Edit

Assess network share configurations in Microsoft Defender Vulnerability Management

Microsoft Defender Vulnerability Management is now part of Microsoft Security Exposure Management. For more details, see the following note.

Note

The Vulnerability Management section in the Microsoft Defender portal is now located under Exposure management. With this change, you can now consume and manage security exposure data and vulnerability data in a unified location, to enhance your existing Vulnerability Management features. Learn more.

These changes are relevant for Preview customers (Microsoft Defender XDR + Microsoft Defender for Identity preview option).

Note

To use this feature, you need either Microsoft Defender Vulnerability Management Standalone or the Defender Vulnerability Management add-on for Microsoft Defender for Endpoint Plan 2.

This article explains how network share configuration assessment in Microsoft Defender Vulnerability Management identifies weak share configurations and surfaces security recommendations you can act on.

Network shares let users access shared files, documents, and media across the network. Because these shares are open to many users, they often have security gaps that attackers can exploit.

When Defender Vulnerability Management finds a weak share setup, it adds a fix to the Security recommendations page. These recommendations help you secure your network shares:

  • Disallow offline access to shares
  • Remove shares from the root folder
  • Remove share write permission set to 'Everyone'
  • Set folder enumeration for shares

Tip

Did you know you can try all the features in Microsoft Defender Vulnerability Management for free? Find out how to start a free trial of Microsoft Defender Vulnerability Management.

Find information about exposed network shares

To view network share recommendations:

  1. In the Microsoft Defender portal, do one of the following:

    • Preview customers using Microsoft Defender XDR and Defender for Identity: Select Exposure management > Recommendations.
    • Existing customers: Select Endpoints > Vulnerability management > Recommendations.
  2. Select Filters, then choose Related component > OS > Shares.

    Options for filtering on network shares

  3. Select Apply.

If vulnerable network shares are detected, they appear in the recommendations list on the Security recommendations page.

Network shares configuration recommendations

Select a recommendation to open a flyout pane with details about the weak share setup:

Network shares configuration recommendation details

Use the Exposed devices and Exposed shares tabs to see which assets are at risk.

Request remediation for the network share configuration

In the recommendation details flyout pane, you can view and submit a remediation request from the Remediation options tab:

Network shares configuration remediation options

View configuration remediation activities

On the Remediation page, filter by remediation type Configuration change to find the activity item for your network share configuration change.