{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
        "slug": "dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/"
        },
        "title": "Do not close security findings from Azure Advisor preview completion state",
        "summary": "Keep security-recommendation status separate from the preview lifecycle states supported for other Advisor categories.",
        "format": {
            "slug": "guide",
            "name": "Guide"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "networks-infrastructure",
                "name": "Networks & Infrastructure",
                "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:29:18+00:00",
        "modified_at": "2026-09-10T00:55:35+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 1,
        "word_count": 217,
        "potentially_affected": "Consumers of Azure Advisor recommendation state management, currently in preview.",
        "dse_recommendation": "Exclude unsupported security completion states from automatic closure logic and verify the underlying finding separately.",
        "primary_source": {
            "name": "Azure Advisor recommendation state management - Azure Advisor | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Azure Advisor recommendation state management is documented as preview. Full state management does not apply to security recommendations: only Active is supported for that category, not Completed, Postponed, or Dismissed.</p>\n<p>Microsoft warns that a security recommendation can nevertheless show Completed in the Advisor table in Azure Resource Graph. That value may not represent the actual status and should not be relied on. <a href=\"https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Review dashboards, exports, and ticket integrations that consume Advisor recommendation states. Identify the recommendation category before interpreting a state, and document the preview dependency in the integration&#8217;s operating record.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends a category-aware closure rule. Route an unsupported security completion value to an exception queue instead of automatically resolving the associated security work item. Ask the finding owner to verify the underlying condition and retain that evidence. Keep the original source value visible for diagnosis without presenting it as remediation proof.</p>\n<h2>Verification</h2>\n<p>Test the consumer with a security recommendation carrying Completed and confirm that the ticket stays open for review. Compare the behavior with an eligible nonsecurity category, without assuming the categories share lifecycle semantics. Verify that the report distinguishes an unsupported status from an independently checked resolution, and preserve the test payload and mapping version.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Azure Advisor recommendation state management</a>. Source retrieved September 9, 2026.</p>",
        "content_text": "Source facts\nAzure Advisor recommendation state management is documented as preview. Full state management does not apply to security recommendations: only Active is supported for that category, not Completed, Postponed, or Dismissed.\nMicrosoft warns that a security recommendation can nevertheless show Completed in the Advisor table in Azure Resource Graph. That value may not represent the actual status and should not be relied on. Microsoft Learn.\nApplicability\nReview dashboards, exports, and ticket integrations that consume Advisor recommendation states. Identify the recommendation category before interpreting a state, and document the preview dependency in the integration’s operating record.\nDSE recommendation\nDSE recommends a category-aware closure rule. Route an unsupported security completion value to an exception queue instead of automatically resolving the associated security work item. Ask the finding owner to verify the underlying condition and retain that evidence. Keep the original source value visible for diagnosis without presenting it as remediation proof.\nVerification\nTest the consumer with a security recommendation carrying Completed and confirm that the ticket stays open for review. Compare the behavior with an eligible nonsecurity category, without assuming the categories share lifecycle semantics. Verify that the report distinguishes an unsupported status from an independently checked resolution, and preserve the test payload and mapping version.\nOfficial references\nMicrosoft Learn: Azure Advisor recommendation state management. Source retrieved September 9, 2026.",
        "content_markdown": "## Source facts\n\nAzure Advisor recommendation state management is documented as preview. Full state management does not apply to security recommendations: only Active is supported for that category, not Completed, Postponed, or Dismissed.\n\nMicrosoft warns that a security recommendation can nevertheless show Completed in the Advisor table in Azure Resource Graph. That value may not represent the actual status and should not be relied on. [Microsoft Learn](https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management).\n\n## Applicability\n\nReview dashboards, exports, and ticket integrations that consume Advisor recommendation states. Identify the recommendation category before interpreting a state, and document the preview dependency in the integration’s operating record.\n\n## DSE recommendation\n\nDSE recommends a category-aware closure rule. Route an unsupported security completion value to an exception queue instead of automatically resolving the associated security work item. Ask the finding owner to verify the underlying condition and retain that evidence. Keep the original source value visible for diagnosis without presenting it as remediation proof.\n\n## Verification\n\nTest the consumer with a security recommendation carrying Completed and confirm that the ticket stays open for review. Compare the behavior with an eligible nonsecurity category, without assuming the categories share lifecycle semantics. Verify that the report distinguishes an unsupported status from an independently checked resolution, and preserve the test payload and mapping version.\n\n## Official references\n\n[Microsoft Learn: Azure Advisor recommendation state management](https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management). Source retrieved September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Do not close security findings from Azure Advisor preview completion state",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/",
                "headline": "Do not close security findings from Azure Advisor preview completion state",
                "description": "Keep security-recommendation status separate from the preview lifecycle states supported for other Advisor categories.",
                "abstract": "Keep security-recommendation status separate from the preview lifecycle states supported for other Advisor categories.",
                "articleBody": "Source facts\nAzure Advisor recommendation state management is documented as preview. Full state management does not apply to security recommendations: only Active is supported for that category, not Completed, Postponed, or Dismissed.\nMicrosoft warns that a security recommendation can nevertheless show Completed in the Advisor table in Azure Resource Graph. That value may not represent the actual status and should not be relied on. Microsoft Learn.\nApplicability\nReview dashboards, exports, and ticket integrations that consume Advisor recommendation states. Identify the recommendation category before interpreting a state, and document the preview dependency in the integration’s operating record.\nDSE recommendation\nDSE recommends a category-aware closure rule. Route an unsupported security completion value to an exception queue instead of automatically resolving the associated security work item. Ask the finding owner to verify the underlying condition and retain that evidence. Keep the original source value visible for diagnosis without presenting it as remediation proof.\nVerification\nTest the consumer with a security recommendation carrying Completed and confirm that the ticket stays open for review. Compare the behavior with an eligible nonsecurity category, without assuming the categories share lifecycle semantics. Verify that the report distinguishes an unsupported status from an independently checked resolution, and preserve the test payload and mapping version.\nOfficial references\nMicrosoft Learn: Azure Advisor recommendation state management. Source retrieved September 9, 2026.",
                "datePublished": "2026-09-10T00:29:18+00:00",
                "dateModified": "2026-09-10T00:55:35+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-158-do-not-close-security-findings-from-azure-advisor-preview-completion-state/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Do not close security findings from Azure Advisor preview completion state"
                },
                "articleSection": [
                    "Cybersecurity",
                    "Networks & Infrastructure"
                ],
                "keywords": [
                    "Cybersecurity",
                    "Networks & Infrastructure",
                    "Guide",
                    "Information priority"
                ],
                "genre": "Guide",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "Networks & Infrastructure",
                        "url": "https://update.dsesecurity.com/topic/networks-infrastructure/"
                    }
                ],
                "wordCount": 217,
                "timeRequired": "PT1M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Azure Advisor recommendation state management - Azure Advisor | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/azure/advisor/advisor-azure-state-management"
                }
            }
        ]
    }
}