New Threat & Vulnerability Management capabilities in Defender ATP

Microsoft announces the following new capabilities that will go into public preview this month:

  • Vulnerability Assessment (VA) support for Windows Servers 2008 R2 and above
  • Integration with ServiceNow for improved IT/Security communication
  • Advanced hunting across vulnerabilities and security alerts
  • Role-based access controls (RBAC) for teams focusing on vulnerability management
  • Automated user-impact analysis

The ServiceNow integration is very easy. Just follow the guide in the settings tab

This feature provides one-click remediation request via Service Now to other IT teams.

TVM capabilities – Let’s use in hunting 🙂

TVM hunting

RBAC – more granular control

Defender ATP rbac

Happy Hunting!

More articles

Replacing Local Admin with Intune EPM

What Works, What Does Not, and What to Expect in Practice The shift becomes easier to understand...

One On One(vinn): Nicklas Ahlberg

External Sharing in Microsoft 365 is changing - what you need to know

When you share files via SharePoint Online or OneDrive, external users have historically been...