Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC1154297

Microsoft Defender for Identity: New recommendations for Microsoft Secure Score

Plan for Change

Message ID

MC1154297
View in Admin Center

Services

Microsoft Defender XDR

Summary

Microsoft Defender for Identity will add new Secure Score improvement actions by late 2025 to better identify identity risks. These include identifying privileged service accounts, removing stale AD accounts, and disabling Entra Seamless SSO. No admin action is needed, but review configurations and notify security teams.

Details

Introduction

To improve the accuracy of Microsoft Secure Score and better reflect your organization’s security posture, we’re updating the improvement actions related to Microsoft Defender for Identity. This update introduces new posture recommendations that will appear as Secure Score improvement actions, helping you identify and remediate potential identity risks more effectively.

When this will happen:
  • Public Preview: Begins mid-October 2025; expected completion by mid-November 2025.
  • General Availability (Worldwide, GCC, GCC High, DoD): Begins late October 2025; expected completion by late November 2025.
How this affects your organization:

Who is affected:
Organizations with Microsoft Defender for Identity sensors installed in their identity infrastructure.

What will happen:

  • New posture recommendations will be added to Microsoft Secure Score as improvement actions:
    • Identify service accounts in privileged groups
    • Remove stale Active Directory accounts
    • Identify Entra ID privileged accounts that are also privileged in Active Directory
    • Locate accounts in built-in Operator Groups
    • Disable Entra Seamless SSO
  • These recommendations will be available by default.
  • Your Secure Score will update automatically based on these new actions.
What you can do to prepare:
  • No admin action is required before or after rollout.
  • Review your current configuration to assess potential impact.
  • Notify your identity and security admins about the upcoming changes.
  • Update any internal documentation that references Secure Score or Defender for Identity.
  • Regularly review Secure Score improvement actions to stay informed of new recommendations.

Learn more: Microsoft Secure Score documentation

Compliance considerations:

No compliance considerations identified, review as appropriate for your organization.

Timeline

📅
Published
Sep 16, 2025
Message published to Message Center
✏️
Updated
Sep 16, 2025
Message content updated
🏁
End Date
Dec 10, 2025
Message timeline ends

Tags

#Feature update#Admin impact

Category

📋Plan for Change

Related Messages

Similar updates

MC1150118

Microsoft Defender for Office 365: New records in Streaming API and Sentinel EmailEvents table

Sep 8, 2025
MC1169078

Microsoft Defender for Cloud Apps: Improvements to threat protection capabilities

Oct 9, 2025
MC1137610

Microsoft Defender for Identity alerts transitioning to XDR-based detection platform

Aug 18, 2025
MC1163754

Enhancements to the Deep Analysis tab of Email Entity page by Microsoft Defender for Office 365

Oct 1, 2025
MC1155429

Microsoft Defender for Identity: New recommendations added to Microsoft Secure Score

Sep 18, 2025