New Microsoft Secure Score recommendations for Microsoft Defender for Endpoint will roll out from late November to mid-December 2025, adding actions like disabling Remote Registry Service on Windows. Available to Microsoft 365 E5 or Defender for Endpoint Plan 2 customers, admins should review and implement these to enhance security.
Introduction
We’re introducing new Microsoft Secure Score recommendations for Microsoft Defender for Endpoint (MDE) to help organizations strengthen their security posture. These recommendations are designed to proactively block common attack techniques and improve endpoint protection.
When this will happen
Public Preview: Rollout will begin at the end of November 2025 and is expected to complete by mid-December 2025.
How this affects your organization
Who is affected: Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score.
Licensing requirements: This functionality is available to Microsoft 365 E5 customers or those with Microsoft Defender for Endpoint Plan 2 (P2).
What will happen:
What you can do to prepare
Learn more:
Compliance considerations
No compliance considerations identified, review as appropriate for your organization.