A cloud-native solution that protects workloads across hybrid and multi-cloud environments with threat detection and security recommendations
Defender Vulnerability Management – Browser Extensions inventory shows "No Data" tenant-wide (GCC High)
Environment
- Cloud: Microsoft 365 GCC High (portal: security.microsoft.us)
- Product: Microsoft Defender for Endpoint Plan 2 with Defender Vulnerability Management
- Onboarded devices: affected: all
- Endpoint OS: Windows 11; browsers in scope: Edge, Chrome, Firefox
Problem Description
The Browser extensions tab (Vulnerability management > Inventories > Browser extensions) displays "No Data" for the entire tenant. All other Vulnerability Management areas populate normally — software inventory, security recommendations, weaknesses, etc— confirming devices are onboarded, healthy, and sending telemetry, and that DVM licensing is being recognized by the service.
Expected Behavior
Browser extensions assessment is a documented DVM premium capability supported in GCC High. With DVM licenses applied and Windows devices running Edge/Chrome/Firefox with extensions installed, the Browser extensions inventory should populate.
Troubleshooting
- Verified DVM licenses are active and assigned in the tenant.
- Confirmed affected devices are onboarded, active, and healthy in device inventory.
- Confirmed endpoints have Edge/Chrome/Firefox installed with extensions present.
- Verified all other DVM inventories/assessments populate normally.
- Advanced Hunting query "DeviceTvmBrowserExtensions | take 1" returns query error indicating that extension telemetry may not be reaching the backend
Reference
This symptom matches a Microsoft-acknowledged known issue in the commercial cloud. In Microsoft Q&A thread "Defender for Endpoint Vulnerability Management Browser Extensions not populating" (Jan 2025, https://learn.microsoft.com/en-us/answers/questions/2141608/), a Microsoft moderator confirmed after consulting the Product Group that browser extension and hardware/firmware data not populating was a known backend issue reported by many customers, that engineering had identified it, and that a fix was being deployed globally to all tenants. We are seeing identical behavior in our GCC High tenant.