Plan the week's patching from real exposure
Every Monday, WebRun opens Microsoft Defender, reads the security recommendations and the devices each one affects, ranks them by how much real exposure they remove, writes the patch plan into Notion, and logs the device level detail in Airtable for the team to work through.
- No credit card
- Under $0.01 per run
- Cancel anytime
How do I decide what to patch first each week?
Every Monday WebRun opens Microsoft Defender, reads the security recommendations and the devices each one affects, and ranks them by how much real exposure they remove. It writes the patch plan into Notion, logs the device level detail in Airtable, and leaves every change to your team.
- Patch work each week is aimed at the largest real exposure
- Recommendations nobody got to are flagged as repeats
- Devices with incomplete onboarding are surfaced before they hide risk
Built for IT administrators · security teams · managed service providers · compliance leads
What does WebRun do on every run?
The exact actions WebRun takes, in order - in plain language, so you can adjust anything.
-
WebRun signs in and gets to work
Opens
security.microsoft.comin a real browser with your saved login - no setup, no API keys. -
1
Microsoft Defender - read the recommendations
WebRun opens Microsoft Defender to read the recommendations. - Open Microsoft Defender and go to the security recommendations for your organisation
- Capture each recommendation with the number of exposed devices behind it and its weakness
- Record the current exposure score and how it moved since last week
- Read only. Never dismiss a recommendation, change a policy or isolate a device
Done when Every recommendation is captured with its exposed device count and the exposure score trend.
-
2
Notion - write the patch plan
WebRun opens Notion to write the patch plan. - Write this week's patch plan page: the top recommendations ranked by devices affected
- Put the exposure score and its movement at the top so progress against last week is plain
- Note which recommendations are repeats from previous weeks, since those are the ones nobody got to
- Keep every past week's page so the trail of what was planned and what shipped survives
Done when Notion holds a ranked patch plan for the week with the exposure trend at the top.
-
3
Airtable - log the device detail
WebRun opens Airtable to log the device detail. - Add a row per affected device with its name, its onboarding status and the recommendations that hit it
- Flag devices that appear under several recommendations at once, since fixing those clears the most at a time
- Flag devices whose onboarding looks incomplete, because their real exposure is unknown
- Mark rows resolved when the device drops off the recommendation on a later run
Done when Airtable lists every affected device with the recommendations that apply to it.
How is each run configured?
Secure by default
Connect once, stays signed in
WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.
Every action is checked against this policy before it runs.
Questions, answered
Will it patch or isolate anything?
No. WebRun reads Defender and never applies a fix, dismisses a recommendation, changes a policy or isolates a device. Every action stays with your IT team.
How does it decide what matters most?
It ranks recommendations by how many of your own devices are affected, so the plan is built from your real estate rather than from a generic severity label.
Is this the same as the incident brief?
No. This one is preventive. It covers known weaknesses on devices that have not been attacked, and it runs weekly as a planning input rather than as an alert.
Put this on autopilot.
Turn it on in minutes - or have our team set it up for you.