Skip to content

Commit 5ef39f4

Browse files
authored
Merge pull request #5475 from limwainstein/mdvm-new-recommendations
New MDVM recommendations
2 parents 7305e90 + 81271e4 commit 5ef39f4

File tree

1 file changed

+12
-1
lines changed

1 file changed

+12
-1
lines changed

defender-vulnerability-management/whats-new-in-microsoft-defender-vulnerability-management.md

Lines changed: 12 additions & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -11,7 +11,7 @@ audience: ITPro
1111
ms.collection:
1212
- m365-security
1313
ms.topic: whats-new
14-
ms.date: 11/19/2024
14+
ms.date: 11/4/2025
1515
---
1616

1717
# What's new in Microsoft Defender Vulnerability Management
@@ -21,6 +21,17 @@ This article provides information about new features and important product updat
2121
> [!TIP]
2222
> Did you know you can try all the features in Microsoft Defender Vulnerability Management for free? Find out how to [sign up for a free trial](defender-vulnerability-management-trial.md).
2323
24+
## November 2025
25+
26+
- (Preview) **Microsoft Secure Score now includes new recommendations** to help organizations proactively prevent common endpoint attack techniques.
27+
- **Require LDAP client signing** and **Require LDAP server signing** - help ensure integrity of directory requests so attackers can't tamper with or manipulate group memberships or permissions in transit.
28+
- **Encrypt LDAP client traffic** - prevents exposure of credentials and sensitive user information by enforcing encrypted communication instead of clear-text LDAP.
29+
- **Enforce LDAP channel binding** - prevents man-in-the-middle relay attacks by ensuring the authentication is cryptographically tied to the TLS session. If the TLS channel changes, the bind fails, stopping credential replay.
30+
- (GA) These Microsoft Secure Score recommendations are now generally available:
31+
- **Block web shell creation on servers**
32+
- **Block use of copied or impersonated system tools**
33+
- **Block rebooting a machine in Safe Mode**
34+
2435
## October 2025
2536

2637
- (Preview) You can now use **CVE exceptions** to exclude specific Common Vulnerabilities and Exposures (CVEs) from analysis in your environment. CVE exceptions allow you to control what type of data is relevant to your organization and to selectively exclude certain data from your remediation efforts. For more information, see [Exceptions in Microsoft Defender Vulnerability Management](tvm-exception-overview.md) and [Create, view, and manage exceptions](tvm-exception.md).

0 commit comments

Comments
 (0)