ExplainerInformationCybersecurityIT

Bound Defender certificate inventory to the Windows machine stores it observes

What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?

Resilient network core with engineered blue and gold data paths.
DSE visual intelligenceNetworks & infrastructureExplainer · 2 min read
Executive summary

What you need to know

What does Defender Vulnerability Management certificate inventory establish, and which certificate locations remain outside it?

Potentially affected

Microsoft Defender Vulnerability Management certificate inventory on Windows devices.

DSE recommendation

Reconcile the inventory's local-machine-store coverage before using it as an organizational certificate register.

Source facts

Defender Vulnerability Management certificate inventory displays certificates discovered in Windows devices’ local machine certificate stores. Its inventory view includes issuer, expiration, key size and instance counts. The installed-devices view identifies machines holding a selected certificate and can export that device list. Microsoft Learn.

The expiration widget reports certificates already expired or approaching expiry within thirty, sixty or ninety days. Advanced hunting can query certificate information through DeviceTvmCertificateInfo. These are documented inventory capabilities, not a claim that every organizational certificate location is observed. Microsoft Learn.

Applicability

Use this review where Microsoft Defender Vulnerability Management certificate inventory is available for Windows devices. Keep certificates outside Windows local machine stores outside this inventory’s asserted coverage. Do not infer their absence from an empty result.

DSE recommendation

DSE recommends attaching the observation boundary to every exported certificate report. Match an expiring certificate to its installed devices before assigning a renewal task; ask the service owner to confirm actual use separately. Maintain an explicit reconciliation list for other certificate locations instead of labeling the Defender result a complete enterprise register. Treat the widget as a queue for investigation, not approval to remove a certificate.

Verification

Compare selected records with the corresponding Windows local machine stores and check the reported device associations. Follow a known certificate through the inventory and its installed-devices export. Record missing or unexpected instances for investigation, and preserve the separate evidence used to identify the dependent service before scheduling renewal or removal.

Official references

Microsoft Learn: Certificate inventory.

Primary reference

Review the official source

Certificate inventory in Microsoft Defender Vulnerability Management - Microsoft Defender Vulnerability Management | Microsoft Learn · Verified September 9, 2026

Open official reference ↗
Plan the next step

Need help applying this guidance safely?

DSE can help confirm applicability, protect service continuity, and validate the result across physical security and IT systems.

Talk with DSE