Forum Discussion

AppleJax's avatar
AppleJax
Copper Contributor
Apr 23, 2025

Secure Score - Vulnerability Exceptions Not Registering

I have followed the guide to configure the proper permissions to manage within Defender. Device groups have been created based off tags we applied to the devices, and the device groups register the expected number of devices.

We apply an exception to the vulnerability recommendation based off the device group, looking at the individual device pages we can confirm the recommendation is excluded and it all appears to work as intended up to this point.

The problem starts on the vulnerability dashboard. The recommendation shows it is in partial exception status however none of the statistics or data reflect this including our secure score.

I can confirm making a global exception works as expected and we can see the score adjust properly.

Has anyone experienced this before or have any pointers? We have been working at this for weeks trying different things without luck, we are ensuring to leave adequate sync times.

 

1 Reply

  • abonsol24's avatar
    abonsol24
    Copper Contributor

    Hello - according to this https://learn.microsoft.com/en-us/defender-xdr/microsoft-secure-score-improvement-actions#recommended-action-status-for-devices from Microsoft, secure score will not update unless its a Global exception.  We just went through the same process as you to find out device group has no impact to the score... :(

Resources