Remediate a vulnerability
- Open Vulnerabilities and filter by SLA status — start with Breached, then Due soon. Click a finding to see which devices are exposed.
- Before dispatching anything, sanity-check the fix in Setup > Setup Health > Pre-flight: pick the same vulnerability, device, and channel, and run the gate without actually dispatching. A clean result reads “Cleared — this remediation could proceed (no blocking checks).” If it isn’t clean, fix what it flags first.
-
From the vulnerability’s device list, dispatch a fix. PatchPilot picks the fastest channel the finding actually supports:
Channel Typical time to complete Defender Live Response Seconds Win32 / Intune app deployment 5–15 minutes Intune Expedited Quality Update Hours Coverage comes from the Winget or Chocolatey catalog, or an engineer-uploaded Script Catalog entry. Some findings have nothing to dispatch at all — see Known Issues.
- Track progress on Jobs — status, target devices, and channel used. A single job can close more than one CVE at once when one package fix covers several findings.
- Once the job completes, the finding drops off Vulnerabilities on the next sync and appears in Remediation History, attributed to the device, technician, and job that closed it.
- If a finding can’t be fixed at all (a bundled library, a misconfiguration, no matching package), record a local exception instead of leaving it to keep breaching SLA — note in Known Issues that this only suppresses it inside PatchPilot, not in Defender itself.