What you need to know
What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?
Potentially affected
Microsoft Defender Vulnerability Management certificate inventory on Windows devices.
DSE recommendation
Reconcile the inventory's local-machine-store coverage before using it as an organizational certificate register.
Source facts
Defender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. Microsoft Learn.
The expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. Microsoft Learn.
Applicability
Use this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.
DSE recommendation
DSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.
Verification
Compare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.
Official references
Review the official source
Certificate inventory in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn · Verified September 9, 2026
Need help applying this guidance safely?
DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.
Talk with DSE