Microsoft Defender Vulnerability Management is not displaying accurate Exposed Devices count

Tom Burton 5 Reputation points
2025-04-25T14:42:46.5966667+00:00

<< NOTE: This relates to Microsoft Defender for Endpoint but there isn't a child tag available for that >>

The Weaknesses table in Microsoft Defender Vulnerability Manager is indicating that there are exposed devices, but when I open the details there are no exposed devices listed. I also know that there are no exposed devices because all devices have been patched. An example is displayed below:

image

Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
255 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Catherine Kyalo 1,390 Reputation points Microsoft Employee
    2025-04-28T06:54:15.6533333+00:00

    Hi @Tom Burton

    I acknowledge that even after remediating the CVEs in your environment, this alert still appears and indicates two devices as exposed. Additionally, they are actually missing from the vulnerability page.

    This appears to be misleading or incomplete information and documented here - https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-weaknesses#report-inaccuracy.

    If you still have access to the vulnerability details, go ahead and report this inaccuracy.

    That being said, I have escalated this to PG and will update if this is a service issue.

    If you find the answer above helpful, please Accept the answer to help anyone in the community who might have a similar question to quickly find the solution.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.