Microsoft · Microsoft Intune

Vulnerability Remediation Agent

A Security Copilot agent in the Microsoft Intune admin center that evaluates Microsoft Defender Vulnerability Management data for Intune-managed devices, prioritises CVEs and produces step-by-step remediation guidance. Microsoft states the agent takes no action on devices.

Recorded characteristics

Function
Microsoft documents that the agent performs automated evaluations that collect vulnerability data from Microsoft Defender Vulnerability Management, analyse and prioritise CVEs across Intune-managed devices using factors such as CVSS score, exposure impact and device count, and generate step-by-step remediation instructions tailored to Intune capabilities, including policy recommendations and settings catalog configuration guidance. The agent also maintains records of suggested remediations and lets administrators track applied solutions over time. Microsoft states explicitly that the agent takes no action on devices: remediation is carried out by an administrator using Intune.
Data access
Microsoft documents that the agent reads vulnerability data from Microsoft Defender Vulnerability Management, including Common Vulnerabilities and Exposures (CVEs) across managed devices, CVSS-based severity classification (Low, Medium, High, Critical), exposure impact based on the Defender Vulnerability Management exposure score, and counts of affected and exposed devices. It also reads Intune data through the Microsoft Intune plugin, with the agentic user requiring read permissions for mobile apps and device configurations. Associated CVE counts cover Windows client operating system editions and exclude Windows Server editions, and the exposed device list includes only devices found in Microsoft Entra that are not Windows Server editions.
Actions
Read only
External actions
Unknown
Human confirmation
Not required
Permission basis
Dedicated agent identity
Administrative control
Microsoft documents that setting up and managing the agent requires an Intune Read Only Operator role (or a custom role with Security Tasks, Mobile apps, Device configurations and Organization read permissions) together with the Security Copilot Copilot owner role. The agentic user must be separately delegated Intune read permissions in Microsoft Entra and Defender permissions equivalent to the Unified RBAC Security Reader role in the Microsoft Defender admin center. Administrators use the Run Readiness Check button to verify delegated permissions, which enables the Run button and the option to schedule runs. Other documented controls include agent setup (Set up Agent / Start agent), manual runs started only from the Intune admin center, creating a new agentic identity, and removing the agent, which deletes the agentic identity and its agentic user. Security Copilot logs record agent management actions such as create, delete and run, and permission failures. Microsoft states the agent does not support scope tags in public preview, and that administrators who access the Intune admin center may see agent-reported data outside their assigned Intune roles or scope.
Default state
Disabled
Availability
Microsoft labels the capability public preview. It supports only the public cloud and does not support government clouds. Evaluation and recommendations are supported for Windows and for apps in Intune. The Microsoft Intune and Microsoft Defender plugins are required. Until all required permissions are delegated to the agentic user and the Run Readiness Check passes, agent runs are disabled.
Licensing
Microsoft documents that using Security Copilot agents in Intune requires a Microsoft Intune Plan 1 subscription, Microsoft Security Copilot with sufficient security compute units (SCUs), and Microsoft Defender Vulnerability Management provided by Microsoft Defender for Endpoint P2 or Defender Vulnerability Management Standalone. Agent runs can fail due to insufficient SCUs. The agentic user must be licensed unless the tenant setting allowing admins without an Intune license is enabled.
External model or provider
Not established
Limitations and uncertainty
Microsoft does not identify a specific underlying model or provider for this agent, so model and provider are not established. The capability is in public preview and its behaviour may change. Microsoft states the agent takes no action on devices and that marking a suggestion as applied is an administrator self-attestation that does not trigger any device change, so no policy creation, policy assignment, configuration change, or application or update deployment by the agent is established. Microsoft states an admin must manually start the agent and that it can be started only from within the Intune admin center, while the readiness check section states that a successful check enables the Run button and the option to schedule runs; the exact scheduling controls and cadence are not documented. Data scope is limited: CVE counts and exposed device lists exclude Windows Server editions. Scope tags are not supported in public preview. Whether the agent performs any action outside Intune is not documented, so external action capability is recorded as unknown rather than no.

Evidence