Managing Windows Endpoints with Vulnerability Remediation and Telemetry

Finished patch deployment may leave endpoints vulnerable. Some applications may still be running old versions of the application, others may require a restart that has not yet occurred, and still others may have stopped reporting for a variety of reasons. Completed deployment and remediated vulnerability are not the same end state as managed endpoints.

But the real work here for IT leaders is correlating the vulnerability data from security tools to specific endpoints that belong to particular users. Also, the leader must verify that the update completed successfully, and consequently, caused no problems to the users who depend on that endpoint for their work. The end point management of Windows environments has gone through several evolutions lately (lifecycle management, hotpatching, AI for endpoint management, etc.). Thus, the end point management of Macs must be held to similar standards with corresponding tools and practices for the OS.

Prioritize vulnerabilities using exposure and business context

The inventory of endpoints that require a patch for a vulnerability to be removed must include all devices that are managed by the endpoint management system (including remote laptops) as well as shared devices (such as terminal servers and public area workstations) and unmanaged devices that are awaiting configuration (e.g. newly joined devices that have not yet had their application updated). Includes installed software applications (in addition to the OS), browsers (and associated extensions), and other software applications (such as VPN client software, collaboration software, remote management software, firmware and driver updates).

For example, software inventory can be expanded to include browsers, browser extensions, VPN clients, collaboration tools and remotes, as well as updates to drivers and firmware. Microsoft’s Microsoft Defender Vulnerability Management offers a variety of inventories related to software, browser extensions, hardware, and firmware. Coverage depends on the specific product and platform.

The exposure identified then has to be prioritized amongst other discovered exposures, using severity as only one of the deciding factors. The CVSS (Common Vulnerability Scoring System) will score a vulnerability for technical severity, but additional information is also needed such as whether the vulnerability is actively exploited in the wild by adversaries. Such information is published by CISA in their Known Exploited Vulnerabilities (KEV) catalog and by FIRST in their Exploit Prediction Scoring System (EPSS) which forecasts the likelihood of published vulnerabilities being exploited in the next 30 days.

However, the simple presence of low EPSS scores or even the absence of a vulnerability from the CISA KEV catalog does not by itself constitute “safe to ignore” vulnerabilities. We have to take into consideration a number of additional risk factors including the reach of the vulnerability on the local endpoint, the privileges that can be gained by a successful attack, and the number of sensitive business applications and resources affected by the endpoint.

When a vulnerability is found, set a remediation deadline. If it can’t be remediated in the specified time, record the reason for the delay, the compensating controls being used, the account holder for the endpoint, and the date when the accepted risk will expire.

Verify remediation on the device

It’s very important to clearly define the end state for each remediation. A fix may temporarily mitigate a vulnerability until a permanent fix is available, at which time the mitigation should be removed and verified to confirm it has been successfully removed. An accepted risk should be clearly documented and tracked until the underlying vulnerability has been fixed.

In the case of Windows updates, we must account for the download, installation, potential reboots, and re-launches of applications that run from within user-profiles as well as older versions of applications that are running side by-side with newer versions. Simple exit codes of installers aren’t closure. We need evidence of the end state of the endpoint, not the process of closure.

Following remediation, verify the desired end state. There’s a difference between a completed remediation and a successfully completed work order (completing a work order isn’t the end). Verify the End State including verifying the End State on offline devices (remediate, then physically go to device and reconnect). If different tools report different results (open vulnerabilities), investigate the circumstance and provide evidence to support Closure or Unresolved/Unknown status.

To complete a security task for a supported vulnerability using Microsoft’s Defender and Intune integration, the administrator of the affected endpoint still needs to manually complete the remediation and verify the updated vulnerability assessment information for the endpoint. Creation or acceptance of the task doesn’t automatically apply the fix to the endpoint.

Also when suspected exploitation occurs (as distinct from weaknesses that can be fixed by patching) an incident response decision is required to remove malware, investigate, contain, and recover credentials as well as remediate.

Collect telemetry that supports a decision

Operational data reported by a device or the device’s management tools are called endpoint telemetry. Operational data is useful only if there is sufficient detail on coverage, freshness, and ability to make a decision from the data.

Telemetry categoryUseful signalsDecision it supports
Employee experienceStartup duration, application crashes, resource pressureWhether a change is disrupting normal work
Management and configurationLast check-in, OS build, application versions, policy statusWhether a device is known, current, and configured as intended
Vulnerability and remediationAffected versions, assessment time, update result, restart statusWhat to fix and whether the fix is verified
SecurityEDR sensor health, detections, suspicious process activityWhether the device needs investigation or containment

The sources above answer different questions. Therefore, link Endpoint Detection and Response (EDR) security information with Management Telemetry that describes the configuration / deployment status of endpoints. Add a Digital Employee Experience (DEX) perspective to monitor the performance of end users.

The startup performance and application reliability of your users can be monitored by using the Microsoft Intune Endpoint Analytics. The analytics contain startup time and crashes per application over time for all your devices. With the analytics it’s possible to investigate whether a certain update has caused longer startup times or more application crashes. The affected device models and the corresponding Intune deployment groups should be compared to start the investigation as quickly as possible.

Freshness is its own measure. Endpoint Analytics data processing time and reporting time for instance are documented on the Endpoint Analytics data collection page. Use security or device query sources that provide current incident information as opposed to information that’s historical in nature.

Document who has access to the data collected in these sources, how long it’s stored, and what specific fields are needed to support each stated purpose. Communicate the reasons for collecting this information in your organization. Give reasonable access and storage to information that supports needed purposes with trade-off to collector burden.

Modernize Windows servicing and recovery

As the remediation effort approaches end of support, windows lifecycle management must be included in the review of remediation measures. Windows 10, version 22H2 reached end of support on October 14, 2025. Supports for Windows 10 versions can continue to receive Extended Security Updates (ESU) for specific security updates. ESU does not provide the same level of support as is available when a version of Windows is under full support. For LTSC editions of Windows 10, the dates for end of support for versions and releases are different.

It’s also important to treat the Extended Security Updates (ESU) for Windows 10 as a transitional measure, a component of a documented transition plan to consider potential issues with application support, hardware, and the window of time needed to identify and replace end-of-life servers and PCs. Don’t confuse being on the Windows 11-based versions of Windows with being on fully supported versions of Windows 11. There are supported releases and unsupported releases of Windows 11.

To support managed devices, Intune, ConfigMgr, or other solutions should be managed in the same way as the endpoints. In rings (for example a pilot with employees who test applications in real workflows), with clearly defined processes for deployment, detection of security fixes, and problems (with fast paths for urgent fixes), all monitored and controlled by a single owner (or owners in case of shared tools).

Hotpatching updates would be an interesting feature to test out on eligible Windows 11 devices. I read up on Microsoft’s approach to hotpatching supported security updates to the OS. The approach has several prerequisites, including an OS, licensing, management, and configuration layer. In the meantime, periodic “baseline updates” require a restart, but these can be released outside of regular scheduled updates. My take: beyond updating the OS for security updates, hotpatching updates also require recovery processes in place.

Automate updates and have a way to recover from failures like having support staff retrieve a BitLocker recovery key for a failed update. Monitor for reliability issues and have criteria to pause delivery of updates for a temporary fix while longer term fixes are developed. Also, be able to revert updates that cannot be uninstalled (such as repairing or re-imaging the device).

Apply Zero Trust and least privilege

Vulnerability patches need to be balanced with vulnerability mitigations, which are the settings that attempt to limit abuse of already-known problems in software. Ensure that all Windows endpoints are following desired configuration settings. Evaluate settings including local administrator group membership, encryption, firewalls, application control policies, and attack surface reduction policies. Test restrictions before enabling them broadly and be sure to provide for exceptions and document the owner and planned review date for each.

To ensure local administrator passwords for the Windows workstations on your premises are up-to-date and backed up, enable the Windows Local Administrator Password Solution (LAPS). You should also ensure all users work under standard user accounts and that approved and audited methods exist for elevated work that requires it.

Integrate the device reliability and security data from Microsoft Defender for Endpoint device risk into your device management processes. Configure Intune compliance policies and Microsoft Entra Conditional Access rules to restrict access to applications protected by the organization, on the basis of the configured requirements for the device. The Defender Conditional Access integration center contains additional information regarding this subject.

A compliance check only tests for whether a device complies with a set of policy-based rules. It does not automatically mean that all vulnerabilities have been fixed, or that a device is free from compromise. In addition, the scope of the policy, data freshness, and exception handling has to be thoroughly reviewed.

Automate where testable

Automation = reproduction of a test case. Very simple.

For this type of work a reinstallation of a management agent, a correction of known issues, updates of approved applications are good starting points. Once you detect an issue verify that same issue has gone away. Programmatically deal with the retry limits of a task and the necessary escalations.

Other features that can be tested for the administrator are AI assistance in explaining policies and analyzing data from devices. Use this assistance to shorten analysis, however verify generated scripts and in particular actions that affect a large number of devices, change permissions or write data. But validate your results because the AI can be wrong from time to time.

I agree that AI assistance should be used to shorten analysis and verify results. We would need to review generated scripts for compliance and ensure that they are tested for completeness in scenarios where they are deployed. The scope of work that AI is used to assist with would be important to review as well as the necessary processes and evidence needed to verify work was completed correctly on a device.

Similarly, all AI desktop applications and browser extensions should also go through the application approval process and update processes in place for other software. These will typically review the permissions that the application requires as well as the amount of organizational data that it has access to. Note that services that are accessed entirely through a browser (e.g. Netflix, Dropbox, etc.) typically require additional control around the browser itself (e.g. through existing identity and data controls) and aren’t captured in the installed software inventory.

Manage macOS updates and verification

For macOS, devices will need to have similar operational outcomes of managed ownership, up-to-date software, secure operation, and remediation. This would incorporate all applications (including cloud stores), browser extensions, use of FileVault, and health of any security agents running on the Macs.

Apple’s declarative device management allows you to declare the updates that need to be applied to devices as well as report on the status of the update installation. You can even report on the progress of each update installation and report on failures during the installation process. This can help to determine if an update was assigned to a device for installation and if the update was actually installed on the device. In some cases, it may help to identify why an update wasn’t installed on a device, like not enough free disk space on the device. As with all other management declarations, make sure the management platform you choose to go with supports the necessary declarations for the various OS versions that you will be supporting. Apple software update management.

Use the same risk criteria, exception owners for established cases and different application and deployment approaches for Windows and Macs. Test out your reports and associated workflows on each platform first though to get a true reading of capability.

Measure the exposure that remains

As with tracking also the endpoint management review should show the team whether vulnerable devices are becoming safer. The tracker should also be able to answer the question if employees are still able to work as expected.

  • % devices with current Management & Security health telemetry.
  • Number of unresolved device/vulnerability pairs where exploitation is known, and the length of time these have been open.
  • Median and 95th-percentile time to remediate a detected issue, as well as age of open issues.
  • Devices awaiting a restart, missing updates, or covered by an expiring exception.
  • Application failures and support incidents caused by endpoints management, and their root-cause analysis and respective recovery time for failures fixed by the team.

It’s also important to keep track of the denominator. The report should distinguish between instances of vulnerabilities that have been fixed by verified remediation, fixed by temporary mitigation, are covered by an exception that is about to expire, are unknown, etc. It’s especially important to get the repair of failing endpoint management processes started, and to track how many devices of a given type are still open to vulnerability.

Start with the simplest scenario which is probably the most common vulnerability on the most common application. Walk through inventory, through analysis to remediation for one vulnerability, to ensure all steps are clear, ownership is assigned, and verification of completion is adequate. Repeat for other vulnerabilities until you have a process that identifies exposed devices, explains why they are still exposed and how you fix them.

Leave a Comment

Item added to cart.
0 items - $0.00