MDE - Devices are displayed in the exposed devices even though the recommendations have been enforced

Lars Wegner 0 Reputation points
2024-12-02T16:31:44.05+00:00

Hi all,

We have problems with the Microsoft Defender vulnerability management. E.g. with the recommendation “Set ‘Maximum password age’ to ‘60 or fewer days, but not 0’”. We have set this setting via GPO and deployed it to the clients/servers. This was also verifiably implemented on the devices. Nevertheless, the Defender Portal still reports the devices as exposed. Since the clients and servers communicate properly with the Defender portal, I cannot explain the behavior even after weeks of waiting. Does anyone have any ideas?

Translated with DeepL.com (free version)

Microsoft Defender for Cloud
Microsoft Defender for Cloud
An Azure service that provides threat protection for workloads running in Azure, on-premises, and in other clouds. Previously known as Azure Security Center and Azure Defender.
1,452 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Prathista Ilango 170 Reputation points Microsoft Employee
    2024-12-30T07:21:30.9866667+00:00

    Hello Lars Wegner,

    This could be because of any of the following reasons,

    1. GPO not successfully applied on the clients/servers: Check a couple of devices to confirm if GPO is applied.
    2. Policy propagation: Sometimes, GPO changes might take time to propagate fully. This could be a reason if GPO is not applied to the devices.
    3. Reporting Delays: Confirm if the devices are able to communicate the status back to defender.

    If all the above are checked, please reach out to support to address this further - Contact Us - Microsoft Support

    If you found the information above helpful, please Click Yes. This will assist others in the community who encounter a similar issue, enabling them to quickly find the solution and benefit from the guidance provided.

    0 comments No comments

Your answer

Answers can be marked as Accepted Answers by the question author, which helps users to know the answer solved the author's problem.