Skip to content

Commit 701e7c0

Browse files
committed
PM feedback
1 parent cde72cb commit 701e7c0

File tree

1 file changed

+1
-1
lines changed

1 file changed

+1
-1
lines changed

defender-vulnerability-management/whats-new-in-microsoft-defender-vulnerability-management.md

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -26,7 +26,7 @@ This article provides information about new features and important product updat
2626
- (Preview) **Microsoft Secure Score now includes new recommendations** to help organizations proactively prevent common endpoint attack techniques.
2727
- **Require LDAP client signing** and **Require LDAP server signing** - help ensure integrity of directory requests so attackers can't tamper with or manipulate group memberships or permissions in transit.
2828
- **Encrypt LDAP client traffic** - prevents exposure of credentials and sensitive user information by enforcing encrypted communication instead of clear-text LDAP.
29-
- **Enforce LDAP channel binding** - stops adversaries from hijacking or relaying authentication sessions by binding New Technology LAN Manager (NTLM) authentication to a secure TLS channel.
29+
- **Enforce LDAP channel binding** - prevents man-in-the-middle relay attacks by ensuring the authentication is cryptographically tied to the TLS session. If the TLS channel changes, the bind fails, stopping credential replay.
3030
- (GA) These Microsoft Secure Score recommendations are now generally available:
3131
- **Block web shell creation on servers**
3232
- **Block use of copied or impersonated system tools**

0 commit comments

Comments
 (0)