First page of Microsoft's 100,000-partner directory, sorted by responsiveness All 6 Microsoft Solutions Partner designations Microsoft Solutions Partner since 2006 1,100+ organizations under management
Home/Services/Fixing vulnerabilities on devices based on Defender for Endpoint data with ASR Module
Security and Protection

Defender for Endpoint Vulnerability Fixing — ASR Remediation

This service helps organizations identify and fix device vulnerabilities by using Microsoft Defender for Endpoint data with the Attack surface reduction module. IT Partner delivers this service as SKU ITPWW120SECOT for $900 per project over 3 days; the manager is Roman Sotnik.

Timeline 3 daysService owner Roman SotnikOffice 365microsoft 365

What this engagement is

IT Partner uses Microsoft Defender for Endpoint data with the Attack surface reduction module to assess vulnerabilities across the client's devices and network infrastructure, create a remediation plan, implement that plan, and report the findings. The goal is to fix vulnerabilities on devices and reduce the organization's attack surface by creating and applying the necessary rules to eliminate identified vulnerabilities and reduce the number of affected devices.

Success criteria

01List of vulnerabilities to be fixed are identified.
02The necessary rules to eliminate vulnerabilities have been created and applied.
03The number of devices with certain vulnerabilities has been significantly reduced or even equals zero.

What you receive

Vulnerability assessment based on data from Microsoft Defender for Endpoint with an Attack surface reduction module.
Comprehensive remediation plan based on the findings from the vulnerability assessment.
Implemented remediation plan to fix the identified vulnerabilities.
Finalized changes and reported findings.

How the work unfolds

Kickoff meeting.

Kickoff meeting.

Conduct vulnerability assessment.

Conduct vulnerability assessment.

Develop a remediation plan.

Develop a remediation plan.

Implement a remediation plan.

Implement a remediation plan.

Finalize changes and report findings.

Finalize changes and report findings.

Prerequisites

An active Microsoft 365 tenant with Microsoft Defender for Endpoint available for the in-scope devices.
In-scope devices should be onboarded to Microsoft Defender for Endpoint and reporting sufficient security telemetry for assessment.
Appropriate administrative access must be available for Microsoft Defender, Microsoft 365 security portals, and the endpoint management method used to deploy Attack surface reduction settings, such as Microsoft Intune, Group Policy, or another approved management tool.
The client should provide an agreed list or group of in-scope devices, users, operating systems, and any pilot or test devices for validating ASR rule impact.
The client should provide approved change windows or deployment timing for applying ASR rules and other remediation actions.
Devices must be able to communicate with required Microsoft cloud services and management endpoints so policies can deploy and Defender data can update.
The client should identify known business-critical applications or workflows that may require ASR rule testing, exclusions, or staged deployment.

Who does what

IT Partner

  • Use data from Microsoft Defender for Endpoint with an Attack surface reduction module to conduct a thorough vulnerability assessment of the client's devices and network infrastructure.
  • Develop a comprehensive remediation plan based on the findings from the vulnerability assessment.
  • Implement the remediation plan to fix the identified vulnerabilities.

Your team

  • Provide a dedicated point of contact responsible for working with our team and coordinate any outside vendor resources and schedules.
  • Configure all networking equipment such as load balancers, routers, firewalls, and switches.
  • Provide access to physical and virtual servers and/or systems and services as needed.

What's not included

Purchase, renewal, or assignment of Microsoft licensing is not included unless separately agreed.
Initial deployment or full onboarding of Microsoft Defender for Endpoint to unmanaged devices is not included unless separately scoped.
Full Microsoft Intune, Group Policy, or endpoint management platform implementation is not included beyond the policy changes needed for the agreed remediation activities.
Remediation that requires third-party vendor action, application code changes, application upgrades, hardware replacement, or major operating system upgrades is not included unless separately agreed.
Configuration of network equipment such as routers, firewalls, switches, and load balancers remains the client's responsibility unless separately scoped.
Incident response, malware removal, forensic investigation, and breach containment services are not included in this fixed-scope engagement.
Ongoing managed detection and response, continuous vulnerability management, recurring reporting, or post-project security monitoring are not included.
Work for devices, tenants, networks, or business units outside the agreed project scope is not included.

Limitations & technical notes

!Results depend on the completeness and accuracy of Microsoft Defender for Endpoint telemetry, device onboarding status, licensing, and device connectivity during the engagement.
!Attack surface reduction rules can affect application behavior. Pilot testing, audit mode, staged deployment, or exclusions may be required to reduce business disruption.
!Not every vulnerability can be remediated by ASR rules. Some findings may require patching, software upgrades, configuration changes, third-party remediation, or hardware replacement outside this service scope.
!Vulnerability and exposure metrics in Microsoft Defender may take time to update after policies are applied, especially for devices that are offline or infrequently connected.
!The service aims to significantly reduce affected device counts, but it does not guarantee elimination of every vulnerability in every environment.
!Changes should follow the client's normal change management and approval process, including rollback planning where appropriate.

Frequently asked questions

What is the “Fixing vulnerabilities on devices based on Defender for Endpoint data with ASR Module” service?

This service helps organizations identify and remediate device vulnerabilities by using Microsoft Defender for Endpoint data with the Attack surface reduction module. IT Partner assesses vulnerabilities across devices and network infrastructure, creates a remediation plan, implements it, and reports the findings.

What is included in this vulnerability remediation service?

The service includes a vulnerability assessment based on Microsoft Defender for Endpoint data with the Attack surface reduction module, a comprehensive remediation plan, implementation of that plan, and final reporting. The intended outcome is to reduce the number of affected devices by creating and applying the necessary rules to eliminate identified vulnerabilities.

What are the expected deliverables from the engagement?

The deliverables are a vulnerability assessment, a remediation plan based on the assessment findings, implementation of the remediation plan, and finalized changes with reported findings. These deliverables are focused specifically on vulnerabilities identified through Microsoft Defender for Endpoint data and Attack surface reduction capabilities.

How long does the service take?

IT Partner delivers this service over 3 days per project. The actual schedule depends on coordination with the client, access to required systems, and the availability of the client’s point of contact and any outside vendor resources.

How much does the service cost?

The service is listed as SKU ITPWW120SECOT and costs $900 per project. If the environment has special requirements or needs work beyond the stated scope, the client should confirm any impact on pricing with IT Partner before starting.

Who manages this service at IT Partner?

The listed manager for this service is Roman Sotnik. Prospective buyers can reference SKU ITPWW120SECOT when discussing the engagement with IT Partner.

What happens during the engagement?

The engagement follows five main milestones: kickoff meeting, vulnerability assessment, remediation plan development, remediation implementation, and final reporting. IT Partner uses Microsoft Defender for Endpoint data with the Attack surface reduction module to identify issues, plan fixes, apply the necessary rules, and summarize the results.

What are the success criteria for this service?

Success is measured by identifying the vulnerabilities to be fixed, creating and applying the necessary rules to eliminate those vulnerabilities, and significantly reducing the number of devices affected by those vulnerabilities. In some cases, the number of affected devices may be reduced to zero, but the stated goal is significant reduction based on the findings and applicable remediation.

Does this service use Microsoft Defender for Endpoint?

Yes, this service is based on data from Microsoft Defender for Endpoint together with the Attack surface reduction module. The assessment and remediation plan rely on that data to identify vulnerabilities and reduce the organization’s attack surface.

What is the role of Attack surface reduction in this service?

Attack surface reduction is used to help create and apply rules that reduce exposure to identified vulnerabilities. The service focuses on applying necessary rules to eliminate vulnerabilities and reduce the number of affected devices.

What responsibilities does IT Partner handle?

IT Partner conducts the vulnerability assessment using Microsoft Defender for Endpoint data with the Attack surface reduction module, develops a remediation plan, and implements that plan to fix identified vulnerabilities. IT Partner also finalizes the changes and reports the findings at the end of the engagement.

What responsibilities does the client have?

The client must provide a dedicated point of contact, coordinate any outside vendor resources and schedules, configure networking equipment such as load balancers, routers, firewalls, and switches, and provide access to required physical and virtual servers, systems, or services. These responsibilities are important because IT Partner needs coordination and access to complete the assessment and remediation work.

Are there any prerequisites for this service?

The original source information does not list explicit prerequisites separate from client responsibilities. The AI-drafted prerequisites should be confirmed during scoping; at minimum, the client should be prepared to provide access to needed systems and services, assign a dedicated point of contact, and coordinate networking or vendor resources as required.

Is configuration of routers, firewalls, switches, or load balancers included?

No specific IT Partner responsibility is listed for configuring networking equipment. The client is responsible for configuring networking equipment such as load balancers, routers, firewalls, and switches, so any exception should be confirmed with IT Partner before the project begins.

What is not included in the service?

The original source information does not specify formal out-of-scope items or additional-cost items. Because the scope is centered on Defender for Endpoint data, Attack surface reduction rules, remediation planning, implementation, and reporting, buyers should confirm any requested work outside that scope with IT Partner.

Will this service cause downtime or business disruption?

The service description does not specify expected downtime or a guaranteed no-downtime implementation. Because remediation actions and Attack surface reduction rules can affect device behavior, the client should coordinate timing, access, and any change windows with IT Partner during the kickoff and implementation planning.

Will IT Partner guarantee that all vulnerabilities are eliminated?

The service aims to identify vulnerabilities, create and apply rules to eliminate them, and significantly reduce the number of affected devices. The stated success criteria allow that affected device counts may be significantly reduced or even equal zero, but the service description does not state a blanket guarantee that every vulnerability in every environment will be eliminated.

What happens after the remediation plan is implemented?

After implementation, IT Partner finalizes the changes and reports the findings. The final report summarizes the work completed and the results of the vulnerability assessment and remediation activities.

Can this service help reduce the organization’s attack surface?

Yes, reducing the attack surface is a stated goal of the service. IT Partner uses Microsoft Defender for Endpoint data and the Attack surface reduction module to identify vulnerabilities, apply necessary rules, and reduce the number of devices affected by those vulnerabilities.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

$900 per project
3 days
Book a meeting