Microsoft Defender Integration for Security Exposure Management

  • Release version: Yokohama
  • Updated July 29, 2026
  • 1 minute to read
  • The Microsoft Defender Integration for Security Exposure Management application is a unified integration point for importing security data from Microsoft TVM and Microsoft Defender for Cloud.

    Note:
    The integrations support commercial cloud environments by default. If you require non-commercial support (GCC High, DoD, etc.), see the Non-commercial configuration for Microsoft Defender Integration for Security Exposure Management Knowledge Base article [KB3141167] for more information.

    The Microsoft Defender Integration for Security Exposure Management application bundles two independent integrations, each with its own configuration steps and distinct API URLs:

    Microsoft Threat and Vulnerability Management (MS TVM)
    Imports vulnerability data, security recommendations, and asset information. Use this data to prioritize and remediate vulnerabilities across your environment. For configuration instructions, see Understanding the Microsoft Threat and Vulnerability Management Vulnerability integrations for Security Exposure Management and Install and configure the Microsoft TVM integrations for Security Exposure Management.
    Microsoft Defender for Cloud
    Imports cloud resource misconfigurations, security assessment findings, compliance assessment data, and container image vulnerabilities. Use this data to manage your cloud security posture. For configuration instructions, see Understanding the Microsoft Defender for Cloud integrations for Security Exposure Management and Install and configure Microsoft Defender for Cloud integrations for Security Exposure Management.

    To view the integrations included with this application, navigate to All > Microsoft Defender Integration for USEM > Administration > Integrations.