False Positive or Planned Remediation; an Apply Exception To scope of Current Tenant Only, All Affected Tenants or All Tenants (Global); a Justification, which is required and is kept alongside the exception with your name and the date; and an optional Exception Expiry Date. Recording an exception where one already exists for the same scope replaces it.
Remove Exception
Removes a recorded exception from the selected CVE, prompting for a Remove Exception From scope of Current Tenant Only, All Affected Tenants or All Tenants (Global). Greyed out on a CVE that has no exception recorded against it.
Current Tenant Only needs a specific tenant selected. It cannot be used while you are on All Tenants, since there is no single tenant for the exception to apply to.
The All Affected Tenants scope currently fails when recording an exception and reports an error instead of writing one. Until this is resolved, use All Tenants (Global) to cover every tenant, or record the exception one tenant at a time with Current Tenant Only. Removing an exception with All Affected Tenants is unaffected.
Feature Requests/Ideas
We value your feedback and ideas. Please raise any feature requests on GitHub.
Last updated
Was this helpful?

