Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Configure Microsoft Defender for Endpoint to send email notifications to specified recipients for new vulnerability events. This feature lets you identify a group of people who are informed right away and can act based on the event that triggered the notification rule. Vulnerability event data comes from Microsoft Defender Vulnerability Management.
If you're using Defender for Business, you can set up vulnerability notifications for specific users only (not roles or groups).
Note
- Only users with
Manage security settingspermissions can configure email notifications. If you've chosen to use basic permissions management, users with an appropriate role, such as Security Administrator, can configure email notifications. User roles and permission options - Device group creation is supported in Defender for Endpoint Plan 1 and Plan 2.
Email notification rules allow you to set the vulnerability events that trigger notifications, and add or remove email notification recipients. New recipients get notified about vulnerabilities after the recipients are added.
If you're using role-based access control (RBAC), recipients only get notifications for device groups set in the matching notification rule. Users with the right permission can only create, edit, or delete notifications within their device group scope. Only users with an admin role, such as Security Administrator, can manage rules for all device groups.
The email notification includes basic information about the vulnerability event. The notification also includes links to filtered views in the Microsoft Defender portal: the Security recommendations page and the Weaknesses page, so you can investigate further. For example, you could get a list of all exposed devices or get additional details about the vulnerability.
Important
Microsoft recommends that you use roles with the fewest permissions. This helps improve security for your organization. Global Administrator is a highly privileged role that should be limited to emergency scenarios when you can't use an existing role.
Create vulnerability email notification rules
Create a rule to send an email when certain exploit or vulnerability events occur, such as a new public exploit. You can select multiple event types for each rule.
Sign in to the Microsoft Defender portal using an account with the Security Administrator role assigned.
In the navigation pane, go to Settings > Endpoints > General > Email notifications > Vulnerabilities.
Select Add notification rule.
Name the email notification rule and include a description.
Check Activate notification rule. Select Next
Fill in the notification settings. Then select Next
If you're using Defender for Endpoint, choose device groups to get notifications for. (If you're using Defender for Business, device groups don't apply.)
Choose the vulnerability event(s) that you want to be notified about when they affect your organization:
New vulnerability found (including severity threshold)
Note
This includes newly detected zero-day vulnerabilities and patches released for existing zero-day vulnerabilities. For more information, see patching zero-day vulnerabilities.
Exploit was verified
New public exploit
Exploit added to an exploit kit
Include organization name if you want the organization name in the email.
Enter the recipient email address then select Add. You can add multiple email addresses.
Review the settings for the new email notification rule and select Create rule when you're ready to create it.
Edit a vulnerability email notification rule
Make sure you have permission to edit the rule before you begin.
From the list of notification rules, select the rule you want to edit.
Select the Edit rule button next to the pencil icon in the flyout.
Delete a vulnerability email notification rule
Make sure you have permission to delete the rule before you begin.
From the list of notification rules, select the rule you want to delete.
Select the Delete button next to the trash can icon in the flyout.
Troubleshoot email notifications for alerts
If vulnerability email notifications aren't working as expected, use the following guidance to resolve common issues.
Problem: Intended recipients report they aren't getting the notifications.
Solution: Make sure that the notifications aren't blocked by email filters:
Check that the Defender for Endpoint email notifications aren't sent to the Junk Email folder. Mark them as Not junk.
Check that your email security product isn't blocking the email notifications from Defender for Endpoint.
Check your email application rules that might be catching and moving your Defender for Endpoint email notifications.
Related articles
For more information, see the following articles: