What is Workspace ONE Vulnerability Defense?
Workspace ONE Vulnerability Defense identifies known software vulnerabilities, called Common Vulnerabilities and Exposures (CVEs), on Windows desktops and servers, and scores each one by exposure and exploitability across your endpoint population. Your team prioritizes real risk and remediates directly from the Workspace ONE UEM console.
See what is exposed
Evaluate your application and OS vulnerability exposure in context, across the Windows desktops and servers you manage.
Prioritize by real risk
See exploitation likelihood, severity, and affected device counts in one view. Includes ExPRT.AI scoring from CrowdStrike.
Fix it fast in UEM
The entire flow lives in Workspace ONE UEM, helping to remove handoffs and bring patch timelines from weeks to days.
Close the gap between finding a vulnerability and fixing it
Workspace ONE Vulnerability Defense gives your team immediate context, streamlined prioritization, and direct remediation of vulnerabilities—all in the Workspace ONE UEM console.
Vulnerability assessment from CrowdStrike
Risk-based prioritization with ExPRT.AI ratings
Automate app and OS remediation
Don’t ticket it, fix it
Explore Omnissa solutions, use cases, and partner integrations
How Vulnerability Defense supports UEM
Your team already uses Workspace ONE UEM to inventory devices and deliver patches. Workspace ONE Vulnerability Defense adds the missing piece: not just what is installed and what is out of date, but which of those gaps are known to be exploitable. Remediation then runs through the patch workflows you have already built, so vulnerability management becomes part of endpoint management instead of a parallel process.
How Vulnerability Defense supports security & compliance
Unpatched software remains one of the most common ways attackers get in. Workspace ONE Vulnerability Defense gives your security team a current view of which known vulnerabilities exist across Windows desktops and servers, and gives IT a way to act on that view without leaving Workspace ONE UEM. Assessment, prioritization, and patch delivery stay in one workflow, which shortens the window a known vulnerability stays open.
How Vulnerability Defense complements mobile device management
Most organizations manage mobile devices and desktops side by side. Workspace ONE Vulnerability Defense covers Windows desktops and servers in that estate, and Workspace ONE Mobile Threat Defense addresses app, device, and network threats on iOS and Android.
With Workspace ONE UEM, your team manages the end-to-end desktop and mobile lifecycles across the full fleet.
Core components and architecture
Workspace ONE Vulnerability Defense brings together the assessment data your security team trusts and the patch workflows your IT team already runs.
Workspace ONE Vulnerability Defense
Assess, prioritize, remediate, and track progress. Add on to Workspace ONE UEM; included with Workspace ONE Platinum.
CrowdStrike Falcon Exposure Management
Provides the vulnerability assessment and the ExPRT.AI rating, which predicts how likely a flaw is to be exploited. Purchased separately from CrowdStrike.
Workspace ONE UEM
Where findings appear and remediation happens. Granular patch management delivers OS updates, and the Enterprise App Repository supplies more than 10,000 prepackaged app updates.
Workspace ONE Vulnerability Defense
Assess, prioritize, remediate, and track progress. Add on to Workspace ONE UEM; included with Workspace ONE Platinum.
CrowdStrike Falcon Exposure Management
Provides the vulnerability assessment and the ExPRT.AI rating, which predicts how likely a flaw is to be exploited. Purchased separately from CrowdStrike.
Workspace ONE UEM
Where findings appear and remediation happens. Granular patch management delivers OS updates, and the Enterprise App Repository supplies more than 10,000 prepackaged app updates.
Workspace ONE Vulnerability Defense
Assess, prioritize, remediate, and track progress. Add on to Workspace ONE UEM; included with Workspace ONE Platinum.
CrowdStrike Falcon Exposure Management
Provides the vulnerability assessment and the ExPRT.AI rating, which predicts how likely a flaw is to be exploited. Purchased separately from CrowdStrike.
Workspace ONE UEM
Where findings appear and remediation happens. Granular patch management delivers OS updates, and the Enterprise App Repository supplies more than 10,000 prepackaged app updates.
Take action and know it worked
Remediate from the same console where you found the problem, then confirm the vulnerability is gone without running a separate compliance scan.
Know your risk
See which vulnerabilities are present across your Windows estate, which ones attackers are exploiting, and how many devices each affects.
Fix on your terms
Choose what gets resolved, when, and on which devices. Remediation follows the policies and maintenance windows your team already has in place.
See the results
Know which vulnerabilities are closed and where exposure remains, giving your team status info to bring to compliance reviews.
Connect with your existing tools and platforms
Workspace ONE Vulnerability Defense integrates with CrowdStrike and works within your existing Workspace ONE UEM deployment to streamline assessment and remediation.
Unified endpoint management integration
Workspace ONE Vulnerability Defense uses your existing Workspace ONE UEM deployment for device enrollment, patch delivery, and reporting.
-
Existing enrollment
-
Patch delivery
-
Unified reporting
Next steps
Pricing and packaging
Workspace ONE Vulnerability Defense is available as an add-on to Workspace ONE, and it is included in the Platinum edition.
-
Prerequisite note
Requires CrowdStrike Falcon Exposure Management, licensed separately from CrowdStrike.
-
$3 per device per month
Deployment and onboarding
Get started with Workspace ONE Vulnerability Defense using guided setup and deployment resources.
-
Getting started
Get step-by-step instructions for setting up and using Workspace ONE Vulnerability Defense.
VIEW DOCUMENTATION -
Tech Zone resources
Access best practices, tutorials, and architecture diagrams.
SEE ON TECH ZONE
Support and training
Access help resources and learning paths to accelerate adoption.
-
24x7 support
Global support team available via portal and phone.
CONTACT SUPPORT -
Training modules
Self-paced courses, live webinars, and certification paths.
Learn more -
Community forums
Connect with peers and experts to share insights and solutions.
JOIN THE DISCUSSION
FAQ
Workspace ONE Vulnerability Defense identifies known software vulnerabilities, or CVEs, on Windows desktops and servers and lets IT teams remediate them through Workspace ONE UEM. It covers known software vulnerabilities and the patches that address them.
The two products address different devices and different kinds of risk. Workspace ONE Vulnerability Defense finds and remediates known software vulnerabilities on Windows desktops and servers. Workspace ONE Mobile Threat Defense protects iOS and Android devices against phishing, risky apps, and network-based threats. Organizations managing both fleets often run both.
Yes. Workspace ONE Vulnerability Defense works with CrowdStrike Falcon Exposure Management, which you purchase directly from CrowdStrike. Omnissa does not resell CrowdStrike products.
ExPRT.AI, short for Expert Prediction Rating AI, is a dynamic score from CrowdStrike that predicts how likely a vulnerability is to be exploited in the real world. Unlike CVSS, which measures theoretical severity, it draws on threat intelligence and adjusts as conditions change.
Workspace ONE Vulnerability Defense scores each vulnerability rather than relying on severity alone. Prioritization uses the ExPRT.AI Rating from CrowdStrike, a composite score that helps your team address the vulnerabilities most likely to be exploited first.
Workspace ONE Vulnerability Defense supports Windows desktop and Windows Server.
Workspace ONE Vulnerability Defense assesses known software vulnerabilities, or CVEs, rather than device configuration posture. When a configuration change is the right mitigation, your team makes it through the existing profile and policy workflows in the Workspace ONE UEM console.
Workspace ONE Vulnerability Defense is available as an add-on to Workspace ONE and is included in the Platinum edition. CrowdStrike Falcon Exposure Management is licensed separately.
Findings appear in the Workspace ONE UEM console, and patches are delivered from there using your existing patch workflows. Your team does not move between consoles to go from finding to fix.
Vulnerability scanners assess weaknesses across systems, networks, and apps, mainly for compliance and asset discovery. Workspace ONE Vulnerability Defense instead surfaces vulnerabilities identified by CrowdStrike Falcon Exposure Management, then correlates and prioritizes them automatically within UEM for faster remediation.