Summary
This article is intended to provide guidelines for Enterprise Technology & Services technicians regarding the handling of Endpoint Remediation service requests.
Remediation Request Guidelines
Clients should always be aware of what steps you are taking to remediate existing vulnerabilities- they may need the version or file in question, in which case a Cybersecurity Exception should be filed.
In most cases, affected files should be updated or uninstalled rather than deleted; deleting the files could cause the system or installed software not to function properly. The idea is to find and address the issue rather than just deleting the file(s)
Reference the .csv file attached to the Service Request to determine the specific issues that need to be addressed:
- The "output" field is the field that indicates where the problem exists on the device
- Step 1: Review the vulnerability on the .csv
- Step 2: Find the associated software
- Step 3: Update or uninstall the software if possible; if the current version is needed for client to complete their work, direct them to file a Cybersecurity Exception to be exempted from these requirements
- Step 4: Repeat for any remaining vulnerabilities
If you are unsure what the latest release version of Windows is, check the Windows release information website

Click to view image full size
Windows update version information for endpoints is available in InTune.
If the client states they have completed updates, complete a remote session to check that all vulnerabilities have been addressed. Trust but verify!
If you think you have completed the remediation but aren't sure whether you have caught all vulnerabilities, contact Endpoint Engineering through the Service Request and ask for a rescan of the device.
Do not close the ticket until vulnerabilities have been verified as complete and/or a Cybersecurity exception has been filed.
Remediation Request Handling Timeline
Endpoint Remediation service requests should be resolved within 30 days so they are completed before the next Cybersecurity check.
- Initial client contact should occur within 1 business day of Service Request assignment.
- If the client does not respond within 2-3 business days, follow up via the Service Request.
- If there has been no response after two attempts to contact the client through the ticket, reach out via email or Teams and document that in the Service Request
- If the client does not respond to email/ Teams, try calling their phone number (listed in the GAL or IIQ)
- If you discover the client is out of office, the request should be put On Hold until their return, and a comment made in the ticket feed.
- If the client does not respond within 2-3 business days of phone call, follow up with the supervisor or department head
- Explain that there is a device in their area with cybersecurity vulnerabilities that need to be resolved as soon as possible, and that you have attempted to contact the device owner several times with no reply.
- Politely request their assistance with getting the device up to date.
- If the department is unable to assist with getting the device in for remediation, send the ticket to your team lead for review.
- Your team lead will review request notes for completeness, including documentation of all attempted contacts (emails or Teams messages can be attached; phone calls should be documented in comments) and determine whether the request should be sent to Cybersecurity
- If the determination is that the request should be reassigned to Cybersecurity for quarantine, the team lead will write a summary of the situation in the comments and then reassign the request.
Further Readings
USNH Endpoint Security Remediation Request
Endpoint Management: Frequently Asked Questions
Cybersecurity Exceptions Overview
Cybersecurity Exception Request Form
Windows Release Information
Need additional help?
If you have additional questions regarding how to complete Endpoint Remediation requests, reach out to your team lead or put in a Service Request with Endpoint Engineering.