First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Fixing vulnerabilities on devices based on Defender for Endpoint data with ASR Module
Security and Protection

Defender for Endpoint Vulnerability Fixing — ASR Remediation

This service helps organizations identify and fix device vulnerabilities using Microsoft Defender for Endpoint vulnerability data — surfaced by Microsoft Defender Vulnerability Management, built into Defender for Endpoint Plan 2 — together with attack surface reduction (ASR) rules. IT Partner assesses the findings, creates and applies the ASR rules and remediation plan, and reports the results.

Timeline 3 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner uses Microsoft Defender for Endpoint vulnerability data together with attack surface reduction (ASR) rules to assess vulnerabilities across the client's devices and network infrastructure, create a remediation plan, implement that plan, and report the findings. The vulnerability findings come from Microsoft Defender Vulnerability Management capabilities built into Defender for Endpoint; ASR rules are then created and applied to eliminate identified vulnerabilities, reduce the organization's attack surface, and reduce the number of affected devices.

Success criteria

01List of vulnerabilities to be fixed are identified.
02The necessary rules to eliminate vulnerabilities have been created and applied.
03The number of devices with certain vulnerabilities has been significantly reduced or even equals zero.

What you receive

Vulnerability assessment based on Microsoft Defender for Endpoint data (Microsoft Defender Vulnerability Management) and attack surface reduction (ASR) rule coverage.
Comprehensive remediation plan based on the findings from the vulnerability assessment.
Implemented remediation plan to fix the identified vulnerabilities.
Finalized changes and reported findings.

How the work unfolds

Kickoff meeting.

Begin the engagement, confirm scope and device groups, and align on change windows.

Conduct vulnerability assessment.

Analyze Defender for Endpoint vulnerability data and security recommendations to identify and prioritize weaknesses on in-scope devices.

Develop a remediation plan.

Create a remediation plan, including the ASR rules to be created and applied, based on the assessment findings.

Implement a remediation plan.

Apply the approved ASR rules and remediation actions, using audit mode, pilot groups, or staged deployment where appropriate.

Finalize changes and report findings.

Verify the results, finalize the changes, and report the findings and remaining recommendations.

Prerequisites

An active Microsoft 365 tenant with Microsoft Defender for Endpoint available for the in-scope devices.
In-scope devices should be onboarded to Microsoft Defender for Endpoint and reporting sufficient security telemetry for assessment.
Appropriate administrative access must be available for Microsoft Defender, Microsoft 365 security portals, and the endpoint management method used to deploy Attack surface reduction settings, such as Microsoft Intune, Group Policy, or another approved management tool.
The client should provide an agreed list or group of in-scope devices, users, operating systems, and any pilot or test devices for validating ASR rule impact.
The client should provide approved change windows or deployment timing for applying ASR rules and other remediation actions.
Devices must be able to communicate with required Microsoft cloud services and management endpoints so policies can deploy and Defender data can update.
The client should identify known business-critical applications or workflows that may require ASR rule testing, exclusions, or staged deployment.

Who does what

IT Partner

  • Use Microsoft Defender for Endpoint vulnerability data and attack surface reduction (ASR) rules to conduct a thorough vulnerability assessment of the client's devices and network infrastructure.
  • Develop a comprehensive remediation plan based on the findings from the vulnerability assessment.
  • Implement the remediation plan to fix the identified vulnerabilities.

Your team

  • Provide a dedicated point of contact responsible for working with our team and coordinate any outside vendor resources and schedules.
  • Configure all networking equipment such as load balancers, routers, firewalls, and switches.
  • Provide access to physical and virtual servers and/or systems and services as needed.

What's not included

Purchase, renewal, or assignment of Microsoft licensing is not included unless separately agreed.
Initial deployment or full onboarding of Microsoft Defender for Endpoint to unmanaged devices is not included unless separately scoped.
Full Microsoft Intune, Group Policy, or endpoint management platform implementation is not included beyond the policy changes needed for the agreed remediation activities.
Remediation that requires third-party vendor action, application code changes, application upgrades, hardware replacement, or major operating system upgrades is not included unless separately agreed.
Configuration of network equipment such as routers, firewalls, switches, and load balancers remains the client's responsibility unless separately scoped.
Incident response, malware removal, forensic investigation, and breach containment services are not included in this fixed-scope engagement.
Ongoing managed detection and response, continuous vulnerability management, recurring reporting, or post-project security monitoring are not included.
Work for devices, tenants, networks, or business units outside the agreed project scope is not included.

Limitations & technical notes

!Results depend on the completeness and accuracy of Microsoft Defender for Endpoint telemetry, device onboarding status, licensing, and device connectivity during the engagement.
!Attack surface reduction rules can affect application behavior. Pilot testing, audit mode, staged deployment, or exclusions may be required to reduce business disruption.
!Not every vulnerability can be remediated by ASR rules. Some findings may require patching, software upgrades, configuration changes, third-party remediation, or hardware replacement outside this service scope.
!Vulnerability and exposure metrics in Microsoft Defender may take time to update after policies are applied, especially for devices that are offline or infrequently connected.
!The service aims to significantly reduce affected device counts, but it does not guarantee elimination of every vulnerability in every environment.
!Changes should follow the client's normal change management and approval process, including rollback planning where appropriate.

Frequently asked questions

What is the “Fixing vulnerabilities on devices based on Defender for Endpoint data with ASR Module” service?

This service helps organizations identify and remediate device vulnerabilities using Microsoft Defender for Endpoint vulnerability data together with attack surface reduction (ASR) rules. IT Partner assesses vulnerabilities across devices and network infrastructure, creates a remediation plan, implements it, and reports the findings.

What is included in this vulnerability remediation service?

The service includes a vulnerability assessment based on Microsoft Defender for Endpoint data (Microsoft Defender Vulnerability Management), a comprehensive remediation plan, implementation of that plan including the creation and deployment of ASR rules, and final reporting. The intended outcome is to reduce the number of affected devices by applying the necessary rules to eliminate identified vulnerabilities.

How long does the service take?

IT Partner delivers this service over 3 days per project. The actual schedule depends on coordination with the client, access to required systems, and the availability of the client’s point of contact and any outside vendor resources.

How much does the service cost?

The service is $900 per project, quoted fixed-price in writing before work begins. If the environment has special requirements or needs work beyond the stated scope, the pricing impact is confirmed with IT Partner before starting.

What happens during the engagement?

The engagement follows five milestones: kickoff meeting, vulnerability assessment, remediation plan development, remediation implementation, and final reporting. IT Partner uses Defender for Endpoint vulnerability data and ASR rules to identify issues, plan fixes, apply the necessary rules, and summarize the results.

What are the success criteria for this service?

Success is measured by identifying the vulnerabilities to be fixed, creating and applying the necessary rules to eliminate those vulnerabilities, and significantly reducing the number of devices affected by them. In some cases the number of affected devices may be reduced to zero, but the stated goal is significant reduction based on the findings and applicable remediation.

What is the role of attack surface reduction (ASR) rules in this service?

ASR rules are built into Microsoft Defender for Endpoint and constrain behaviors that attackers commonly abuse on endpoints. In this service they are created and applied — through Microsoft Intune, Group Policy, or another approved management tool — to reduce exposure to the identified vulnerabilities and reduce the number of affected devices.

Do we need Microsoft Defender for Endpoint already deployed before starting?

Yes. In-scope devices should be onboarded to Microsoft Defender for Endpoint with eligible licensing and reporting sufficient security telemetry before the assessment begins. Initial deployment or full onboarding of unmanaged devices is scoped separately.

What responsibilities does the client have?

The client provides a dedicated point of contact, coordinates any outside vendor resources and schedules, configures networking equipment such as load balancers, routers, firewalls, and switches, and provides access to required physical and virtual servers, systems, or services. The client should also identify business-critical applications that may require ASR rule testing, exclusions, or staged deployment.

Will this service cause downtime or business disruption?

ASR rules can affect application behavior. Pilot testing, audit mode, staged deployment, or exclusions are used to reduce business disruption, and deployment follows the client’s approved change windows and change management process, including rollback planning where appropriate.

What is not included in the service?

The service does not include license purchases, initial Defender for Endpoint onboarding of unmanaged devices, full Intune or Group Policy platform implementation, remediation requiring third-party vendor action or hardware and OS replacement, network equipment configuration, incident response and forensics, or ongoing managed detection and response after the project.

Will IT Partner guarantee that all vulnerabilities are eliminated?

No. The service aims to identify vulnerabilities, apply rules to eliminate them, and significantly reduce the number of affected devices — in some cases to zero — but not every vulnerability can be remediated by ASR rules, and some findings require patching, upgrades, or third-party remediation outside this scope.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$900 per project
3 days
Book a meeting