Exposure Management unified security recommendations for assets discovered across Microsoft security products. Each row is a recommendation for an asset, including its status, severity, and remediation guidance.
Schema
Name
Description
Type
AdditionalFields
Additional fields for this recommendation.
Object
AssessmentKey
Stable id of the assessment type (unique per recommendation logic). If not provided, it will be calculated based on AssessmentTypeId.
String
AssessmentTypeId
The provider’s unique type id for the assessment.
String
AssetId
Unique identifier for the asset the recommendation applies to.
String
AssetName
Display name of the asset.
String
AssetType
Type of asset identification.
String
Description
Description of the information gathered.
String
EnvironmentType
Platform / environment type.
String
FindingType
Type of posture finding.
String
Identifiers
All known identifiers of the asset.
Object
IsPreview
True when the recommendation is in preview; false when generally available.
Boolean
MitreTactics
MITRE ATT&CK / ATLAS tactic ids associated with the recommendation.
Object
MitreTechniques
MITRE ATT&CK / ATLAS technique ids associated with the recommendation.
Object
ProductComponentNames
Defender service / plan / sub-domain related to the product.
Object
ProductName
Defender workload/product.
String
RemediationSteps
The remediation steps of the recommendation.
String
ReportTime
Date and time when the record was generated.
DateTime
Severity
Indicates the potential impact (Critical, high, medium, or low) of the recommendation.
String
SourceSystem
String
StatusCode
The recommendation health status of the asset. Possible values are Healthy, Unhealthy and NotApplicable.