{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
        "slug": "dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/"
        },
        "title": "Interpret vulnerability exceptions without reporting excluded exposure as repaired",
        "summary": "What changes in Defender Vulnerability Management after an exception is applied?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "cyber-defense",
            "label": "Cyber defense",
            "alt": "Layered glass and metal cyber-defense structure with controlled blue and gold signal paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:25:03+00:00",
        "modified_at": "2026-09-10T02:04:57+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 264,
        "potentially_affected": "Defender Vulnerability Management recommendation or CVE exceptions in the Microsoft Defender portal.",
        "dse_recommendation": "Reconcile exception-adjusted reporting with the unchanged remediation obligation before explaining a score movement.",
        "primary_source": {
            "name": "Create, view, and manage exceptions in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management can except an entire recommendation or an individual CVE. Applying an exception can suppress associated threat analytics and alerts and change exposure or secure scores. Microsoft allows up to an hour for exposed-asset counts and exposure-score changes to process. An exception&#8217;s duration cannot be extended; continuing beyond expiry requires another exception. The documented management surface is the Defender portal, not a public API. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Identify the exception type, authorized device-group or global scope, duration and operator&#8217;s exception-handling permission. Microsoft distinguishes preview navigation from existing-customer navigation; this brief does not require adopting the preview interface. For recommendation reporting, compare the explicit after-exceptions columns rather than assuming every displayed count uses the same basis.</p>\n<h2>DSE recommendation</h2>\n<p>Reconcile exception-adjusted reporting with the unchanged remediation obligation before explaining a score movement. Label the decision as an exclusion with its reason and affected scope, not as a completed software correction. Ask the detection owner to assess the documented suppression consequence before approval. Plan a fresh decision at expiry rather than promising an extension of the existing object. Preserve the pre-exception view alongside the adjusted result for management reporting.</p>\n<h2>Verification</h2>\n<p>Following an approved exception, allow for the documented processing interval and inspect its scope, state and adjusted counts. Confirm that the reporting explanation identifies excluded items separately from repaired ones. At cancellation or expiry, review the current recommendation or CVE and the outstanding action owner. Investigate discrepancies between report columns before interpreting a lower number as a reduction in underlying vulnerability.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Create, view, and manage exceptions</a>. Source reviewed September 9, 2026.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management can except an entire recommendation or an individual CVE. Applying an exception can suppress associated threat analytics and alerts and change exposure or secure scores. Microsoft allows up to an hour for exposed-asset counts and exposure-score changes to process. An exception’s duration cannot be extended; continuing beyond expiry requires another exception. The documented management surface is the Defender portal, not a public API. Microsoft Learn.\nApplicability\nIdentify the exception type, authorized device-group or global scope, duration and operator’s exception-handling permission. Microsoft distinguishes preview navigation from existing-customer navigation; this brief does not require adopting the preview interface. For recommendation reporting, compare the explicit after-exceptions columns rather than assuming every displayed count uses the same basis.\nDSE recommendation\nReconcile exception-adjusted reporting with the unchanged remediation obligation before explaining a score movement. Label the decision as an exclusion with its reason and affected scope, not as a completed software correction. Ask the detection owner to assess the documented suppression consequence before approval. Plan a fresh decision at expiry rather than promising an extension of the existing object. Preserve the pre-exception view alongside the adjusted result for management reporting.\nVerification\nFollowing an approved exception, allow for the documented processing interval and inspect its scope, state and adjusted counts. Confirm that the reporting explanation identifies excluded items separately from repaired ones. At cancellation or expiry, review the current recommendation or CVE and the outstanding action owner. Investigate discrepancies between report columns before interpreting a lower number as a reduction in underlying vulnerability.\nOfficial references\nMicrosoft Learn: Create, view, and manage exceptions. Source reviewed September 9, 2026.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management can except an entire recommendation or an individual CVE. Applying an exception can suppress associated threat analytics and alerts and change exposure or secure scores. Microsoft allows up to an hour for exposed-asset counts and exposure-score changes to process. An exception’s duration cannot be extended; continuing beyond expiry requires another exception. The documented management surface is the Defender portal, not a public API. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception).\n\n## Applicability\n\nIdentify the exception type, authorized device-group or global scope, duration and operator’s exception-handling permission. Microsoft distinguishes preview navigation from existing-customer navigation; this brief does not require adopting the preview interface. For recommendation reporting, compare the explicit after-exceptions columns rather than assuming every displayed count uses the same basis.\n\n## DSE recommendation\n\nReconcile exception-adjusted reporting with the unchanged remediation obligation before explaining a score movement. Label the decision as an exclusion with its reason and affected scope, not as a completed software correction. Ask the detection owner to assess the documented suppression consequence before approval. Plan a fresh decision at expiry rather than promising an extension of the existing object. Preserve the pre-exception view alongside the adjusted result for management reporting.\n\n## Verification\n\nFollowing an approved exception, allow for the documented processing interval and inspect its scope, state and adjusted counts. Confirm that the reporting explanation identifies excluded items separately from repaired ones. At cancellation or expiry, review the current recommendation or CVE and the outstanding action owner. Investigate discrepancies between report columns before interpreting a lower number as a reduction in underlying vulnerability.\n\n## Official references\n\n[Microsoft Learn: Create, view, and manage exceptions](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception). Source reviewed September 9, 2026."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Interpret vulnerability exceptions without reporting excluded exposure as repaired",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/",
                "headline": "Interpret vulnerability exceptions without reporting excluded exposure as repaired",
                "description": "What changes in Defender Vulnerability Management after an exception is applied?",
                "abstract": "What changes in Defender Vulnerability Management after an exception is applied?",
                "articleBody": "Source facts\nDefender Vulnerability Management can except an entire recommendation or an individual CVE. Applying an exception can suppress associated threat analytics and alerts and change exposure or secure scores. Microsoft allows up to an hour for exposed-asset counts and exposure-score changes to process. An exception’s duration cannot be extended; continuing beyond expiry requires another exception. The documented management surface is the Defender portal, not a public API. Microsoft Learn.\nApplicability\nIdentify the exception type, authorized device-group or global scope, duration and operator’s exception-handling permission. Microsoft distinguishes preview navigation from existing-customer navigation; this brief does not require adopting the preview interface. For recommendation reporting, compare the explicit after-exceptions columns rather than assuming every displayed count uses the same basis.\nDSE recommendation\nReconcile exception-adjusted reporting with the unchanged remediation obligation before explaining a score movement. Label the decision as an exclusion with its reason and affected scope, not as a completed software correction. Ask the detection owner to assess the documented suppression consequence before approval. Plan a fresh decision at expiry rather than promising an extension of the existing object. Preserve the pre-exception view alongside the adjusted result for management reporting.\nVerification\nFollowing an approved exception, allow for the documented processing interval and inspect its scope, state and adjusted counts. Confirm that the reporting explanation identifies excluded items separately from repaired ones. At cancellation or expiry, review the current recommendation or CVE and the outstanding action owner. Investigate discrepancies between report columns before interpreting a lower number as a reduction in underlying vulnerability.\nOfficial references\nMicrosoft Learn: Create, view, and manage exceptions. Source reviewed September 9, 2026.",
                "datePublished": "2026-09-10T00:25:03+00:00",
                "dateModified": "2026-09-10T02:04:57+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-413-interpret-vulnerability-exceptions-without-reporting-excluded-exposure-as-repaired/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/cyber-defense-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Interpret vulnerability exceptions without reporting excluded exposure as repaired"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 264,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Create, view, and manage exceptions in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-exception"
                }
            }
        ]
    }
}