First page of Microsoft's 100,000-partner directory, sorted by responsiveness Microsoft Solutions Partner — Security, Modern Work, Infrastructure, App Innovation Microsoft partner since 2006 1,100+ organizations under management
Home/Services/Managed Vulnerability Remediation Service
Managed ServicesSecurity and Protection

Managed Vulnerability Remediation Service

Managed Vulnerability Remediation Service is a recurring monthly program for organizations of roughly 50–500 devices that own Microsoft Defender's vulnerability data but have nobody working the queue. Each month, IT Partner triages new findings from Microsoft Defender Vulnerability Management, prioritizes them by real-world risk, executes remediation within the monthly cap agreed in your service order — software updates, configuration changes, and mitigations through your Microsoft tooling — maintains a documented exception register, and delivers a trend report formatted for the auditors and cyber insurers who ask for a vulnerability management program rather than a one-off cleanup. The service costs $8 per device per month with no long-term contract: stop any month. It builds on the vulnerability capabilities already included in Defender for Endpoint Plan 2 and Defender for Business; network gear and anything else outside Defender's coverage is honestly out of scope.

Timeline 30 daysService owner Dan ApplebyMicrosoft Defender for EndpointMicrosoft Defender Vulnerability ManagementMicrosoft Intune

What this engagement is

There is a specific moment when a vulnerability scanner stops helping and starts hurting: the day an auditor, insurer, or attacker discovers that you had the data and nobody acted on it. Microsoft Defender Vulnerability Management — its core capabilities included in Defender for Endpoint Plan 2 and, for smaller organizations, in Defender for Business inside Microsoft 365 Business Premium — surfaces CVEs, misconfigurations, and outdated software across your onboarded devices continuously. In most 50–500 device organizations, that queue grows monthly because there is no patch-and-vulnerability role on the org chart. The tooling was never the gap; the recurring labor is. This service is that labor, on a monthly cycle with a fixed rhythm. Triage: we review what Defender surfaced since last month and separate the genuinely dangerous from the noise, weighing exploit availability, exposure, and what the affected device does for your business. Remediate: we execute the top of the prioritized list — application updates and version upgrades, configuration corrections, Windows Update and policy fixes, applicable mitigations — through Intune and your Microsoft-native tooling, within the monthly remediation cap defined in your service order, so scope and cost stay predictable. Document: anything you decide to accept rather than fix goes on a maintained exception register with a named owner and reasoning, and the month closes with a report showing what was found, what was fixed, what was excepted, and how your exposure is trending — written so it can be handed directly to an auditor or attached to a cyber-insurance renewal. Two honest boundaries frame the program. If you are starting with a mountain of historical findings, a one-time cleanup — our Defender for Endpoint vulnerability remediation engagement, or its ASR-hardening variant — clears the backlog first; this program then keeps it clear. And the program remediates what Microsoft Defender can see: onboarded devices. Firewalls, switches, printers, and appliances outside Defender's coverage need different scanning and are excluded rather than vaguely implied.

Success criteria

01Every month closes with a delivered report: new findings, remediations completed, exceptions, and the exposure trend across the fleet.
02The prioritized high-risk findings for the month are remediated within the agreed cap, or explicitly carried with a documented reason.
03The exception register stays current — every accepted risk has a named owner, a reason, and a review date.
04Your vulnerability exposure trends visibly downward (or holds at a managed baseline) instead of accumulating.
05When an auditor or insurer asks for evidence of a vulnerability management program, the monthly reports and exception register answer without preparation.
06You can stop any month and keep everything: the reports, the register, and every remediation already delivered.

What you receive

Onboarding baseline (first month): verification of Defender Vulnerability Management data quality and device onboarding coverage, a baseline exposure assessment, agreement of the monthly remediation cap in your service order, and — where a large backlog exists — a recommendation for a one-time cleanup engagement before the recurring rhythm starts.
Monthly triage of new Defender Vulnerability Management findings, prioritized by exploitability, exposure, and business context — not raw CVSS alone.
Monthly remediation execution within the agreed cap: application updates and upgrades, configuration and policy corrections, Windows servicing fixes, and applicable mitigations, delivered through Intune and your Microsoft-native tooling with change notes for every action.
A maintained exception register: accepted risks with owner, justification, compensating controls where relevant, and review dates.
A monthly report formatted for third parties — auditors, cyber insurers, leadership — covering findings, actions, exceptions, and the rolling exposure trend.
A standing monthly review call to walk through the report, decide on exceptions, and set priorities for the next cycle.

How the work unfolds

1. Onboard and baseline (first month)

Verify Defender licensing and device onboarding coverage, assess the current exposure baseline, agree the monthly remediation cap and priorities in the service order, and route any heavy backlog to a one-time cleanup first.

2. Monthly cycle — triage

Review everything Defender Vulnerability Management surfaced since the last cycle and produce the prioritized list, weighing exploit availability, exposure, and device role.

3. Monthly cycle — remediate

Execute the prioritized remediations within the agreed cap through Intune and Microsoft-native tooling, with change notes and rollback awareness for anything user-facing.

4. Monthly cycle — document and review

Update the exception register, deliver the monthly trend report, and hold the review call that closes the month and sets the next one's priorities.

Prerequisites

Administrative access to your Microsoft 365 tenant (we request granular, time-bound GDAP access that you approve — never standing global admin).
Licensing that surfaces vulnerability data: Microsoft Defender for Endpoint Plan 2 (including via Microsoft 365 E5 or E5 Security) or Microsoft Defender for Business (included in Microsoft 365 Business Premium). The premium Defender Vulnerability Management add-on extends coverage further but is not required to start — we work with the data your licensing already produces, verified at onboarding.
In-scope devices onboarded to Defender for Endpoint and manageable through Intune (or an agreed management path) — remediation needs a lever, not just a report. Our Defender for Endpoint deployment and Intune setup services establish this foundation where it is missing.
A named contact empowered to approve remediation windows and make exception decisions at the monthly review.
A service order recording the device count, the monthly remediation cap, and reporting recipients.

Who does what

IT Partner

  • Run the monthly triage and maintain the prioritized remediation list.
  • Execute remediations within the agreed monthly cap, with change notes for every action.
  • Maintain the exception register and deliver the monthly trend report.
  • Flag findings that exceed the program's scope (vendor-dependent fixes, end-of-life platforms, incidents) promptly and honestly, with a recommended path.
  • Hold the monthly review call and adjust priorities to your business.

Your team

  • Maintain the qualifying Microsoft licensing and keep new devices onboarded to Defender (or ask us to handle onboarding as part of the monthly cycle by agreement).
  • Approve maintenance windows for remediations that need them.
  • Own exception decisions — accepting a risk is a business call we document, not one we make for you.
  • Attend the monthly review and keep the named contact current.
  • Act on escalations that fall outside the program, such as hardware replacement or vendor application upgrades.

What's not included

One-time backlog cleanups: a large historical queue is cleared faster and cheaper through our one-time Defender for Endpoint vulnerability remediation engagement (or its ASR variant) — this program is the rhythm that keeps you clean afterward, not a bulldozer priced as a subscription.
Scanning or remediation of network equipment and appliances — firewalls, switches, routers, printers, IoT — or any asset outside Microsoft Defender's onboarded coverage. That requires different scanning tooling and is scoped separately if needed.
Deploying or operating third-party vulnerability scanning platforms (Tenable, Qualys, Rapid7, and similar). If you already run one, we can take its exported findings as an input to monthly triage where practical, but the remediation machinery of this program is Microsoft-native and we do not manage the third-party platform itself.
Incident response, breach investigation, malware removal, and 24/7 threat monitoring — detection and response is our Managed Detection and Response (MDR) service; the two programs are complementary, not interchangeable.
Remediations that are not ours to execute: vendor-dependent application fixes, custom application code changes, hardware replacement, and major platform migrations. These are identified, documented, and escalated with a recommended path.
Microsoft license purchases — Defender licensing and any premium Defender Vulnerability Management add-on are Microsoft costs, quoted transparently before any purchase.
Devices persistently offline, unmanaged, or outside the agreed scope.

Limitations & technical notes

!The program's visibility equals Microsoft Defender's visibility: findings come from Defender Vulnerability Management on onboarded devices. Capability depth varies by license tier (Defender for Business, Defender for Endpoint Plan 2, and the premium add-on differ, per Microsoft's published plan comparison at the time of writing) — onboarding verifies what your licensing actually surfaces before we promise anything against it.
!The monthly remediation cap is defined in your service order at onboarding, sized to your fleet and backlog. Prioritization means the riskiest findings are addressed first; findings beyond a month's cap remain visible in the report and roll into the next cycle rather than disappearing.
!A vulnerability management program reduces exposure; it does not guarantee that no vulnerability will ever be exploited. The monthly reports and exception register document diligence honestly — including what was not yet fixed and why — because that is what auditors and insurers actually respect.
!Some remediations require restarts or carry user impact; those run in maintenance windows you approve, which means client scheduling directly affects monthly throughput.
!This page describes the program for insurer and auditor evidence purposes; we do not promise any specific insurer, auditor, or framework outcome — those decisions belong to the third parties making them.
!Billing is per device per month for devices in the agreed scope; the device count is reconciled at the monthly review as your fleet changes.

Frequently asked questions

What does the Managed Vulnerability Remediation Service include each month?

A full cycle on your Microsoft Defender Vulnerability Management data: triage of new findings, risk-based prioritization, remediation execution within the monthly cap agreed in your service order, exception register maintenance, a trend report formatted for auditors and insurers, and a monthly review call. The price is $8 per device per month with no long-term commitment.

What licensing do we need before starting?

Vulnerability data has to come from somewhere: Microsoft Defender for Endpoint Plan 2 (standalone or via Microsoft 365 E5/E5 Security) includes core Defender Vulnerability Management capabilities, and Microsoft Defender for Business — included in Microsoft 365 Business Premium — includes core vulnerability management for smaller organizations. Microsoft's premium Defender Vulnerability Management add-on extends assessments further but is not required to start. We verify what your licensing actually surfaces during onboarding, and quote any Microsoft costs before you buy anything.

How is this different from your one-time vulnerability remediation services?

The one-time engagements — Defender for Endpoint vulnerability remediation, and the variant that adds attack surface reduction rules — are cleanups: a scoped effort that clears an accumulated backlog. This is a program: a monthly rhythm that keeps the queue worked, the exceptions documented, and the trend visible. They chain deliberately — many clients run a cleanup first, then start the program so the mountain never rebuilds. Auditors and insurers increasingly ask for the program, not the cleanup.

How is this different from MDR (Managed Detection and Response)?

MDR watches for active attacks and responds around the clock; this program shrinks the attack surface those attacks need. One is smoke detection and firefighting; the other is fixing the wiring, monthly. They complement each other — our MDR service covers detection and response, and this program covers the vulnerability remediation MDR deliberately does not.

What is the monthly remediation cap and what happens if we exceed it?

The cap is the amount of remediation work included in a month, agreed in your service order at onboarding and sized to your fleet and backlog — it is what makes a flat per-device price honest instead of vague. Prioritization means the riskiest findings are handled first; anything beyond the cap stays visible in the report and rolls forward. If the queue consistently outruns the cap, we say so at the review and adjust the program with you rather than letting a backlog build silently.

What kinds of fixes do you actually perform?

The remediations Defender's findings call for on managed devices: application updates and version upgrades, insecure configuration corrections, Windows servicing and policy fixes, and applicable mitigations, executed through Intune and Microsoft-native tooling with change notes. What we cannot fix — vendor-dependent application flaws, end-of-life hardware, custom code — we document and escalate with a recommended path instead of quietly skipping.

Does this cover our servers, network gear, or cloud resources?

Coverage follows Defender onboarding and Intune manageability — primarily your Windows client fleet, with Defender-onboarded servers includable by agreement in the service order. Network equipment, printers, appliances, and anything Defender cannot see are honestly out of scope; they need different scanning tooling, which we can discuss separately rather than imply here.

We already run Tenable/Qualys/Rapid7 — does that conflict?

No conflict, and no pretense either: we do not deploy or operate third-party scanning platforms. If you have one, we can take its exported findings as an input to the monthly triage where practical, so one prioritized list drives the work. The remediation machinery itself stays Microsoft-native — that is what keeps the program efficient at this price point.

Will the reports satisfy our cyber insurer or auditor?

The reports are designed for exactly that audience: monthly evidence of a functioning vulnerability management program — findings, actions, documented exceptions, and trend over time. What we will not do is promise a specific insurer's or auditor's verdict; those are their decisions. If you want your broader posture reviewed against a full insurance questionnaire, our Cyber Insurance Readiness Assessment covers that ground.

Are we locked into a contract?

No. The program is month to month — stop any month, and all we ask is payment of previously approved invoices. Everything the program produced stays yours: the reports, the exception register, and every fix already applied. We keep the exit door visibly open because a program that has to lock you in is not confident it is worth keeping.

What happens in the first month?

Onboarding: we verify Defender licensing and onboarding coverage, establish the exposure baseline, agree the monthly cap and reporting recipients in the service order, and start the first triage. If the baseline reveals a heavy backlog, we will recommend the one-time cleanup engagement first — it is the cheaper way to clear a mountain, and this program is the right way to keep it cleared.

How does billing work as our device count changes?

Billing is $8 per device per month for the devices in the agreed scope, reconciled at the monthly review as machines join and leave the fleet. No tiers to fall off, no true-up surprises at renewal — the number moves with reality, in both directions.

Didn’t find your question?

Ask it here. A real engineer answers by email within one business day — and if it’s a good one, it becomes part of this page so the next person finds it.

Answered by a person, one time, to your inbox. Nothing you type here is published without a human reviewing and anonymizing it first.

Often combined with

$8 per device per month
30 days
Start the vulnerability program