New Microsoft Secure Score recommendations for Microsoft Defender for Endpoint will roll out in November 2025, focusing on LDAP security enhancements like client signing, traffic encryption, channel binding, and server signing to improve endpoint protection and prevent attacks. Admins should review and implement these changes.
Introduction
We’re introducing new Microsoft Secure Score recommendations for Microsoft Defender for Endpoint (MDE) to help organizations strengthen their security posture. These recommendations are designed to proactively block common attack techniques and improve endpoint protection.When this will happen:
Public Preview: Rollout begins in early November 2025 and is expected to complete by mid-November 2025.
How this affects your organization:
Who is affected: Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score.
What’s changing:
Lightweight Directory Access Protocol (LDAP) is a protocol used to access and manage directory information, commonly for authentication and authorization in enterprise environments.
Customers in Public Preview will see the following new recommendations in Microsoft Secure Score:
Secure Score will be updated based on the implementation of these recommendations.
What you can do to prepare:
Compliance considerations:
No compliance considerations identified, review as appropriate for your organization.