Bulk exemption/suppression for SoftwareUpdate recommendations in Defender for Cloud

KAMADA, MIZUHO 20 Reputation points
2026-06-03T02:57:16.4433333+00:00

We are currently experiencing a large volume of recommendations related to software updates (SoftwareUpdate) in Microsoft Defender for Cloud.

Background:

Due to a recent behavior change in Defender for Cloud, recommendations are now generated per individual software component (such as libraries) within container images, instead of per container image.

As a result, a large number of similar "Update ~" recommendations are continuously being generated.

Current handling:

We are currently applying exemptions manually via Azure Portal, based on recommendation titles such as "Update ~".

However, new software components (libraries) continue to be detected, which results in new recommendations being generated.

This has led to a repetitive situation where exemptions must be applied continuously.

Issue:

Even after applying exemptions for existing recommendations, similar recommendations continue to be generated for newly detected software components.

As a result, we are facing significant operational overhead, including repeated manual exemption and PIM-related procedures.

Additional context:

These software update recommendations are already managed through regular maintenance processes by our application/vendor teams.

Therefore, from an operational standpoint, these recommendations are considered low-priority and are generating excessive alert noise.

Questions:

  1. Is there any way to apply exemptions in bulk for similar types of recommendations (e.g., Software Update-related recommendations), rather than handling them individually?
  2. Is it possible to define rule-based or policy-based exclusion (for example, by recommendation type, category, or assessment ID)?
  3. Are there any recommended best practices from Microsoft for handling scenarios where recommendations are generated per software component (library level)?
  4. Is there any current or planned feature that enables bulk exemption, suppression, or filtering for this kind of use case?

We would appreciate your guidance on how to effectively manage and suppress such alert noise while maintaining an appropriate security posture.


Note:

This inquiry has been translated into English using generative AI for communication purposes.

While we have tried to ensure accuracy, there may be minor nuances that differ from the original intent.

If anything is unclear, please feel free to ask for clarification.

(Original intent: We would like to confirm whether bulk or rule-based suppression of Software Update recommendations is possible, due to the increasing operational burden caused by repeated manual exemptions.)

Microsoft Security | Microsoft Defender | Microsoft Defender for Cloud

Answer accepted by question author

AI answer

2026-06-03T02:57:35.58+00:00
  1. Bulk exemptions for similar SoftwareUpdate recommendations

Yes. With the new individual-recommendation model, exemptions and governance are applied at the security category level instead of per single recommendation. For SoftwareUpdate-type findings (including per‑library container vulnerabilities), bulk handling is done by targeting the SoftwareUpdate recommendation category:

  • Go to Defender for Cloud → Environment settings → Exemptions.
  • Select + Create.
  • Choose the scope (management group, subscription, or specific resource).
  • Choose exemption type (Mitigated or Waiver).
  • On the recommendations step, select Recommendation category instead of individual recommendations.
  • Select the relevant category (for software update–style findings, this is typically the SoftwareUpdate category used by the new per‑component recommendations).

This applies to all current and future individual recommendations in that category at the chosen scope, which removes the need to exempt each new “Update ~” recommendation manually.

  1. Rule‑ or policy‑based exclusion by type/category/assessment

Yes, at the management plane level this is done via:

  • Exemptions by recommendation category (as above), which effectively act as rule‑based exclusions for all assessments in that category at the selected scope.
  • Governance rules scoped to a security category instead of a single grouped recommendation key. Governance rules can set ownership and automation consistently for all individual recommendations of that category.

The transition to individual recommendations explicitly changes the scoping model so that Governance rules, Continuous export, and Exemptions now target a security category, and each category automatically includes all current and future individual recommendations of that type.

This provides the rule‑like behavior requested: once the category is selected, new assessments of that type are automatically covered without additional manual action.

  1. Recommended practices for per‑component (library‑level) recommendations

From the documented transition guidance:

  • Use individual recommendations for investigation and remediation, but manage them at scale via security categories rather than per‑assessment keys.
  • Define an internal operating model for the transition period, including:
    • Prioritizing Critical and High risk individual recommendations in daily operations.
    • Using aggregation views to scale remediation and investigation.
    • Using filters and tags so operational teams see only the model and categories they actively work on.

For low‑priority SoftwareUpdate recommendations that are already handled by existing patch/maintenance processes, the recommended pattern is:

  • Apply category‑level exemptions (Mitigated or Waiver) at an appropriate scope so they do not affect secure score or appear as unhealthy/noisy.
  • Keep high‑risk or business‑critical scopes un‑exempted so that important software update findings still surface.
  1. Current or planned features for bulk exemption/suppression/filtering

The following capabilities are already available and are the supported way to handle this scenario:

  • Individual recommendations + security categories: grouped recommendations are being deprecated in favor of individual ones, but management actions (Governance rules, Continuous export, Exemptions) are explicitly designed to work at the category level to avoid per‑finding manual work.
  • Exemptions at scale: the Exemptions experience in Environment settings → Exemptions is designed for bulk creation at management group, subscription, or resource scope, including by Recommendation category. This automatically covers future recommendations of the same type.

Additionally, the release notes highlight that older grouped container vulnerability recommendations are being deprecated and replaced by the new individual format, and explicitly advise customers to update queries, automation, governance rules, or workflows to use individual recommendations and security categories instead. This aligns with using category‑level exemptions and governance rules as the long‑term solution for bulk suppression and management.

Summary for the described use case

  • To stop repeated manual exemptions for “Update ~” SoftwareUpdate recommendations, configure Exemptions and/or Governance rules at the SoftwareUpdate security category level for the relevant scopes.
  • Use Mitigated or Waiver exemptions at scale so these low‑priority findings no longer impact secure score or operational noise, while still allowing high‑priority categories or scopes to remain fully monitored.

References:

AI-generated content may be incorrect. Read our transparency notes for more information.

Was this answer helpful?

1 person found this answer helpful.

1 additional answer

Sort by: Oldest
  1. VEMULA SRISAI 14,065 Reputation points Microsoft External Staff Moderator
    2026-06-03T04:14:01.1233333+00:00

    KAMADA, MIZUHO Thank you for the detailed context — this behavior is expected with the recent change where Defender for Cloud generates recommendations at the individual software component (library/CVE) level, which increases the volume of “Update” recommendations.

    Regarding your questions:

    1. Bulk exemption – Yes, you can create exemptions at scale by defining a single exemption at the subscription or management group level, and applying it to specific recommendations or recommendation categories. This exemption applies to both existing and future resources within that scope.
    2. Rule-based exclusion – Currently, Defender for Cloud supports exemptions by recommendation/category and also provides disable rules for vulnerability findings (e.g., based on CVE, severity, image, OS), but it does not support fully dynamic rules to automatically suppress all newly generated sub‑assessments (e.g., all SoftwareUpdate-type findings).
    3. Best practice – For container/software update noise, Microsoft recommends:
    • Applying exemptions at a broader scope (management group/subscription) instead of per-resource
    • Using category-based exemptions where possible
    • Leveraging disable rules (e.g., filter by severity or known CVEs) to reduce noise
      • Periodically reviewing exemptions to ensure they remain valid This is important because container vulnerability findings are continuously generated as new libraries and CVEs are detected.
    1. Feature availability – At this time, there is *no built-in capability to automatically suppress all future recommendations of a certain pattern (e.g., “Update”) at the sub-assessment level. The closest supported approach is combining scope-based exemptions + disable rules.

    Was this answer helpful?

    2 people found this answer helpful.

Your answer

Answers can be marked as 'Accepted' by the question author and 'Recommended' by moderators, which helps users know the answer solved the author's problem.