Loading...

Microsoft Secure Score: New recommendation for Microsoft Defender for Endpoint

Microsoft Secure Score: New recommendation for Microsoft Defender for Endpoint

Microsoft Secure Score will add a new recommendation to block outbound traffic from mshta.exe in Microsoft Defender for Endpoint, starting public preview in late March 2026. This reduces risk from attacks using mshta.exe, requires admin action to enable, and impacts compliance monitoring and data access. Introduction To help organizations strengthen endpoint security and reduce exposure to common attack techniques, we’re introducing a new Microsoft Secure Score recommendation in Microsoft Defender for Endpoint (MDE). This recommendation focuses on blocking outbound traffic from mshta.exe, a legitimate Windows binary that is frequently abused by attackers to execute malicious scripts. Implementing this recommendation helps reduce risk from living-off-the-land binary (LOLBIN) attacks and improves your overall security posture. When this will happen Public Preview: Rollout begins late March 2026 and is expected to complete by early April 2026. General Availability (Worldwide): Rollout begins late March 2026 and is expected to complete by late May 2026. How this affects your organization Who is affected Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score. What will happen A new Secure Score recommendation titled “Block outbound traffic from mshta.exe” will appear in Microsoft Secure Score for tenants enrolled in Public Preview:  View image in new tab Secure Score points will reflect whether this recommendation is implemented. The recommendation is not enabled by default and requires admin action to implement. There is no direct user experience change unless your organization enforces the configuration. Why this matters What you can do to prepare Compliance considerations mshta.exe is commonly abused by attackers to download and execute malicious payloads from remote sources. Blocking outbound traffic from this binary reduces attack surface and aligns with modern endpoint hardening best practices. Review the new recommendation in Microsoft Secure Score once available. Evaluate potential line of business or scripting dependencies before enforcement. Implement the recommended configuration to improve your organization’s security posture. Communicate these changes to your security and endpoint management teams. Learn more: Microsoft Secure Score | Microsoft Defender XDR | Microsoft Defender | Microsoft Learn Question Answer Does the change alter how existing customer data is processed, stored, or accessed? Yes. Blocking outbound traffic from […]

The post Microsoft Secure Score: New recommendation for Microsoft Defender for Endpoint appeared first on M365 Admin.

Published on:

Learn more
Need help with this product?

We can help you with Microsoft Secure Score: New recommendation for Microsoft Defender for Endpoint

If you want help implementing, troubleshooting, or improving this product, contact us and we’ll point you in the right direction.

M365 Admin
M365 Admin

by João Ferreira

Share post:

Related posts

Customized PowerBI reports behavior after major report updates

Microsoft Viva Insights customized Power BI reports will remain tied to their original report versions and won’t auto-update with major report...

9 hours ago

Microsoft SharePoint: Changes to the FAQ web part authoring experience

The SharePoint FAQ web part will shift AI-assisted FAQ creation to Copilot in SharePoint, while retaining manual FAQ editing in the web part. ...

9 hours ago

Microsoft 365 Copilot: Federated Copilot connectors support create, update, and delete actions

Microsoft 365 Copilot’s federated connectors will support create, update, and delete actions in third-party services starting October 20...

9 hours ago

Microsoft Defender for Office 365: Remediation actions from the Teams message entity flyout

Microsoft Defender for Office 365 will enhance the Teams message entity flyout by late September 2026, enabling security admins to submit mess...

9 hours ago

Microsoft 365 Copilot: Updates to the Researcher experience

Microsoft 365 Copilot is updating Researcher to use shared Copilot components, retiring specific controls and tabs by December 30, 2026. Core ...

9 hours ago

Dynamics 365 Field Service – Automate optimizations with Scheduling Operations Agent (Preview)

We are announcing the ability to automatically schedule and run recurring optimizations through the Scheduling Operations Agent in Dynamics 36...

11 hours ago

Dynamics 365 Contact Center – Enable AI-assisted time-off and swap requests

We are announcing the ability to enable AI-assisted time-off and swap requests in Dynamics 365 Contact Center. This feature will reach general...

11 hours ago

Dynamics 365 Project Operations – Perform bulk operations for bookings on schedule board

We are announcing the ability to move or reassign multiple bookings at once, directly from the schedule board in Dynamics 365 Project Operatio...

11 hours ago

Browser Use Admin Control for Copilot Cowork

Admins can now control browser use in Copilot Cowork via Microsoft 365 admin center, enabling access for specific users or groups. Rolling out...

11 hours ago

Microsoft Copilot (Microsoft 365): Power BI reports as references in Copilot Notebooks

Copilot Notebooks now support adding Power BI reports as references, enhancing summaries with real business data. Public preview starts late S...

11 hours ago

Newsletter

Get the latest Dynamics 365 and Power Platform content in your inbox

A curated digest of community blogs, product news, videos, and podcasts — delivered without the noise.

Weekly updates Unsubscribe anytime Fresh community picks
We use your email only for the newsletter and you can unsubscribe at any time.
By subscribing, you agree to the privacy policy.