All templates
For IT administrators, security teams & managed service providers

Plan the week's patching from real exposure

Every Monday, WebRun opens Microsoft Defender, reads the security recommendations and the devices each one affects, ranks them by how much real exposure they remove, writes the patch plan into Notion, and logs the device level detail in Airtable for the team to work through.

  • No credit card
  • Under $0.01 per run
  • Cancel anytime
14,115 templates Safe automation No code
Every Monday at 8:00 AM WebRun
1 Microsoft Defender read the recommendations
2 Notion write the patch plan
3 Airtable log the device detail
Run a sample
In short

How do I decide what to patch first each week?

Every Monday WebRun opens Microsoft Defender, reads the security recommendations and the devices each one affects, and ranks them by how much real exposure they remove. It writes the patch plan into Notion, logs the device level detail in Airtable, and leaves every change to your team.

  • Patch work each week is aimed at the largest real exposure
  • Recommendations nobody got to are flagged as repeats
  • Devices with incomplete onboarding are surfaced before they hide risk

Built for IT administrators · security teams · managed service providers · compliance leads

Step by step

What does WebRun do on every run?

The exact actions WebRun takes, in order - in plain language, so you can adjust anything.

  1. WebRun signs in and gets to work

    Opens security.microsoft.com in a real browser with your saved login - no setup, no API keys.

  2. 1
    Microsoft Defender - read the recommendations
    security.microsoft.com
    WebRun in Microsoft Defender: read the recommendations
    WebRun opens Microsoft Defender to read the recommendations.
    • Open Microsoft Defender and go to the security recommendations for your organisation
    • Capture each recommendation with the number of exposed devices behind it and its weakness
    • Record the current exposure score and how it moved since last week
    • Read only. Never dismiss a recommendation, change a policy or isolate a device

    Done when Every recommendation is captured with its exposed device count and the exposure score trend.

  3. 2
    Notion - write the patch plan
    notion.so How to Automate Notion
    WebRun in Notion: write the patch plan
    WebRun opens Notion to write the patch plan.
    • Write this week's patch plan page: the top recommendations ranked by devices affected
    • Put the exposure score and its movement at the top so progress against last week is plain
    • Note which recommendations are repeats from previous weeks, since those are the ones nobody got to
    • Keep every past week's page so the trail of what was planned and what shipped survives

    Done when Notion holds a ranked patch plan for the week with the exposure trend at the top.

  4. 3
    Airtable - log the device detail
    airtable.com How to Automate Airtable
    WebRun in Airtable: log the device detail
    WebRun opens Airtable to log the device detail.
    • Add a row per affected device with its name, its onboarding status and the recommendations that hit it
    • Flag devices that appear under several recommendations at once, since fixing those clears the most at a time
    • Flag devices whose onboarding looks incomplete, because their real exposure is unknown
    • Mark rows resolved when the device drops off the recommendation on a later run

    Done when Airtable lists every affected device with the recommendations that apply to it.

Run settings

How is each run configured?

Starting pageWhere Chrome opens at the start of each run
security.microsoft.com
ScheduleRuns automatically on this cadence
Every Monday at 8:00 AM
DeliveryHow each run's result reaches you
Patch plan · Notion
OutputWhat each run produces - The week's security recommendations ranked by devices affected, with the exposure score trend and a device level list of what each fix clears.
Text
Setup & safety

Secure by default

Connect once, stays signed in

WebRun signs in once and keeps each session in a persistent environment, so every run picks up right where it left off.

Your credentials stay in your own private environment - WebRun never stores your passwords.
Strict Lockdown

Every action is checked against this policy before it runs.

Domains ALLOWLIST
Typed input ALLOW
Shell command BLOCK
File uploads BLOCK
Runs in a contained environment More on policies
Good to know

Questions, answered

Will it patch or isolate anything?

No. WebRun reads Defender and never applies a fix, dismisses a recommendation, changes a policy or isolates a device. Every action stays with your IT team.

How does it decide what matters most?

It ranks recommendations by how many of your own devices are affected, so the plan is built from your real estate rather than from a generic severity label.

Is this the same as the incident brief?

No. This one is preventive. It covers known weaknesses on devices that have not been attacked, and it runs weekly as a planning input rather than as an alert.

Put this on autopilot.

Turn it on in minutes - or have our team set it up for you.