Remediate a vulnerability

  1. Open Vulnerabilities and filter by SLA status — start with Breached, then Due soon. Click a finding to see which devices are exposed.
  2. Before dispatching anything, sanity-check the fix in Setup > Setup Health > Pre-flight: pick the same vulnerability, device, and channel, and run the gate without actually dispatching. A clean result reads “Cleared — this remediation could proceed (no blocking checks).” If it isn’t clean, fix what it flags first.
  3. From the vulnerability’s device list, dispatch a fix. PatchPilot picks the fastest channel the finding actually supports:

    Channel Typical time to complete
    Defender Live Response Seconds
    Win32 / Intune app deployment 5–15 minutes
    Intune Expedited Quality Update Hours

    Coverage comes from the Winget or Chocolatey catalog, or an engineer-uploaded Script Catalog entry. Some findings have nothing to dispatch at all — see Known Issues.

  4. Track progress on Jobs — status, target devices, and channel used. A single job can close more than one CVE at once when one package fix covers several findings.
  5. Once the job completes, the finding drops off Vulnerabilities on the next sync and appears in Remediation History, attributed to the device, technician, and job that closed it.
  6. If a finding can’t be fixed at all (a bundled library, a misconfiguration, no matching package), record a local exception instead of leaving it to keep breaching SLA — note in Known Issues that this only suppresses it inside PatchPilot, not in Defender itself.

This site uses Just the Docs, a documentation theme for Jekyll.