Managed Vulnerability Remediation Service
Managed Vulnerability Remediation Service is a recurring monthly program for organizations of roughly 50–500 devices that own Microsoft Defender's vulnerability data but have nobody working the queue. Each month, IT Partner triages new findings from Microsoft Defender Vulnerability Management, prioritizes them by real-world risk, executes remediation within the monthly cap agreed in your service order — software updates, configuration changes, and mitigations through your Microsoft tooling — maintains a documented exception register, and delivers a trend report formatted for the auditors and cyber insurers who ask for a vulnerability management program rather than a one-off cleanup. The service costs $8 per device per month with no long-term contract: stop any month. It builds on the vulnerability capabilities already included in Defender for Endpoint Plan 2 and Defender for Business; network gear and anything else outside Defender's coverage is honestly out of scope.
What this engagement is
There is a specific moment when a vulnerability scanner stops helping and starts hurting: the day an auditor, insurer, or attacker discovers that you had the data and nobody acted on it. Microsoft Defender Vulnerability Management — its core capabilities included in Defender for Endpoint Plan 2 and, for smaller organizations, in Defender for Business inside Microsoft 365 Business Premium — surfaces CVEs, misconfigurations, and outdated software across your onboarded devices continuously. In most 50–500 device organizations, that queue grows monthly because there is no patch-and-vulnerability role on the org chart. The tooling was never the gap; the recurring labor is. This service is that labor, on a monthly cycle with a fixed rhythm. Triage: we review what Defender surfaced since last month and separate the genuinely dangerous from the noise, weighing exploit availability, exposure, and what the affected device does for your business. Remediate: we execute the top of the prioritized list — application updates and version upgrades, configuration corrections, Windows Update and policy fixes, applicable mitigations — through Intune and your Microsoft-native tooling, within the monthly remediation cap defined in your service order, so scope and cost stay predictable. Document: anything you decide to accept rather than fix goes on a maintained exception register with a named owner and reasoning, and the month closes with a report showing what was found, what was fixed, what was excepted, and how your exposure is trending — written so it can be handed directly to an auditor or attached to a cyber-insurance renewal. Two honest boundaries frame the program. If you are starting with a mountain of historical findings, a one-time cleanup — our Defender for Endpoint vulnerability remediation engagement, or its ASR-hardening variant — clears the backlog first; this program then keeps it clear. And the program remediates what Microsoft Defender can see: onboarded devices. Firewalls, switches, printers, and appliances outside Defender's coverage need different scanning and are excluded rather than vaguely implied.
Success criteria
What you receive
How the work unfolds
Verify Defender licensing and device onboarding coverage, assess the current exposure baseline, agree the monthly remediation cap and priorities in the service order, and route any heavy backlog to a one-time cleanup first.
Review everything Defender Vulnerability Management surfaced since the last cycle and produce the prioritized list, weighing exploit availability, exposure, and device role.
Execute the prioritized remediations within the agreed cap through Intune and Microsoft-native tooling, with change notes and rollback awareness for anything user-facing.
Update the exception register, deliver the monthly trend report, and hold the review call that closes the month and sets the next one's priorities.
Prerequisites
Who does what
IT Partner
- Run the monthly triage and maintain the prioritized remediation list.
- Execute remediations within the agreed monthly cap, with change notes for every action.
- Maintain the exception register and deliver the monthly trend report.
- Flag findings that exceed the program's scope (vendor-dependent fixes, end-of-life platforms, incidents) promptly and honestly, with a recommended path.
- Hold the monthly review call and adjust priorities to your business.
Your team
- Maintain the qualifying Microsoft licensing and keep new devices onboarded to Defender (or ask us to handle onboarding as part of the monthly cycle by agreement).
- Approve maintenance windows for remediations that need them.
- Own exception decisions — accepting a risk is a business call we document, not one we make for you.
- Attend the monthly review and keep the named contact current.
- Act on escalations that fall outside the program, such as hardware replacement or vendor application upgrades.
What's not included
Limitations & technical notes
Frequently asked questions
What does the Managed Vulnerability Remediation Service include each month?
A full cycle on your Microsoft Defender Vulnerability Management data: triage of new findings, risk-based prioritization, remediation execution within the monthly cap agreed in your service order, exception register maintenance, a trend report formatted for auditors and insurers, and a monthly review call. The price is $8 per device per month with no long-term commitment.
What licensing do we need before starting?
Vulnerability data has to come from somewhere: Microsoft Defender for Endpoint Plan 2 (standalone or via Microsoft 365 E5/E5 Security) includes core Defender Vulnerability Management capabilities, and Microsoft Defender for Business — included in Microsoft 365 Business Premium — includes core vulnerability management for smaller organizations. Microsoft's premium Defender Vulnerability Management add-on extends assessments further but is not required to start. We verify what your licensing actually surfaces during onboarding, and quote any Microsoft costs before you buy anything.
How is this different from your one-time vulnerability remediation services?
The one-time engagements — Defender for Endpoint vulnerability remediation, and the variant that adds attack surface reduction rules — are cleanups: a scoped effort that clears an accumulated backlog. This is a program: a monthly rhythm that keeps the queue worked, the exceptions documented, and the trend visible. They chain deliberately — many clients run a cleanup first, then start the program so the mountain never rebuilds. Auditors and insurers increasingly ask for the program, not the cleanup.
How is this different from MDR (Managed Detection and Response)?
MDR watches for active attacks and responds around the clock; this program shrinks the attack surface those attacks need. One is smoke detection and firefighting; the other is fixing the wiring, monthly. They complement each other — our MDR service covers detection and response, and this program covers the vulnerability remediation MDR deliberately does not.
What is the monthly remediation cap and what happens if we exceed it?
The cap is the amount of remediation work included in a month, agreed in your service order at onboarding and sized to your fleet and backlog — it is what makes a flat per-device price honest instead of vague. Prioritization means the riskiest findings are handled first; anything beyond the cap stays visible in the report and rolls forward. If the queue consistently outruns the cap, we say so at the review and adjust the program with you rather than letting a backlog build silently.
What kinds of fixes do you actually perform?
The remediations Defender's findings call for on managed devices: application updates and version upgrades, insecure configuration corrections, Windows servicing and policy fixes, and applicable mitigations, executed through Intune and Microsoft-native tooling with change notes. What we cannot fix — vendor-dependent application flaws, end-of-life hardware, custom code — we document and escalate with a recommended path instead of quietly skipping.
Does this cover our servers, network gear, or cloud resources?
Coverage follows Defender onboarding and Intune manageability — primarily your Windows client fleet, with Defender-onboarded servers includable by agreement in the service order. Network equipment, printers, appliances, and anything Defender cannot see are honestly out of scope; they need different scanning tooling, which we can discuss separately rather than imply here.
We already run Tenable/Qualys/Rapid7 — does that conflict?
No conflict, and no pretense either: we do not deploy or operate third-party scanning platforms. If you have one, we can take its exported findings as an input to the monthly triage where practical, so one prioritized list drives the work. The remediation machinery itself stays Microsoft-native — that is what keeps the program efficient at this price point.
Will the reports satisfy our cyber insurer or auditor?
The reports are designed for exactly that audience: monthly evidence of a functioning vulnerability management program — findings, actions, documented exceptions, and trend over time. What we will not do is promise a specific insurer's or auditor's verdict; those are their decisions. If you want your broader posture reviewed against a full insurance questionnaire, our Cyber Insurance Readiness Assessment covers that ground.
Are we locked into a contract?
No. The program is month to month — stop any month, and all we ask is payment of previously approved invoices. Everything the program produced stays yours: the reports, the exception register, and every fix already applied. We keep the exit door visibly open because a program that has to lock you in is not confident it is worth keeping.
What happens in the first month?
Onboarding: we verify Defender licensing and onboarding coverage, establish the exposure baseline, agree the monthly cap and reporting recipients in the service order, and start the first triage. If the baseline reveals a heavy backlog, we will recommend the one-time cleanup engagement first — it is the cheaper way to clear a mountain, and this program is the right way to keep it cleared.
How does billing work as our device count changes?
Billing is $8 per device per month for the devices in the agreed scope, reconciled at the monthly review as machines join and leave the fleet. No tiers to fall off, no true-up surprises at renewal — the number moves with reality, in both directions.