[{"data":1,"prerenderedAt":500},["ShallowReactive",2],{"blog-\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management":3,"blog-\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management-surround":382,"blog-\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management-certifications":442},{"id":4,"title":5,"body":6,"categories":364,"cover":367,"cover_contain":368,"credly_badge_id":369,"date":370,"description":371,"extension":372,"meta":373,"navigation":374,"path":375,"related_certifications":376,"seo":378,"slug":379,"stem":380,"__hash__":381},"blog\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management.md","Achieving a 0% Exposure Score with Microsoft Defender Vulnerability Management",{"type":7,"value":8,"toc":347},"minimark",[9,14,18,56,73,77,95,98,117,123,136,153,162,166,169,176,180,194,199,205,209,212,217,222,229,236,239,253,256,260,265,271,275,278,288,291,295,298,313,317,320,329,332,337,340,343],[10,11,13],"h2",{"id":12},"real-world-use-case","Real-world use case",[15,16,17],"p",{},"You need to prove to an auditor that your vulnerabilities are under control: discover how Microsoft Defender Vulnerability Management let me achieve a 0% exposure score.",[15,19,20,21,25,26,33,34,37,38,41,42,45,46,33,49,37,52,55],{},"Vulnerability management is a fundamental IT security activity: it involves ensuring ",[22,23,24],"strong",{},"proactive"," defense by systematically identifying known and unknown ",[27,28,32],"a",{"href":29,"rel":30},"https:\u002F\u002Flearn.microsoft.com\u002Ffr-fr\u002Fdefender-vulnerability-management\u002Ftvm-weaknesses",[31],"nofollow","weaknesses"," (",[22,35,36],{},"CVEs",", ",[22,39,40],{},"zero-days","), assessing their ",[22,43,44],{},"impact"," and ",[22,47,48],{},"exploitability",[22,50,51],{},"CVSS",[22,53,54],{},"EPSS","), prioritizing remediation, and continuously adapting to emerging threats.",[15,57,58,59,62,63,66,67,72],{},"To get a handle on the threat landscape within my organization, I use ",[22,60,61],{},"Microsoft Defender Vulnerability Management",".",[64,65],"br",{},"\nIt lets me manage all my critical vulnerability management tasks: identification, assessment, prioritization, and remediation. ",[27,68,71],{"href":69,"rel":70},"https:\u002F\u002Flearn.microsoft.com\u002Ffr-fr\u002Fdefender-vulnerability-management\u002Fdefender-vulnerability-management",[31],"Learn more"," about the solution.",[10,74,76],{"id":75},"asset-inventory","Asset inventory",[15,78,79,80,83,84,89,90,62],{},"Asset inventory is the ",[22,81,82],{},"first phase",", obviously essential to know our assets in detail. To do this, I developed ",[27,85,88],{"href":86,"rel":87},"http:\u002F\u002FSerenetics.app",[31],"Serenetics.app",", a tool that connects to all our data to dynamically map the fleet and its risk level, ",[27,91,94],{"href":92,"rel":93},"https:\u002F\u002Fwww.serenetics.fr\u002F",[31],"learn more",[15,96,97],{},"Next comes deploying solutions, such as Microsoft Defender XDR. In our case, it protects our systems on our devices:",[99,100,101,111,114],"ul",{},[102,103,104,105,110],"li",{},"Microsoft Windows 11 (25H2 - ",[27,106,109],{"href":107,"rel":108},"https:\u002F\u002Fsupport.microsoft.com\u002Ffr-fr\u002Ftopic\u002F20-octobre-2025-kb5070773-builds-du-syst%C3%A8me-d-exploitation-26200-6901-et-26100-6901-hors-bande-0f533ed7-949a-4b89-8d0f-6ee751adfcd4",[31],"26200.6901",")",[102,112,113],{},"macOS 26.0.1 (25A362)",[102,115,116],{},"iOS 26.0.1 (23A355)",[118,119,120],"blockquote",{},[15,121,122],{},"I haven't (yet) entrusted the protection and vulnerability management of my servers (Linux and Windows) to Microsoft Defender.",[15,124,125,126,129,130,135],{},"The ",[22,127,128],{},"second phase begins"," with Microsoft Defender Vulnerability Management, which collects the ",[27,131,134],{"href":132,"rel":133},"https:\u002F\u002Flearn.microsoft.com\u002Ffr-fr\u002Fdefender-vulnerability-management\u002Ftvm-software-inventory",[31],"following data",":",[99,137,138,141,144,147,150],{},[102,139,140],{},"Device information",[102,142,143],{},"Software applications",[102,145,146],{},"Digital certificates",[102,148,149],{},"Browser extensions",[102,151,152],{},"Firmware assessments",[15,154,155,156,161],{},"The software inventory now correctly retrieves all CPEs; the default filter shows all software with official ",[27,157,160],{"href":158,"rel":159},"https:\u002F\u002Fnvd.nist.gov\u002Fproducts\u002Fcpe",[31],"Common Platform Enumerations (CPE)",". The view includes details such as vendor name, number of weaknesses, threats, and the number of exposed devices.",[10,163,165],{"id":164},"the-dashboard","The dashboard",[15,167,168],{},"Here's our current exposure score: 0\u002F100, as of October 25, 2025:",[15,170,171],{},[172,173],"img",{"alt":174,"src":175},"","\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002Fa100fabcd4.png",[10,177,179],{"id":178},"security-recommendations","Security recommendations",[15,181,182,183,188,189,193],{},"In our ",[27,184,187],{"href":185,"rel":186},"https:\u002F\u002Fwww.kassianoff.fr\u002Fblog\u002Fobjectif-100-securite-exposition-microsoft365",[31],"previous article",", I mentioned our known vulnerability issue with \"",[172,190],{"alt":191,"src":192},"openssl","\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002F3b72e82b94.png","\". I took the time (manually) to do what was needed to no longer be exposed. Clicking \"improve score\", the default \"active\" filter now shows no issues. However, if I remove the filter:",[15,195,196],{},[172,197],{"alt":174,"src":198},"\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002Fbcc77615e6.png",[15,200,201,202,204],{},"These are security recommendations, with no impact on the exposure score.",[64,203],{},"\nWe find three exceptions out of the 5 in place in our tenant regarding the security score.",[10,206,208],{"id":207},"focus-on-one-device","Focus on one device",[15,210,211],{},"Despite a 0\u002F100 exposure score, let's look at the data the solution has gathered on my Windows 11 machine.",[213,214,216],"h3",{"id":215},"vulnerable-components","Vulnerable components",[15,218,219],{},[172,220],{"alt":174,"src":221},"\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002F83dc01c91f.png",[15,223,224,225,228],{},"Surprisingly, there are still so-called \"vulnerable\" components: these are libraries used notably by OneDrive or third-party tools. They have no identified weaknesses ",[22,226,227],{},"currently",", but MDVM monitors them because they have a history of known CVEs.",[15,230,231,232,235],{},"So I'll need to keep analyzing these components regularly. That said, ",[22,233,234],{},"be careful",": manually removing these libraries can destabilize the applications that depend on them (like OneDrive).",[15,237,238],{},"Best practice is instead to:",[99,240,241,244,247,250],{},[102,242,243],{},"Regularly check whether new CVEs emerge for these components",[102,245,246],{},"Monitor updates to the parent applications (OneDrive, etc.)",[102,248,249],{},"Accept the risk if the component is needed and up to date",[102,251,252],{},"Document these \"false positives\" in MDVM",[15,254,255],{},"This will become a routine regular review for me, but one focused more on monitoring than on systematically removing vulnerable components.",[213,257,259],{"id":258},"at-risk-certificates","At-risk certificates",[15,261,262],{},[172,263],{"alt":174,"src":264},"\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002F044073c163.png",[15,266,267,268,270],{},"Here too, I need to take corrective action to limit expired or less trustworthy certificates on the machine.",[64,269],{},"\nI'm not including a specific screenshot, but there's also a view for browser extensions, under \"Browser extensions\". The extensions and their permissions are visible, in my case for Edge and Firefox, which is quite handy for understanding the associated risks.",[213,272,274],{"id":273},"additional-information","Additional information",[15,276,277],{},"Rather than relying solely on raw severity scores (like CVSS), MDVM uses a risk-based approach to decide where to focus efforts. The system quickly and continuously prioritizes the main vulnerabilities detected on our resources.",[15,279,280,281,283,284,287],{},"I also appreciate being able to get alerted (via webhook or email) when a new vulnerability is detected.",[64,282],{},"\nIt's also possible to use a key feature: ",[22,285,286],{},"blocking vulnerable applications",". You can proactively block known vulnerable versions of applications or alert users via custom desktop notifications.",[15,289,290],{},"Of course, evidence and traceability elements are included; the tool lets you track progress and trends in real time thanks to remediation tracking and device reports.",[10,292,294],{"id":293},"microsoft-defender-vulnerability-management-add-on","Microsoft Defender Vulnerability Management Add-On",[15,296,297],{},"I had never taken the time to go \"beyond\" standard baseline vulnerability management. And yet, under \"Vulnerability management\" there's \"Security baselines assessment\", and that's where things become (in my view) more interesting, provided you accept paying an extra per-user fee.",[15,299,300,301,303,304,307,308],{},"It then becomes possible to create continuous device audits tied to reference standards: STIG or CIS.",[64,302],{},"\nIt seems to me that this is the only place where a posture of excellence really comes into play, despite our current secure score of 100% ",[22,305,306],{},"(based on the CIS M365 Foundations Benchmark)"," and our 0% exposure score. ",[27,309,312],{"href":310,"rel":311},"https:\u002F\u002Flearn.microsoft.com\u002Fen-us\u002Fdefender-vulnerability-management\u002Ftvm-security-baselines",[31],"More information",[213,314,316],{"id":315},"cis-level-2","CIS level 2",[15,318,319],{},"For this, the profile I now want to standardize across my Microsoft Windows environment is:",[99,321,322],{},[102,323,324,325,328],{},"CIS Level 2 (L2) - High Security\u002FSensitive Data Environment (limited functionality) - ",[22,326,327],{},"Benchmark:"," 3.0.0-windows_11",[15,330,331],{},"Here's the score on the Windows 11 25H2 device, obtained on October 26, 2025:",[15,333,334],{},[172,335],{"alt":174,"src":336},"\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002F78897bd6d6.png",[15,338,339],{},"I now know how much ground I still have to cover to meet the most widely recognized protection standards.",[15,341,342],{},"And you, how do you manage your inventory, your CPEs, and the associated CVEs\u002FCVSS? Are you proactively reducing risk to secure your data?",[10,344,346],{"id":345},"conclusion","Conclusion",{"title":174,"searchDepth":348,"depth":348,"links":349},2,[350,351,352,353,354,360,363],{"id":12,"depth":348,"text":13},{"id":75,"depth":348,"text":76},{"id":164,"depth":348,"text":165},{"id":178,"depth":348,"text":179},{"id":207,"depth":348,"text":208,"children":355},[356,358,359],{"id":215,"depth":357,"text":216},3,{"id":258,"depth":357,"text":259},{"id":273,"depth":357,"text":274},{"id":293,"depth":348,"text":294,"children":361},[362],{"id":315,"depth":357,"text":316},{"id":345,"depth":348,"text":346},[365,366],"Microsoft","Sécurité","\u002Fimages\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management\u002Fe8a06eec09.png",false,null,"2025-10-27","0% exposure score and 100% Secure Score: how MDVM automates vulnerability scanning, asset inventory, and compliance.","md",{},true,"\u002Fen\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management",[377],"certificat-microsoft-security-compliance-and-identity-fundamentals",{"title":5,"description":371},"assurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","en\u002Fblog\u002Fassurer-un-score-exposition-de-0-avec-microsoft-defender-vulnerability-management","sOJChqDYEAM8dSjqEz9aFpqQrz4PoMrS2mpKkb0jzDA",[383,391,397,405,413,421,428,435],{"title":384,"path":385,"stem":386,"date":387,"cover":388,"categories":389,"children":-1},"Configuration de base sous Vyatta","\u002Fblog\u002Fconfiguration-base-sous-vyatta","blog\u002Fconfiguration-base-sous-vyatta","2013-09-08","\u002Fimages\u002Fblog\u002Fconfiguration-base-sous-vyatta\u002F8a3fd53886.png",[390],"Réseau",{"title":392,"path":393,"stem":394,"date":395,"cover":396,"categories":369,"children":-1},"Distribution Arch linux : installation","\u002Fblog\u002Fdistribution-arch-linux-installation","blog\u002Fdistribution-arch-linux-installation","2013-09-01","\u002Fimages\u002Fblog\u002Fdistribution-arch-linux-installation\u002F68a1cb957a.png",{"title":398,"path":399,"stem":400,"date":401,"cover":402,"categories":403,"children":-1},"AI Wars, Supply Chain Attack: how to protect yourself from the AI threat?","\u002Fen\u002Fblog\u002Fwebinar-ai-wars-supply-chain-attack-menace-ia","en\u002Fblog\u002Fwebinar-ai-wars-supply-chain-attack-menace-ia","2026-08-07","\u002Fimages\u002Fblog\u002Fwebinar-ai-wars-supply-chain-attack-menace-ia\u002Fthumbnail.jpg",[404],"Webinar",{"title":406,"path":407,"stem":408,"date":409,"cover":410,"categories":411,"children":-1},"ISO\u002FIEC 27001 Lead Implementer","\u002Fen\u002Fblog\u002Fcertificat-iso27001-lead-implementer","en\u002Fblog\u002Fcertificat-iso27001-lead-implementer","2026-03-05","\u002Fimages\u002Fblog\u002Fcertificat-iso27001-lead-implementer\u002F364fa30a2c.png",[412,366],"Certifications",{"title":414,"path":415,"stem":416,"date":417,"cover":418,"categories":419,"children":-1},"GitHub Copilot","\u002Fen\u002Fblog\u002Fcertificat-microsoft-github-copilot","en\u002Fblog\u002Fcertificat-microsoft-github-copilot","2025-08-28","\u002Fimages\u002Fblog\u002Fcertificat-microsoft-github-copilot\u002Fcf8333d63e.png",[412,420],"Code",{"title":422,"path":423,"stem":424,"date":425,"cover":426,"categories":427,"children":-1},"Take Back Control of Your Microsoft Directories with an Infrastructure as Code Approach","\u002Fen\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","en\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code","2025-08-25","\u002Fimages\u002Fblog\u002Freprenez-controle-annuaires-microsoft-infrastructure-as-code\u002F96c873f6c1.png",[365,366],{"title":429,"path":430,"stem":431,"date":432,"cover":433,"categories":434,"children":-1},"Goal: 100%, Veeam Backup & Replication v12 Security","\u002Fen\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","en\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication","2025-08-18","\u002Fimages\u002Fblog\u002Fobjectif-100-securite-veeam-backup-replication\u002Ffd1cbd3a9e.png",[366],{"title":436,"path":437,"stem":438,"date":439,"cover":440,"categories":441,"children":-1},"Optimal Hardening of Active Directory Security","\u002Fen\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","en\u002Fblog\u002Fdurcissement-optimal-securite-active-directory","2025-08-13","\u002Fimages\u002Fblog\u002Fdurcissement-optimal-securite-active-directory\u002F9dc4acd9d6.png",[366],[443],{"id":444,"title":445,"body":446,"categories":490,"cover":491,"cover_contain":374,"credly_badge_id":492,"date":493,"description":494,"extension":372,"meta":495,"navigation":374,"path":496,"related_certifications":369,"seo":497,"slug":377,"stem":498,"__hash__":499},"blog\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals.md","Microsoft: Security, Compliance, and Identity Fundamentals",{"type":7,"value":447,"toc":486},[448,450,453,456,478,481,483],[10,449,13],{"id":12},[15,451,452],{},"To advise my clients on Microsoft security and compliance, I took the Security, Compliance, and Identity Fundamentals certification.",[15,454,455],{},"The \"Microsoft Security, Compliance, and Identity Fundamentals\" training path is designed for IT professionals in charge of deploying and securing cloud resources.\nThe course catalog covers the following modules:",[99,457,458,463,468,473],{},[102,459,460],{},[22,461,462],{},"Describe security, compliance, and identity concepts",[102,464,465],{},[22,466,467],{},"Describe the capabilities of Microsoft Entra",[102,469,470],{},[22,471,472],{},"Describe the capabilities of Microsoft security solutions",[102,474,475],{},[22,476,477],{},"Describe the capabilities of Microsoft compliance solutions",[15,479,480],{},"The training takes about 3 days.\nYou should then allow around 1h00 for the certification exam itself: Microsoft Security, Compliance, and Identity Fundamentals.",[10,482,346],{"id":345},[15,484,485],{},"This Microsoft course covers security, compliance, and identity management concepts, as well as the main associated Microsoft solutions (Entra, security, and compliance). It complements the Azure fundamentals already acquired by providing a broader view of protecting Microsoft environments. A useful certification for any professional in charge of securing cloud resources.",{"title":174,"searchDepth":348,"depth":348,"links":487},[488,489],{"id":12,"depth":348,"text":13},{"id":345,"depth":348,"text":346},[412,365],"\u002Fimages\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals\u002F70ef935f2a.png","82a09914-e95c-43b6-a371-f308b5ee8185","2022-10-17","Microsoft: Security, Compliance, and Identity Fundamentals: course completed as part of my professional watch in cybersecurity and IT.",{},"\u002Fen\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals",{"title":445,"description":494},"en\u002Fblog\u002Fcertificat-microsoft-security-compliance-and-identity-fundamentals","pzrV5JRrELrJgaqSoqL2QuFzeb9_7_olBJ4fv_fRsgo",1786644869256]