Microsoft 365 Defender for Business not updating exposed devices

Guillem Albert 0 Reputation points
2023-07-28T10:19:40.89+00:00

Dear all,

I have been working with Microsoft 365 Defender for Business for several months now in synchronization with Microsoft Intune.

I have been mitigating vulnerabilities through packet updates (Google Chrome, Adobe Acrobat and so on) with any issue with it.

Moreover, I know Windows 10, 11, Office, Edge and Teams updates deploy slow but automatically.

My main concern is that until now, all automatic updates were installed and the exposed devices in Defender slowly went down from all exposed devices to 0.

However, since last big zero-day update form Windows 10 and 11 (around 11th of July), the exposed devices number from these vulnerabilities doesn't change.

I can surely affirm, some devices are updated due to automatic or manual update done by myself.

It has been two weeks since then but number of exposed devices keeps the same.

Any help with this issue would be kindly appreciated.

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
11,052 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,766 questions
Microsoft Intune Updates
Microsoft Intune Updates
Microsoft Intune: A Microsoft cloud-based management solution that offers mobile device management, mobile application management, and PC management capabilities.Updates: Broadly released fixes addressing specific issue(s) or related bug(s). Updates may also include new or modified features (i.e. changing default behavior).
90 questions
Microsoft Defender for Identity
Microsoft Defender for Identity
A Microsoft service that helps protect enterprise hybrid environments from multiple types of advanced, targeted cyberattacks and insider threats.
175 questions
0 comments No comments
{count} votes

1 answer

Sort by: Most helpful
  1. Limitless Technology 44,096 Reputation points
    2023-07-31T11:06:56.4533333+00:00

    Hello,

    If you are experiencing issues with Microsoft 365 Defender for Business not updating the exposed devices count after the Windows 10 and 11 zero-day update around 11th of July, there are a few troubleshooting steps you can try to resolve the problem:

    Verify Microsoft 365 Defender Data Sync: Ensure that the data sync between Microsoft 365 Defender and Microsoft Intune is functioning correctly. Check the synchronization logs and settings to confirm that data is being updated and shared properly between the two services.

    Check Vulnerability Scan Settings: Review the vulnerability scan settings in Microsoft 365 Defender to ensure that the scans are being performed regularly and accurately. Verify that the scan schedules and configurations are appropriate for your organization's needs.

    Check Endpoint Status and Connection: Verify that the affected devices are properly connected to Microsoft 365 Defender and Intune. Check the status of the devices in both platforms to see if there are any connectivity issues or errors.

    Force Vulnerability Scan: Consider manually initiating a vulnerability scan on specific devices to check if the exposed devices count updates correctly. This can help determine if the issue is related to the automatic scanning process.

    Review Update Deployment Policies: Check the update deployment policies in Microsoft Intune to ensure that they are correctly configured. Verify that the policies are targeting the appropriate devices and updates are being deployed as expected.

    Check Update Status on Devices: On the devices that are not getting updated in Microsoft 365 Defender, manually check for updates and confirm that they are successfully installed. This will help identify if the issue lies with the update process on specific devices.

    Check for Software Conflicts: Investigate if there are any third-party security software or applications on the devices that might be interfering with Microsoft 365 Defender's update process. Temporarily disable such software to test if they are causing the problem.

    Review Event Logs and Logs from Intune: Examine the event logs on the affected devices and the logs from Intune for any error messages or warnings related to update deployments. This might provide insights into the cause of the issue.

    Contact Microsoft Support: If the problem persists and you are unable to identify the root cause, consider reaching out to Microsoft Support for further assistance. They can analyze specific logs and configurations to help troubleshoot the issue.

    It's important to address any potential issues with updating exposed devices promptly to maintain the security and health of your organization's devices. Regularly checking for updates and maintaining proper configurations in Microsoft 365 Defender and Intune can help ensure that devices are protected against vulnerabilities.

    I used AI provided by ChatGPT to formulate part of this response. I have verified that the information is accurate before sharing it with you.

    Hope this resolves your Query !!

    --If the reply is helpful, please Upvote and Accept it as an answer–

    0 comments No comments