← Back
Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint
MC1191616 · build prod-20251231-200323
Category
stayInformed
Severity
normal
Major change
False
Last modified
2025-12-03 00:04:38
Summary source
Azure OpenAI (gpt-4.1)
Action by (Graph)
Action by (AI)
Services
Microsoft Defender XDR
Tags
New feature, User impact, Admin impact
Master tags
Security
Roadmap IDs

One-line summary

New Secure Score recommendations for Defender for Endpoint will roll out in public preview, helping block attacks and improve endpoint protection by end of Nov 2025.

Similar updates

More like this
MC1192254 Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations
Microsoft Defender for Endpoint: New Microsoft Secure Score recommendations New Secure Score recommendations for Defender for Endpoint will roll out in public preview at end of Dec 2025, helping admins proactively block attacks and improve endpoint security. We’re introducing new Microsoft Secure Score recommendations for Microsoft Defender for.
MC1179155 (Updated) Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score
(Updated) Microsoft Defender for Identity: New recommendation added to Microsoft Secure Score Microso... When this will happen: Public Preview: Rollout begins early November 2025, completes by mid-December 2025 General Availability (Worldwide, GCC, GCC High, and DoD):  Rollout begins early November 2025, completes by mid-December 2025 How.
MC1147984 (Updated) Microsoft Teams: User reporting for incorrectly identified security concerns
(Updated) Microsoft Teams: User reporting for incorrectly identified security concerns Teams users can now report messages incorrectly flagged as security threats; feature rolls out GA by end of Nov 2025 and is on by default, with admin controls in Teams and Defender portals. ...les users to report messages they believe were incorrectly flagged.
MC1155429 (Updated) Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score
(Updated) Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score Microsoft Secure Score adds new improvement actions based on Defender for Identity posture recommendations for PingOne, with rollout starting November 2025 and GA in January 2026. [Introduction:] We’re enhancing Microsoft Secure Score by intro... [When.
MC1163754 Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365
Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365 Defender for Office 365's Deep Analysis tab gains enhanced UI, improved detonation chains, expanded metadata, and exportable insights for better threat investigation, rolling out Nov 2025. We’re excited to share recent enhancements to the Deep.
MC1187386 Microsoft Defender for Identity alerts transitioning to XDR-based detection platform
Microsoft Defender for Identity alerts transitioning to XDR-based detection platform Defender for Identity classic alerts will shift to the XDR detection platform starting mid-December 2025; update workflows and alert exclusions to use new XDR Detector IDs. [Introduction] Microsoft Defender for Identity classic alerts will transition to the XDR.

Details

Summary
New Microsoft Secure Score recommendations for Microsoft Defender for Endpoint will roll out from late November to mid-December 2025, adding actions like disabling Remote Registry Service on Windows. Available to Microsoft 365 E5 or Defender for Endpoint Plan 2 customers, admins should review and implement these to enhance security.

Body (from Message Center)

Introduction

We’re introducing new Microsoft Secure Score recommendations for Microsoft Defender for Endpoint (MDE) to help organizations strengthen their security posture. These recommendations are designed to proactively block common attack techniques and improve endpoint protection.

When this will happen

Public Preview: Rollout will begin at the end of November 2025 and is expected to complete by mid-December 2025.

How this affects your organization

Who is affected: Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score.

Licensing requirements: This functionality is available to Microsoft 365 E5 customers or those with Microsoft Defender for Endpoint Plan 2 (P2).

What will happen:

  • Customers in Public Preview will see new recommendations in Microsoft Secure Score:
    • Disable Remote Registry Service on Windows
  • Secure Score will update based on the implementation of these recommendations.

What you can do to prepare

  • Review the new recommendations in Microsoft Secure Score once available.
  • Complete the recommended actions to improve your organization’s security posture.
  • Communicate these changes to your security and endpoint management teams.

Learn more: 

Compliance considerations

No compliance considerations identified, review as appropriate for your organization.

Raw JSON (for debugging)

Expand/collapse the full payload below.
Show/hide raw
{
  "snapshot_item": {
    "action_required_by": null,
    "ai_action_required_by": null,
    "ai_actions": [
      "Review new Secure Score recommendations",
      "Complete recommended security actions",
      "Inform security and endpoint teams"
    ],
    "ai_master_tags": [
      "Security"
    ],
    "ai_model": "gpt-4.1",
    "ai_summary": "New Secure Score recommendations for Defender for Endpoint will roll out in public preview, helping block attacks and improve endpoint protection by end of Nov 2025.",
    "ai_topics": [
      "Defender",
      "Secure Score"
    ],
    "category": "stayInformed",
    "details_map": {
      "Summary": "New Microsoft Secure Score recommendations for Microsoft Defender for Endpoint will roll out from late November to mid-December 2025, adding actions like disabling Remote Registry Service on Windows. Available to Microsoft 365 E5 or Defender for Endpoint Plan 2 customers, admins should review and implement these to enhance security."
    },
    "id": "MC1191616",
    "importance": 1,
    "is_major_change": false,
    "last_modified": "2025-12-03T00:04:38Z",
    "ms_products": [
      "Defender"
    ],
    "platforms": null,
    "roadmap_ids": [],
    "services": [
      "Microsoft Defender XDR"
    ],
    "severity": "normal",
    "tags": [
      "New feature",
      "User impact",
      "Admin impact"
    ],
    "title": "Microsoft Secure Score: New recommendations for Microsoft Defender for Endpoint"
  }
}