Skip to content

Security Recommendations

The Security Recommendations page provides a comprehensive list of security improvement actions for your Azure environment, sourced from Microsoft Defender for Cloud and Microsoft Defender XDR.

At the top of the page, a Security Indicators Panel displays key security metrics:

MetricDescription
Secure ScoreCurrent security score percentage with 30-day difference indicator
Unhealthy ResourcesCount of unhealthy resources out of total resources monitored
Passed ControlsNumber of controls passed from the Cloud Security Benchmark
Active RecommendationsCount of active recommendations affecting your Secure Score

The page provides a detailed breakdown view of your Secure Score across five categories:

CategoryDescription
InfrastructureInfrastructure-related security posture score
AppsApplication security score
IdentityIdentity and access management score
DataData protection and encryption score
DevicesDevice security score

Each category displays:

  • Current score percentage
  • 30-day difference (improvement or decline)
  • Count of active recommendations

When the customerIncludeM365SecurityFeature feature flag is enabled, a Microsoft 365 consent banner appears at the top of the page, allowing you to grant permissions for M365 security features.

The main recommendations grid displays comprehensive information for each security recommendation:

ColumnDescription
StatusCurrent status: Completed, Failed, or Not Applicable
Recommendation NameClickable link to open the recommendation profile page
SeverityRisk level: High, Medium, or Low
Unhealthy ResourcesCount of affected resources and resource types
EffortEstimated remediation effort: High, Medium, or Low
User ImpactWhether remediation will impact users: Yes or No
Cost ImpactWhether remediation will impact costs: Yes or No
Compliance Control IDsAssociated compliance control identifiers (e.g., CIS Controls)
Potential Score IncreaseEstimated Secure Score points gained upon remediation
TasksNumber of associated tasks

Scope filters are required and determine which recommendations are displayed:

ScopeDescription
Secure Score: InfrastructureInfrastructure-related recommendations (default)
Secure Score: AppsApplication security recommendations
Secure Score: IdentityIdentity and access management recommendations
Secure Score: DataData protection recommendations
Secure Score: DevicesDevice security recommendations
Cloud Security BenchmarkRecommendations aligned with Cloud Security Benchmark
CIS M365 Foundations BenchmarkCIS M365 Foundations Benchmark recommendations

Refine your view using these optional filters:

FilterOptions
StatusCompleted, Failed, Not Applicable
SeverityLow, Medium, High
EffortLow, Medium, High
User ImpactYes, No
Cost ImpactYes, No

Organize recommendations by different dimensions:

Grouping OptionDescription
ControlGroup by compliance control (default when scope is set)
CategoryGroup by recommendation category
SeverityGroup by risk severity level
EffortGroup by remediation effort level
SubscriptionGroup by Azure subscription (not available for M365)
Resource GroupGroup by Azure resource group (not available for M365)
Resource TypeGroup by resource type
ProductGroup by product (not available for M365)
No GroupingDisplay as flat list

Available actions for managing recommendations:

ActionDescription
Create TaskCreate tasks for selected recommendations (bulk action supported)
Mute/UnmuteTemporarily hide recommendations or restore muted items
ExportExport recommendations in various formats:
• Datagrid Excel export
• Inventory export
• Download Questionnaire (MSP-only)
Import RecommendationsImport recommendations from external sources (MSP-only)
Share ReportEmail security report to stakeholders
Download ReportDownload security report in PDF or other formats
Show MutedToggle visibility of muted recommendations

Clicking on a recommendation name opens a detailed profile page with the following sections:

  • Recommendation name
  • Status badge (Completed/Failed/Not Applicable)
  • Back button to return to recommendations list
  • Editable properties (MSP only)
  • Key recommendation metadata
  • Detailed description of the security issue
  • Associated compliance controls and CIS Controls
  • Step-by-step instructions for addressing the recommendation
  • Best practices and guidance

Navigate between different resource states:

TabDescription
UnhealthyResources that need remediation
HealthyResources that already meet the recommendation
Not ApplicableResources where the recommendation doesn’t apply
MutedResources where the recommendation has been muted
TasksAssociated remediation tasks

For each resource, the grid displays:

ColumnDescription
Resource NameResource icon and clickable link
Resource TypeType of Azure resource
SubscriptionAzure subscription name
DataAdditional resource metadata
StateCurrent resource state
Mute UntilMute expiration date (if muted)
TasksAssociated tasks

Available actions from the recommendation profile:

  • Edit Properties - Modify recommendation properties (MSP only)
  • Create Task - Create a new remediation task
  • Mute/Unmute Resources - Mute or restore specific resources
  • Share - Share the recommendation profile
  • Export - Export resource details

The Security Recommendations feature uses the following routes:

  • /security/recommendations - Main recommendations list page
  • /security/recommendations/:code - Recommendation profile page
  • /security/recommendations/:code/resource - Resource-specific view

The following feature flags control Security Recommendations functionality:

  • BI_ANALYTICS - Enables BI analytics integration
  • CAN_VIEW_SECURITY_INVENTORY - Controls access to security inventory views
  • SECURITY - Main security feature flag
  • TASKS - Enables task management features

Security Recommendations Dashboard