Skip to content
Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation

Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation

Written By Anoop C Nair
Last Updated February 11, 2026
SHARE

Key Takeaways:

  • New Reporting Filters in Defender Vulnerability Management
  • Filters are designed to make it easier to identify high‑risk device
  • Admins gain clearer insights into vulnerable devices, enabling more efficient troubleshooting and reporting
  • Changes support better decision‑making by aligning vulnerability

Let’s discuss about Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation. The public preview of Device Vulnerabilities report in Microsoft Defender Vulnerability Management is available now.

Table of Contents

Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation

Microsoft release the public preview of Device Vulnerabilities report in Microsoft Defender. With this public preview Vulnerable devices report now includes some changes and enhancements. These changes are not yet visible to government cloud customer and will be visible in late January 2026. The following table shows the new changes and enhancements.

Changes and Enhancements
The Vulnerable devices by Windows 10/11 version over time section has been removed
The report’s filters have been simplified to only include the Device group filter
The report’s history is now limited to the last 30 days
Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation – Table.1

How to Locate Vulnerability Management Section

The Vulnerability Management section in the Microsoft Defender portal is now located under Exposure management. With this change, you can now consume and manage security exposure data and vulnerability data in a unified location, to enhance your existing Vulnerability Management features.

  • Sign in to the Microsoft Defender portal.
  • In the left navigation pane, go to Exposure management (previously called Threat & Vulnerability Management).
  • Select Reports > Device vulnerabilities.
  • The Device vulnerabilities report will open, showing
    • Vulnerable devices by severity, exploit availability, and age.
    • Filters for device groups, OS, and vulnerability categories.
    • Trend charts to track remediation progress over time.
Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation - Fig.1
Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation – Fig.1

Columns and Filters on Vulnerable Devices Report

You can easily access the report in the Microsoft Defender portal by going to Reports > Vulnerable devices. There are 2 columns available on Vulnerable Devices Report which are trends and status. The trends can show data from the past 30 days up to six months. The Status shows the current status.

Patch My PC

Severity Level Graphs

Each device is counted only once according to the most severe vulnerability found on that device. Look at the below screenshots.

Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation - Fig.2 - Creds to MS
Explore New Device Report Filters in Microsoft Defender Vulnerability Management for Prioritize Remediation – Fig.2 – Creds to MS

Need Further Assistance or Have Technical Questions?

Join the LinkedIn Page and Telegram group to get the step-by-step guides and news updates. Join our Meetup Page to participate in User group meetings. Also, Join the WhatsApp Community  and WhatsApp Channel to get the latest news on Microsoft Technologies. We are there on Reddit as well.

Author

Anoop C Nair has been Microsoft MVP for 10 consecutive years from 2015 onwards. He is a Workplace Solution Architect with more than 22+ years of experience in Workplace technologies. He is a Blogger, Speaker, and Local User Group Community leader. His primary focus is on Device Management technologies like SCCM and Intune. He writes about technologies like Intune, SCCM,  Windows,  Cloud PC,  Windows, Entra, Microsoft Security, Career, etc.

Written by

Anoop C Nair is Workplace Technology solution architect with 25+ years of experience in global enterprise organizations such as JP Morgan, Capgemini, etc. Microsoft Certified Trainer. Microsoft MVP from 2015 onwards for consecutive 11+ years! He also conducts Intune and modern workplace tech training for enterprise organizations. He is Blogger, Speaker, and Founder of HTMD Community and HTMD Conference. His main focus is on Device Management technologies like Intune, Windows, Cloud PC. He writes about technologies like Intune, SCCM, Windows, Cloud PC, Windows, Entra, Microsoft Security.

Discussion

Join the discussion

Your email address will not be published. Required fields are marked *

Related guides

Microsoft Defender for Endpoint

Microsoft Defender for Endpoint EDR Updates are now Separate from Monthly Windows Security Updates for Faster Protection

Key Takeaways In this post, we are discussing how Microsoft Defender for Endpoint EDR Updates Will Be Delivered Through Microsoft Update. Microsoft has introduced a new update model for Microsoft Defender for Endpoint Detection and Response (EDR) security updates. Previously, these updates were included with the monthly Windows security updates. This change enables Microsoft to […]

AC Anoop C Nair 5 min read
Microsoft Defender for Endpoint

Microsoft Defender Custom Data Collection Lets You Collect Custom Endpoint Logs Without Extra Agents

Key Takeaways: Let’s discuss about Microsoft Defender Custom Data Collection to Streamlined Telemetry without Extra Agent. Microsoft announced the general availability of Microsoft Defender Custom Data Collection. This feature is simplified collection of logging through the Defender agent itself. Microsoft Defender Custom Data Collection to Streamlined Telemetry without Extra Agent Admins can define which events […]

AC Anoop C Nair 3 min read
Intune

Manage Offline Security Updates for Linux using Microsoft Defender and Intune

Key Takeaways Manage Offline Security Updates for Linux using Microsoft Defender and Intune! Microsoft now allows admins to manage offline security intelligence updates for Linux devices directly from the Defender and Intune portals. Admins can configure how Linux devices receive Defender security updates without using manual command-line configurations on each device. Configure Offline Security Intelligence […]

AC Anoop C Nair 3 min read
Microsoft Defender for Endpoint

New Selective Response Actions Improve Safer Device Onboarding in Microsoft Defender for Endpoint

Key Takeaways Selective Response Actions is a new Preview feature in Microsoft Defender for Endpoint that gives organizations better control over security response actions during device onboarding. It helps IT and security teams apply high-impact actions more carefully on Tier-0 systems and other important devices, improving protection while maintaining operational stability. New Selective Response Actions […]

AC Anoop C Nair 3 min read