{
    "api_version": "1",
    "kind": "dse_post",
    "self": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
    "item": {
        "id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
        "slug": "dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes",
        "url": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
        "alternate_urls": {
            "markdown": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes.md",
            "json": "https://update.dsesecurity.com/api/v1/posts/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/"
        },
        "title": "Bound Defender certificate inventory to the Windows machine stores it observes",
        "summary": "What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?",
        "format": {
            "slug": "explainer",
            "name": "Explainer"
        },
        "priority": {
            "slug": "info",
            "name": "Information"
        },
        "featured": false,
        "image": {
            "theme": "network-infrastructure",
            "label": "Networks & infrastructure",
            "alt": "Resilient network core with engineered blue and gold data paths.",
            "card_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-card.webp?v=1.8.20",
            "hero_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-hero.webp?v=1.8.20",
            "social_url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
            "width": 2400,
            "height": 1350
        },
        "topics": [
            {
                "slug": "cybersecurity",
                "name": "Cybersecurity",
                "url": "https://update.dsesecurity.com/topic/cybersecurity/"
            },
            {
                "slug": "it",
                "name": "IT",
                "url": "https://update.dsesecurity.com/topic/it/"
            }
        ],
        "author": {
            "name": "DSE Security Editorial Team",
            "url": "https://update.dsesecurity.com/#editorial-team",
            "type": "Organization"
        },
        "publisher": {
            "name": "Detection Systems & Engineering",
            "url": "https://dsesecurity.com/"
        },
        "published_at": "2026-09-10T00:22:32+00:00",
        "modified_at": "2026-09-10T02:14:31+00:00",
        "reviewed_on": "2026-09-09",
        "reading_minutes": 2,
        "word_count": 248,
        "potentially_affected": "Microsoft Defender Vulnerability Management certificate inventory on Windows devices.",
        "dse_recommendation": "Reconcile the inventory's local-machine-store coverage before using it as an organizational certificate register.",
        "primary_source": {
            "name": "Certificate inventory in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
            "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory",
            "published_on": null,
            "authority": "Microsoft Learn"
        },
        "publishing_principles": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
        "usage_info": "https://update.dsesecurity.com/usage/",
        "copyright_notice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
        "content_html": "<h2>Source facts</h2>\n<p>Defender Vulnerability Management certificate inventory displays certificates discovered in Windows devices&#8217; local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<p>The expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. <a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn</a>.</p>\n<h2>Applicability</h2>\n<p>Use this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory&#8217;s asserted coverage. Do not infer their absence from an empty result.</p>\n<h2>DSE recommendation</h2>\n<p>DSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.</p>\n<h2>Verification</h2>\n<p>Compare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.</p>\n<h2>Official references</h2>\n<p><a href=\"https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory\" target=\"_blank\" rel=\"noopener noreferrer\">Microsoft Learn: Certificate inventory</a>.</p>",
        "content_text": "Source facts\nDefender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. Microsoft Learn.\nThe expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. Microsoft Learn.\nApplicability\nUse this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.\nDSE recommendation\nDSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.\nVerification\nCompare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.\nOfficial references\nMicrosoft Learn: Certificate inventory.",
        "content_markdown": "## Source facts\n\nDefender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory).\n\nThe expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory).\n\n## Applicability\n\nUse this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.\n\n## DSE recommendation\n\nDSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.\n\n## Verification\n\nCompare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.\n\n## Official references\n\n[Microsoft Learn: Certificate inventory](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory)."
    },
    "json_ld": {
        "@context": "https://schema.org",
        "@graph": [
            {
                "@type": "Organization",
                "@id": "https://dsesecurity.com/#organization",
                "name": "Detection Systems & Engineering",
                "alternateName": "DSE Security",
                "url": "https://dsesecurity.com/",
                "logo": {
                    "@type": "ImageObject",
                    "url": "https://update.dsesecurity.com/assets/dse-logo-20260812.png?v=1.8.20"
                }
            },
            {
                "@type": "Organization",
                "@id": "https://update.dsesecurity.com/#editorial-team",
                "name": "DSE Security Editorial Team",
                "url": "https://update.dsesecurity.com/",
                "parentOrganization": {
                    "@id": "https://dsesecurity.com/#organization"
                }
            },
            {
                "@type": "WebSite",
                "@id": "https://update.dsesecurity.com/#website",
                "name": "DSE Updates",
                "alternateName": "DSE Security Knowledge Hub",
                "url": "https://update.dsesecurity.com/",
                "inLanguage": "en-US",
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "potentialAction": {
                    "@type": "SearchAction",
                    "target": {
                        "@type": "EntryPoint",
                        "urlTemplate": "https://update.dsesecurity.com/?q={search_term_string}"
                    },
                    "query-input": "required name=search_term_string"
                }
            },
            {
                "@type": "WebPage",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
                "isPartOf": {
                    "@id": "https://update.dsesecurity.com/#website"
                },
                "lastReviewed": "2026-09-09"
            },
            {
                "@type": "BreadcrumbList",
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/#breadcrumbs",
                "itemListElement": [
                    {
                        "@type": "ListItem",
                        "position": 1,
                        "name": "DSE Updates",
                        "item": "https://update.dsesecurity.com/"
                    },
                    {
                        "@type": "ListItem",
                        "position": 2,
                        "name": "Bound Defender certificate inventory to the Windows machine stores it observes",
                        "item": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/"
                    }
                ]
            },
            {
                "@type": [
                    "Article",
                    "TechArticle"
                ],
                "@id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/#article",
                "identifier": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
                "url": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/",
                "headline": "Bound Defender certificate inventory to the Windows machine stores it observes",
                "description": "What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?",
                "abstract": "What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?",
                "articleBody": "Source facts\nDefender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. Microsoft Learn.\nThe expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. Microsoft Learn.\nApplicability\nUse this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.\nDSE recommendation\nDSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.\nVerification\nCompare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.\nOfficial references\nMicrosoft Learn: Certificate inventory.",
                "datePublished": "2026-09-10T00:22:32+00:00",
                "dateModified": "2026-09-10T02:14:31+00:00",
                "mainEntityOfPage": {
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/"
                },
                "inLanguage": "en-US",
                "isAccessibleForFree": true,
                "author": {
                    "@type": "Organization",
                    "name": "DSE Security Editorial Team",
                    "url": "https://update.dsesecurity.com/#editorial-team"
                },
                "publisher": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "image": {
                    "@type": "ImageObject",
                    "@id": "https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/#primaryimage",
                    "url": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "contentUrl": "https://update.dsesecurity.com/assets/editorial/network-infrastructure-social-v2.jpg?v=1.8.20",
                    "width": 1200,
                    "height": 630,
                    "caption": "Bound Defender certificate inventory to the Windows machine stores it observes"
                },
                "articleSection": [
                    "Cybersecurity",
                    "IT"
                ],
                "keywords": [
                    "Cybersecurity",
                    "IT",
                    "Explainer",
                    "Information priority"
                ],
                "genre": "Explainer",
                "about": [
                    {
                        "@type": "Thing",
                        "name": "Cybersecurity",
                        "url": "https://update.dsesecurity.com/topic/cybersecurity/"
                    },
                    {
                        "@type": "Thing",
                        "name": "IT",
                        "url": "https://update.dsesecurity.com/topic/it/"
                    }
                ],
                "wordCount": 248,
                "timeRequired": "PT2M",
                "publishingPrinciples": "https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/",
                "usageInfo": "https://update.dsesecurity.com/usage/",
                "copyrightHolder": {
                    "@id": "https://dsesecurity.com/#organization"
                },
                "copyrightNotice": "Copyright © 2026 Detection Systems & Engineering. All rights reserved.",
                "citation": {
                    "@type": "CreativeWork",
                    "name": "Certificate inventory in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn",
                    "url": "https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory"
                }
            }
        ]
    }
}