Note
Access to this page requires authorization. You can try signing in or changing directories.
Access to this page requires authorization. You can try changing directories.
Microsoft Defender Vulnerability Management is now part of Microsoft Security Exposure Management. For more details, see the following note.
Note
The Vulnerability Management section in the Microsoft Defender portal is now located under Exposure management. With this change, you can now consume and manage security exposure data and vulnerability data in a unified location, to enhance your existing Vulnerability Management features. Learn more.
These changes are relevant for Preview customers (Microsoft Defender XDR + Microsoft Defender for Identity preview option).
Note
To use this feature, you need either Microsoft Defender Vulnerability Management Standalone or the Defender Vulnerability Management add-on for Microsoft Defender for Endpoint Plan 2.
This article explains how network share configuration assessment in Microsoft Defender Vulnerability Management identifies weak share configurations and surfaces security recommendations you can act on.
Network shares let users access shared files, documents, and media across the network. Because these shares are open to many users, they often have security gaps that attackers can exploit.
When Defender Vulnerability Management finds a weak share setup, it adds a fix to the Security recommendations page. These recommendations help you secure your network shares:
- Disallow offline access to shares
- Remove shares from the root folder
- Remove share write permission set to 'Everyone'
- Set folder enumeration for shares
Tip
Did you know you can try all the features in Microsoft Defender Vulnerability Management for free? Find out how to start a free trial of Microsoft Defender Vulnerability Management.
Find information about exposed network shares
To view network share recommendations:
In the Microsoft Defender portal, do one of the following:
- Preview customers using Microsoft Defender XDR and Defender for Identity: Select Exposure management > Recommendations.
- Existing customers: Select Endpoints > Vulnerability management > Recommendations.
Select Filters, then choose Related component > OS > Shares.
Select Apply.
If vulnerable network shares are detected, they appear in the recommendations list on the Security recommendations page.
Select a recommendation to open a flyout pane with details about the weak share setup:
Use the Exposed devices and Exposed shares tabs to see which assets are at risk.
Request remediation for the network share configuration
In the recommendation details flyout pane, you can view and submit a remediation request from the Remediation options tab:
View configuration remediation activities
On the Remediation page, filter by remediation type Configuration change to find the activity item for your network share configuration change.