Vulnerability Remediation Agent
A Security Copilot agent in the Microsoft Intune admin center that evaluates Microsoft Defender Vulnerability Management data for Intune-managed devices, prioritises CVEs and produces step-by-step remediation guidance. Microsoft states the agent takes no action on devices.
Recorded characteristics
- Function
- Microsoft documents that the agent performs automated evaluations that collect vulnerability data from Microsoft Defender Vulnerability Management, analyse and prioritise CVEs across Intune-managed devices using factors such as CVSS score, exposure impact and device count, and generate step-by-step remediation instructions tailored to Intune capabilities, including policy recommendations and settings catalog configuration guidance. The agent also maintains records of suggested remediations and lets administrators track applied solutions over time. Microsoft states explicitly that the agent takes no action on devices: remediation is carried out by an administrator using Intune.
- Data access
- Microsoft documents that the agent reads vulnerability data from Microsoft Defender Vulnerability Management, including Common Vulnerabilities and Exposures (CVEs) across managed devices, CVSS-based severity classification (Low, Medium, High, Critical), exposure impact based on the Defender Vulnerability Management exposure score, and counts of affected and exposed devices. It also reads Intune data through the Microsoft Intune plugin, with the agentic user requiring read permissions for mobile apps and device configurations. Associated CVE counts cover Windows client operating system editions and exclude Windows Server editions, and the exposed device list includes only devices found in Microsoft Entra that are not Windows Server editions.
- Actions
- Read only
- External actions
- Unknown
- Human confirmation
- Not required
- Permission basis
- Dedicated agent identity
- Administrative control
- Microsoft documents that setting up and managing the agent requires an Intune Read Only Operator role (or a custom role with Security Tasks, Mobile apps, Device configurations and Organization read permissions) together with the Security Copilot Copilot owner role. The agentic user must be separately delegated Intune read permissions in Microsoft Entra and Defender permissions equivalent to the Unified RBAC Security Reader role in the Microsoft Defender admin center. Administrators use the Run Readiness Check button to verify delegated permissions, which enables the Run button and the option to schedule runs. Other documented controls include agent setup (Set up Agent / Start agent), manual runs started only from the Intune admin center, creating a new agentic identity, and removing the agent, which deletes the agentic identity and its agentic user. Security Copilot logs record agent management actions such as create, delete and run, and permission failures. Microsoft states the agent does not support scope tags in public preview, and that administrators who access the Intune admin center may see agent-reported data outside their assigned Intune roles or scope.
- Default state
- Disabled
- Availability
- Microsoft labels the capability public preview. It supports only the public cloud and does not support government clouds. Evaluation and recommendations are supported for Windows and for apps in Intune. The Microsoft Intune and Microsoft Defender plugins are required. Until all required permissions are delegated to the agentic user and the Run Readiness Check passes, agent runs are disabled.
- Licensing
- Microsoft documents that using Security Copilot agents in Intune requires a Microsoft Intune Plan 1 subscription, Microsoft Security Copilot with sufficient security compute units (SCUs), and Microsoft Defender Vulnerability Management provided by Microsoft Defender for Endpoint P2 or Defender Vulnerability Management Standalone. Agent runs can fail due to insufficient SCUs. The agentic user must be licensed unless the tenant setting allowing admins without an Intune license is enabled.
- External model or provider
- Not established
- Limitations and uncertainty
- Microsoft does not identify a specific underlying model or provider for this agent, so model and provider are not established. The capability is in public preview and its behaviour may change. Microsoft states the agent takes no action on devices and that marking a suggestion as applied is an administrator self-attestation that does not trigger any device change, so no policy creation, policy assignment, configuration change, or application or update deployment by the agent is established. Microsoft states an admin must manually start the agent and that it can be started only from within the Intune admin center, while the readiness check section states that a successful check enables the Run button and the option to schedule runs; the exact scheduling controls and cadence are not documented. Data scope is limited: CVE counts and exposed device lists exclude Windows Server editions. Scope tags are not supported in public preview. Whether the agent performs any action outside Intune is not documented, so external action capability is recorded as unknown rather than no.
Evidence
- Vulnerability Remediation Agent in Microsoft Intune
Supports: Function · Data access · Actions · External actions · Human confirmation · Permission basis · Admin controls · Default state · Availability · Licensing · Limitations · Primary source
The agent uses data from Defender Vulnerability Management to identify CVEs on managed devices; results are prioritised for remediation and include step-by-step instructions to guide the administrator in using Intune to remediate the threat. Documented workflow: data collection, analysis and prioritisation, remediation guidance, tracking and reporting.
The agent collects vulnerability data from Defender Vulnerability Management, analysing CVEs across managed devices and prioritising by CVSS score, exposure impact and device count; CVE counts and exposed device lists exclude Windows Server editions.
Remediation guidance is instructional: the agent provides step-by-step remediation instructions tailored to Intune capabilities, including policy recommendations and configuration guidance, and maintains records of suggested remediations for tracking.
Documentation describes reading Defender Vulnerability Management data and presenting guidance in the Intune admin center; no action taken outside Intune is documented.
An admin must manually start the agent, and the agent can be started only from within the Intune admin center; after a successful readiness check the Run button and the option to schedule runs are enabled.
The agent uses a Microsoft Entra agentic identity: during setup it provisions an agentic identity and corresponding agentic user in the tenant directory, and runs under the permissions delegated to that agentic user rather than under a human user account; behaviour is limited to the permissions and scope tag assigned to the agentic user.
Setup and management require Intune Read Only Operator (or custom read role) plus the Security Copilot Copilot owner role; the agentic user must be delegated Intune read permissions and Defender permissions equivalent to Unified RBAC Security Reader in the Entra and Defender admin centers; Run Readiness Check verifies delegation; agents can be removed, which deletes the agentic identity and agentic user; scope tags are not supported in public preview.
Until all required permissions are delegated to the agentic user, agent runs are disabled; required permissions must be assigned and the Run Readiness Check passed before the agent can run. The agent must also be explicitly set up in the Intune admin center.
Feature is in public preview; supports only the public cloud and not government clouds; supports Windows and apps in Intune; requires the Microsoft Intune and Microsoft Defender plugins.
Requires Microsoft Intune Plan 1, Microsoft Security Copilot with sufficient security compute units, and Defender Vulnerability Management via Defender for Endpoint P2 or Defender Vulnerability Management Standalone; the agentic user must be licensed unless admins without an Intune license are allowed.
Public preview; CVE counts cover Windows client editions only and exclude Windows Server; exposed device list includes only non-Windows-Server devices found in Entra; scope tags unsupported in preview; agent runs cannot be stopped or paused; admins in the Intune admin center may see agent-reported data outside their assigned roles or scope.
- Use the Vulnerability Remediation Agent
Supports: Function · Data access · Actions · Human confirmation · Permission basis · Admin controls · External model · Limitations · Primary source
The agent uses AI-powered analysis to identify and prioritise vulnerabilities across managed devices and provides step-by-step remediation guidance through the Intune admin center; suggestions include impact, exposed devices, suggested actions and a Configurations section of recommended settings catalog settings.
Suggestions expose remediation type, impact from the Defender Vulnerability Management exposure score, exposed device counts, status and last applied user account.
Microsoft states the agent takes no action on devices; an admin drills into a reported vulnerability to review and deploy the suggested remediation, and marking a suggestion as applied is a self-attestation that does not trigger device changes. Suggestions persist with Not applied or Applied status and a Last marked as applied timestamp and serve as a baseline for later runs.
The agent runs until evaluation completes and cannot be stopped or paused; no per-item approval of its analysis is documented, and any actual remediation is performed by an administrator.
The agent runs under its agentic identity, and operations are limited to the permissions delegated to the agentic user.
Administrators manage the agent from Overview, Suggestions and Settings tabs, view and manage identity options, run the readiness check, start runs, and review run activity; Security Copilot logs record create, delete and run actions and permission failures.
Microsoft describes AI-powered analysis but does not identify the underlying model or provider for this agent.
Runs can fail due to insufficient security compute units; agent logs exclude discovered vulnerabilities and applied-remediation records; suggestions reflect the latest data at each run and may change between runs.
- Security Copilot in Microsoft Intune
Supports: Function · Primary source
Security Copilot integrates with Microsoft Intune, providing the Copilot platform surface in which the Intune agents operate.
- Microsoft Defender Vulnerability Management
Supports: Data access · Primary source
Microsoft Defender Vulnerability Management is the Microsoft service providing the vulnerability data consumed by the agent.
- Understand authentication in Microsoft Security Copilot
Supports: Permission basis · Primary source
Security Copilot role documentation underlying the Copilot owner role required to set up and manage the agent.
- What is Microsoft Security Copilot?
Supports: Licensing · Primary source
Microsoft Security Copilot platform documentation covering the Security Copilot service and its capacity model.