(Preview) Microsoft Secure Score now includes new recommendations
November 2025
- (Preview) Microsoft Secure Score now includes new recommendations to help organizations proactively prevent common endpoint attack techniques.
- Require LDAP client signing and Require LDAP server signing - help ensure integrity of directory requests so attackers can't tamper with or manipulate group memberships or permissions in transit.
- Encrypt LDAP client traffic - prevents exposure of credentials and sensitive user information by enforcing encrypted communication instead of clear-text LDAP.
- Enforce LDAP channel binding - prevents man-in-the-middle relay attacks by ensuring the authentication is cryptographically tied to the TLS session. If the TLS channel changes, the bind fails, stopping credential replay.
- (GA) These Microsoft Secure Score recommendations are now generally available:
- Block web shell creation on servers
- Block use of copied or impersonated system tools
- Block rebooting a machine in Safe Mode

