A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
- Bulk exemptions for similar SoftwareUpdate recommendations
Yes. With the new individual-recommendation model, exemptions and governance are applied at the security category level instead of per single recommendation. For SoftwareUpdate-type findings (including per‑library container vulnerabilities), bulk handling is done by targeting the SoftwareUpdate recommendation category:
- Go to Defender for Cloud → Environment settings → Exemptions.
- Select + Create.
- Choose the scope (management group, subscription, or specific resource).
- Choose exemption type (Mitigated or Waiver).
- On the recommendations step, select Recommendation category instead of individual recommendations.
- Select the relevant category (for software update–style findings, this is typically the SoftwareUpdate category used by the new per‑component recommendations).
This applies to all current and future individual recommendations in that category at the chosen scope, which removes the need to exempt each new “Update ~” recommendation manually.
- Rule‑ or policy‑based exclusion by type/category/assessment
Yes, at the management plane level this is done via:
- Exemptions by recommendation category (as above), which effectively act as rule‑based exclusions for all assessments in that category at the selected scope.
- Governance rules scoped to a security category instead of a single grouped recommendation key. Governance rules can set ownership and automation consistently for all individual recommendations of that category.
The transition to individual recommendations explicitly changes the scoping model so that Governance rules, Continuous export, and Exemptions now target a security category, and each category automatically includes all current and future individual recommendations of that type.
This provides the rule‑like behavior requested: once the category is selected, new assessments of that type are automatically covered without additional manual action.
- Recommended practices for per‑component (library‑level) recommendations
From the documented transition guidance:
- Use individual recommendations for investigation and remediation, but manage them at scale via security categories rather than per‑assessment keys.
- Define an internal operating model for the transition period, including:
- Prioritizing Critical and High risk individual recommendations in daily operations.
- Using aggregation views to scale remediation and investigation.
- Using filters and tags so operational teams see only the model and categories they actively work on.
For low‑priority SoftwareUpdate recommendations that are already handled by existing patch/maintenance processes, the recommended pattern is:
- Apply category‑level exemptions (Mitigated or Waiver) at an appropriate scope so they do not affect secure score or appear as unhealthy/noisy.
- Keep high‑risk or business‑critical scopes un‑exempted so that important software update findings still surface.
- Current or planned features for bulk exemption/suppression/filtering
The following capabilities are already available and are the supported way to handle this scenario:
- Individual recommendations + security categories: grouped recommendations are being deprecated in favor of individual ones, but management actions (Governance rules, Continuous export, Exemptions) are explicitly designed to work at the category level to avoid per‑finding manual work.
- Exemptions at scale: the Exemptions experience in Environment settings → Exemptions is designed for bulk creation at management group, subscription, or resource scope, including by Recommendation category. This automatically covers future recommendations of the same type.
Additionally, the release notes highlight that older grouped container vulnerability recommendations are being deprecated and replaced by the new individual format, and explicitly advise customers to update queries, automation, governance rules, or workflows to use individual recommendations and security categories instead. This aligns with using category‑level exemptions and governance rules as the long‑term solution for bulk suppression and management.
Summary for the described use case
- To stop repeated manual exemptions for “Update ~” SoftwareUpdate recommendations, configure Exemptions and/or Governance rules at the SoftwareUpdate security category level for the relevant scopes.
- Use Mitigated or Waiver exemptions at scale so these low‑priority findings no longer impact secure score or operational noise, while still allowing high‑priority categories or scopes to remain fully monitored.
References: