# Bound Defender certificate inventory to the Windows machine stores it observes

> What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?

- Canonical URL: https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/
- Publisher: Detection Systems & Engineering (DSE Security)
- Author: DSE Security Editorial Team
- Published: 2026-09-10T00:22:32+00:00
- Modified: 2026-09-10T02:14:31+00:00
- Last reviewed by DSE: 2026-09-09
- Resource type: Explainer
- DSE priority: Information
- Topics: Cybersecurity, IT
- Reading time: 2 minutes

## What you need to know

What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?

## Potentially affected

Microsoft Defender Vulnerability Management certificate inventory on Windows devices.

## DSE recommendation

Reconcile the inventory's local-machine-store coverage before using it as an organizational certificate register.

## Article

## Source facts

Defender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory).

The expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. [Microsoft Learn](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory).

## Applicability

Use this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.

## DSE recommendation

DSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.

## Verification

Compare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.

## Official references

[Microsoft Learn: Certificate inventory](https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory).

## Primary reference

- Name: Certificate inventory in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn
- Authority: Microsoft Learn
- URL: https://learn.microsoft.com/en-us/defender-vulnerability-management/tvm-certificate-inventory
- Source publication date: Not stated by the source

## Citation and use

Preferred citation: “Bound Defender certificate inventory to the Windows machine stores it observes,” DSE Security, https://update.dsesecurity.com/updates/dse-20260909-564-bound-defender-certificate-inventory-to-the-windows-machine-stores-it-observes/
Publishing principles: https://update.dsesecurity.com/updates/dse-updates-editorial-methodology/
Usage and citation policy: https://update.dsesecurity.com/usage/
Copyright © 2026 Detection Systems & Engineering. All rights reserved.
