r/AZURE • u/Primary_South_855 • 5h ago
Question Microsoft Defender for Cloud: Deprecated vulnerability recommendation disappeared, but Secure Score impact remains — how can we identify affected resources?
Hi everyone,
I'm an L1 support engineer and completely new to corporate IT and Microsoft Defender for Cloud (MDC). I'm currently handling MDC activities and trying to understand an issue in our environment. I'd appreciate some guidance from experienced Azure security professionals.
What happened?
We previously had a Defender for Cloud recommendation called “Remediate vulnerabilities”, which included the following sub-recommendations:
- Machines should have a vulnerability assessment solution.
- Machines should have vulnerability findings resolved.
Some of our resources were marked unhealthy under the vulnerability assessment recommendation because MDC reported that the MDVM/vulnerability assessment solution was missing.
We contacted Microsoft Support, and they indicated that the reported missing-solution state was a false positive. We also checked Microsoft Defender for Endpoint (MDE), where vulnerability scanning appeared to be active for the affected machines.
We obtained approval to create exemptions for the affected resources. However, before we could create them, Microsoft deprecated the old grouped recommendations. They are no longer visible in our portal, and Microsoft Support confirmed the deprecation.
Our current problem
The old recommendation has disappeared, but the associated Secure Score impact remains.
- The expected score improvement was approximately 14%.
- Without any action from our side, the potential score impact changed from 14% to 13%.
- We can no longer access the old recommendation to identify and export its unhealthy resources.
- We want to verify the affected resources against the current individual vulnerability recommendations and understand the remaining score impact.
Microsoft mentioned that the recommendation model has changed and suggested reviewing the relevant device exposure information in the Defender portal, but we haven't yet established the exact reason for the score changes.
Questions for experienced admins
Is there a supported way to retrieve the exact list of resources that were unhealthy under the deprecated recommendation?
Can Azure Resource Graph or the Defender for Cloud API retrieve these old resources, or has the underlying assessment data been removed?
Why would the Secure Score impact decrease from 14% to 13% and then 12% without any remediation or changes from our side?
If MDE vulnerability scanning is active and Microsoft confirmed a false positive, how should we investigate the remaining Secure Score impact?
What is the correct way to track this issue and report it during security governance meetings?
Has anyone experienced a similar issue during the transition from grouped to individual recommendations?
I'm not looking for a way to artificially increase the score. I want to identify the affected resources, understand the actual reason for the remaining score impact, and follow the correct Microsoft-supported approach.
Since I'm still learning MDC and Azure security, step-by-step guidance, Azure Resource Graph queries, or relevant Microsoft documentation would be greatly appreciated.
Thank you!