Teams talk about “our vulnerability scanner” as though the tenant owns one thing. It owns three. There is a score that measures how exploitable your devices are, and it goes down when you improve. There is a score that measures how well configured your estate is, and it goes up when you improve. And there is a third mechanism, newer than both, that scores your progress against named campaigns like ransomware or Zero Trust and derives from neither of the other two. Microsoft states plainly that two of them are calculated independently. I have watched more posture programs report the wrong number because nobody separated these three than for any other reason, and the separation is not a detail. It decides who owns which conversation.
Three instruments, and the direction each one runs
The exposure score belongs to Defender Vulnerability Management and measures how exposed your devices are to exploitation. It runs from zero to a hundred and lower is better, banded at zero to twenty-nine for low, thirty to sixty-nine for medium, and seventy upward for high. Microsoft Secure Score measures configuration posture across the whole tenant, is expressed in points, and higher is better. Underneath it sits a device-scoped instrument confusingly named Microsoft Secure Score for Devices, which is fed by the same product that produces the exposure score and still runs in the opposite direction to it. The documentation is unambiguous about the relationship: exposure score and Secure Score for Devices are calculated independently, and changes to how one behaves do not change the other. Software update recommendations move the exposure score. Configuration recommendations move Secure Score for Devices. One product, two outputs, no arithmetic connecting them.
The third instrument is the initiative score inside Microsoft Security Exposure Management, and it is a different kind of object again. An initiative is a named programme, ransomware or business email compromise or Zero Trust or a per-workload set, and its score is a percentage rollup of weighted metrics rather than a derivation from either score above. Nothing feeds anything. What the three share is substrate, not arithmetic: the exposure graph, a unified recommendations catalog, and asset criticality. Since November 2025 that shared substrate has widened, with cloud security posture management from Defender for Cloud and vulnerability management presented together in one recommendations surface. Convergence in this product is structural. It is not, and has never been announced as, a merger of the numbers.
Two of the three run in opposite directions, and Microsoft says in writing that they are calculated independently. Any dashboard that adds them is lying to somebody.
The practical consequence is that these three answer to different people. The exposure score is an operational number owned by whoever patches. Secure Score is a governance number that leaves the security team and reaches an audit committee, which is a different discipline and the subject of its own article later in this block. The initiative scores are programme management, useful to whoever has to say how the ransomware project is going. Handing all three to the same weekly meeting without saying which is which produces the meeting where the exposure score fell, Secure Score fell, and nobody can say whether that was a good week.
What Defender Vulnerability Management actually contains
The product splits into a core tier and a premium add-on, and the split is worth knowing precisely because half the disappointment I encounter in the field is somebody expecting a premium capability from a core licence. Core, which arrives with Defender for Endpoint Plan 2 and therefore with Microsoft 365 E5, is nine capabilities: device discovery, device inventory, vulnerability assessment, configuration assessment, risk-based prioritization, remediation tracking, continuous monitoring, software inventory, and software usage insights. That is a complete vulnerability management programme. It finds the machines, enumerates what is on them, assesses both their patch state and their configuration, ranks the findings, and tracks the work.
Premium is exactly six things, and every one of them is a specialist assessment rather than a better version of the core: baseline assessments against CIS and STIG benchmarks, block vulnerable applications, browser extensions assessment, digital certificate assessment, network share analysis, and hardware and firmware assessment. Notice what that list is. It is not “the good vulnerability management”. It is a set of surfaces the core does not look at, plus one enforcement action. If nothing on that list describes a risk you are actually carrying, the add-on is not a gap in your programme, and I would rather a client spend the money on the remediation capacity to act on what core already tells them.
The premium features also carry narrower platform scopes than their names imply, which is the sort of thing you want to know before you buy rather than after. Baseline assessments are Windows only. Digital certificate assessment reads the local machine certificate store on Windows devices and nowhere else. Hardware and firmware assessment collects inventory across Windows, Linux and macOS, but the weaknesses it reports derive from HP, Dell and Lenovo advisories covering processors and BIOS, and it does not report on Apple silicon at all. Block vulnerable applications is Windows only, and it has a dependency that matters more than the platform: it works by generating file indicators on the vulnerable executables, and indicator enforcement requires Defender Antivirus in active mode. Passive mode cannot enforce it, and neither can endpoint detection and response in block mode. If you took the position in the protection engine article that a third-party antivirus stays primary, you have already decided you cannot use this feature.
The licensing edges, which are sharper than the marketing
Core rides Plan 2, so every Plan 2 vehicle carries it: Microsoft 365 E5 and its academic and government equivalents, Windows Enterprise E5, standalone Plan 2, and the security add-on that Microsoft renamed from Microsoft 365 E5 Security to the Microsoft Defender Suite effective October 2025. That rename is worth tracking because documentation lags it in both directions and you will meet both names in the same tenant’s paperwork. The important thing about the Suite is what it does not contain. It bundles Entra ID Plan 2, Defender for Identity, Defender for Office 365 Plan 2, Defender for Endpoint Plan 2 and Defender for Cloud Apps. The vulnerability management premium add-on is not in it. The Suite is a vehicle you can buy the add-on on top of, not a package that includes it.
Three other edges catch people. The standalone product exists for tenants without Plan 2 and is explicitly sold to run alongside any endpoint detection and response solution, which makes it the answer for an E3 estate or one that standardised on someone else’s agent. Defender for Servers Plan 2 includes all six premium capabilities natively for server devices, and the sentence people miss is the next one: client devices still require the add-on licence, so a tenant with excellent server coverage can have none of it on laptops. And Defender for Business includes the core capabilities but has no path to premium at all, because neither the add-on nor the standalone is available to it. That last one is not a gap you can buy your way out of, and for a business-premium client it is a genuine ceiling worth naming during design rather than discovering at renewal.
Then there is the trap that runs the other way, and it is my favourite in this suite because it inverts the one from the series anchor. Enterprise Mobility and Security E5 contains no Defender for Endpoint, therefore no vulnerability management, therefore no exposure score and no device data of any kind. But Enterprise Mobility and Security E5 is a full-access licence for Security Exposure Management, because it carries Defender for Identity and Defender for Cloud Apps and any one of those is sufficient. So that tenant opens Exposure Management, sees a working product populated with identity and software-as-a-service posture, sees attack paths drawn through its directory, and sees nothing at all about the vulnerability state of a single endpoint. The console does not look broken. It looks like a product with an empty section, which is a far more expensive kind of wrong.
What changed underneath a 2024-era understanding
Anyone who learned this product two years ago is now carrying at least four stale assumptions. The first is the exposure score itself, which was rebuilt and reached general availability in June 2026. The new model weights common vulnerability scoring with exploit prediction scoring rather than severity alone, combines every relevant vulnerability on an asset instead of over-weighting the worst one, and factors in whether the asset faces the internet and whether you have classified it as critical. The organisation score is now the average of asset scores. Microsoft does not publish the weighting, so print the factors and never the arithmetic.
The second is that the migration to that model is staged and, as I write this, unfinished. Two models are live across the tenant estate and the documentation says outright that depending on rollout stage your tenant might show either experience. There is no banner, no toggle, and no documented way to tell which one you are looking at. That has a governance consequence people are not braced for: your exposure score can move for reasons that have nothing to do with your environment, and your recommendation priorities can reorder underneath you. If you report this number to anyone who will hold you to it, say now, in writing, that the number is mid-migration.
The third is the Windows authenticated scan, which was deprecated with effect from December 2025 and has no replacement. Microsoft’s own guidance is to explore alternative solutions, which is as close to an admission as that phrase gets. If your design for unmanaged Windows assets rested on it, it needs rebuilding. What was not affected, and what people conflate with it constantly, is authenticated scanning of network devices over the simple network management protocol. That remains supported, so the network-device discovery story told in the device inventory article stands as published.
The fourth is the navigation, and this one needs stating carefully because it is the claim most often reported wrong. The capabilities are generally available: the unified recommendations catalog, cloud posture and vulnerability management presented in one place, the whole November 2025 integration. What is still in preview is the navigation migration for existing vulnerability management customers, so most tenants continue to reach the product where they always did while opted-in tenants see it relocated under Exposure Management with renamed pages. Microsoft manages to name two different preview programmes as the gate for this within two paragraphs of the same page, so if you go looking for the toggle, expect to meet both. Generally available capability, preview navigation. Those are separate sentences and collapsing them produces a claim that is wrong in one direction or the other.
The edges of this pillar
This block owns the aggregation story, which is to say it owns the question of how findings from every other pillar roll up into a number somebody reports. It does not re-teach the pillars themselves. Identity posture assessments belong to the identity block and software-as-a-service posture to the cloud apps block; here they appear only as inputs to a score. Device discovery is already built in the endpoint block. Cloud security posture management from Defender for Cloud now shares this console, and that adjacency is worth knowing, but Defender for Cloud is outside this series and stays outside it. The exposure graph is queryable through advanced hunting, and I will name the tables when we reach them without teaching the query language here, because that belongs to the capstone.
What comes next is the part of this pillar that is not about measurement at all. Every one of these instruments produces recommendations, and a recommendation is worth exactly nothing until somebody with the authority to change a device acts on it. That handoff, between the organisation that finds the problem and the organisation that fixes it, is the real subject of this block, and it starts at who owns the fix.
Defender XDR
‹ Previous: [D 5.3] Session Controls and Conditional Access App Control
Next: [D 6.1] Recommendations to Remediation: Who Owns the Fix ›




