Skip to main content
🦉
Message CenterMicrosoft 365 Updates
HomePermissionsTenant FinderPortfolio
🦉
M365 Message Centerby Cengiz YILMAZ

Track the latest updates, features, and announcements for Microsoft 365 services. Comprehensive archive of service updates and important changes.

Quick Links

HomePermissionsTenant FinderPortfolio

Connect

© 2026 M365 Message Center. Created with ❤️ by Cengiz YILMAZ

Data sourced from Microsoft 365 Message Center • Not affiliated with Microsoft

  1. Home
  2. /
  3. MC971037

Exposure Management Recommendations Retirement

Plan for Change
Major Change

Message ID

MC971037
View in Admin Center

Services

Microsoft Defender XDR

Summary

Certain SSPM recommendations will be retired from Exposure Management in the Defender portal to ensure accurate security posture representation. The rollout will occur from mid-February to mid-April 2025. No action is required from organizations, and security scores will be updated accordingly.

Details

Updated March 27, 2025: We have updated the rollout timeline below. Thank you for your patience.

We will be retiring certain SaaS security posture management (SSPM) recommendations from Exposure Management in the Defender portal. This update is to help ensure a more accurate representation of security posture.

When this will happen:

This will begin rollout in mid-February 2025 and is expected to be complete by mid-April 2025 (previously mid-March).

How this will affect your organization:

You are receiving this message because our reporting indicates your organization may be using this feature.

As part of our efforts to keep recommendations updated and relevant, we will be retiring the following recommendations due to either low security value or change of settings in the applications.

Recommendations names:

  • AAD: Ensure that collaboration invitations are sent to allowed domains only
  • EXO: Ensure notifications for internal users sending malware is enabled
  • EXO: Audit Exchange online Organization Sharing
  • Defender for Office: Ensure that DKIM is enabled for all Exchange Online Domains
  • Purview: Ensure external domains are not allowed in Skype or Teams
  • SPO: Guests must sign in using the same account to which sharing invitations are sent
  • Intune: Ensure devices lock after a period of inactivity to prevent unauthorized access
  • Intune: Ensure mobile device management policies are required for email profiles - iOS/iPadOS only
  • Intune: Ensure mobile device management policies are set to require advanced security configurations
  • Intune: Ensure mobile devices are set to wipe on multiple sign-in failures to prevent brute force compromise
  • Intune: Ensure mobile devices require the use of a password
  • Intune: Ensure that devices connecting have AV and a local firewall enabled
  • Intune: Ensure that mobile device encryption is enabled to prevent unauthorized access to mobile data
  • Intune: Ensure that mobile device password reuse is prohibited
  • Intune: Ensure that mobile devices are set to never expire passwords
  • Intune: Ensure that mobile devices require a minimum password length to prevent brute force attacks
  • Intune: Ensure that mobile devices require complex passwords (Simple Passwords = Blocked)
  • Intune: Ensure that mobile devices require complex passwords (Type = Alphanumeric)
  • Intune: Ensure that users cannot connect from devices that are jail broken or rooted
  • Defender for Cloud Apps: Create an OAuth app policy to notify you about new OAuth applications
  • Defender for Cloud Apps: Create an app discovery policy to identify new and trending cloud apps in your org
  • Defender for Cloud Apps: Create a custom activity policy to get alerts about suspicious usage patterns

What you need to do to prepare:

There's no action needed to prepare for this change. Your score will be updated accordingly.

Timeline

📅
Published
Jan 3, 2025
Message published to Message Center
✏️
Updated
Mar 28, 2025
Message content updated
🏁
End Date
Jun 2, 2025
Message timeline ends

Tags

#Updated message#User impact#Admin impact#Retirement

Category

📋Plan for Change

Related Messages

Similar updates

MC1220762●

Retirement notice: MDE and XDR Advanced Hunting APIs retiring; migrate to Microsoft Graph Security API

Jan 22, 2026
MC783218●

Cloud Discovery anomaly detection policy to be retired

Apr 22, 2024
MC783216●

"Investigation priority score increase" Policy to be retired

Apr 22, 2024
MC698130●

Threat Protection report page retirement

Dec 14, 2023
MC690173●

Microsoft to stop honoring mail flow rules tracking user reporting

Nov 15, 2023