Back to the registry
Agent passport

Endpoint Risk Insights

Avanade, Inc. · Cybersecurity & IT

SaaSNo attestation published

Certification per Microsoft Marketplace.

Endpoint Vulnerability AnalysisCritical CVEs Defender HealthCVE Health Scan
Provenance reach4 of 12 layers traced

Evidence tier Source Confirmed · 8 captures on record

User ratingNot rated0 reviews on the listing
Runs onSaaSSaaS
ProvenanceUnknown44% of the provenance layers this product can disclose
Evidence riskHighSign in to see the basis for this band.

What the publisher says

As described on Microsoft Marketplace.

Traditional vulnerability assessments often fall short missing the context needed to act with confidence. Endpoint Risk Insights transforms how security teams manage endpoint risk by automatically identifying high-impact vulnerabilities (CVSS ≥ 9.0), surfacing CISA Known Exploited Vulnerabilities (KEVs), and monitoring Defender sensor health across the environment.

By focusing on threats with known exploits, this agent empowers teams to respond faster and smarter—reducing manual effort and enabling risk-based remediation. The result? Stronger endpoint resilience, streamlined operations, and protection where it matters most.

Show the rest of the publisher’s description (18 more lines)

Agents Tasks:

The Endpoint Risk Insights agent enhances endpoint security by automatically detecting high-impact vulnerabilities (CVSS ≥ 9.0), surfacing CISA Known Exploited Vulnerabilities (KEVs), and monitoring Defender sensor health. It enables faster, risk-based remediation, helping security teams respond efficiently and strengthen endpoint resilience.

Agent Workflow:

  • Discover Devices – Identify endpoints to scan using KQL on Manifest
  • Analyze CVEs – Flag critical vulnerabilities (CVSS ≥ 9.0) using KQL on Manifest
  • Find Threat Intelligence – Match CVEs against CISA Known Exploited Vulnerabilities.
  • Assess Sensor Health – Evaluate Defender sensor status using KQL on Manifest
  • Generate Report – Summarize findings and highlight top risks.

Inputs:

  • Microsoft Defender for Endpoint
  • CISA Kev Database

Output:

  • Summary Report
  • Executive Overview
  • Top 5 Vulnerable Devices
  • Device Health Status
  • Critical CVEs with KEV, Recommendation
  • Excel Report Attachment

Preview

1 image
Endpoint Risk Insights preview 1

Agent build and provenance

See the full provenance

The layer-by-layer build, the evidence behind each claim, the risk basis and the cross-marketplace links are open to any account. Some rows are disclosed, some the source leaves Unknown; a free account shows you which.

Compliance

Government
  • FedRAMPConfirmedNot listed90%, registry-checkedNo FedRAMP Marketplace entry matched this vendor's domain, checked 2026-08-27registry recordas observed 2026-08-27

Confirmed means matched to a public authoritative registry. Claimed means the vendor or its listing states it, not yet cross-checked. A framework not shown was not found in any source we hold, which is not evidence against it. Not listed means a scoped registry check found no match for this vendor's domain: a No is a scoped registry check, not a compliance judgment. Confidence bands: 95% domain-verified, 90% registry-checked, 80% self-attested, 70% weak signal. Self-attested items marked “vendor's site” are gathered from the vendor's own website and are not verified by us.

Plans and pricing as listed

1 listed
Endpoint Risk Insights Agent Plan
First month free, then $0.00/year
1-year subscription

Sources

Marketplace listingmarketplace.microsoft.comSource
Privacy PolicyPrivacy PolicySource
License TermsLicense TermsSource

Publisher resources

1 link
Supportwww.avanade.comSource

Linked repositories

RepositoriesUnknownUnknown

Unknown means this listing does not publish a repository. It is not a statement that the code is closed, and a linked repository is not a claim that the publisher wrote it: the registry computes that relationship privately and does not publish it.

Pricing
Paid
1 plan listed
Delivery
SaaS
https://www.avanade.com/en/services/microsoft-tech/microsoft-security/copilot-readiness-assessment
Open the source listing ↗

Evidence risk is the share of the build you cannot see before you deploy, not a security rating. Sign in to see the layer-by-layer basis for this band.