You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: defender-xdr/microsoft-secure-score-history-metrics-trends.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -72,7 +72,7 @@ In the **Metrics & trends** tab, view how your organization's Secure Score compa
72
72
73
73
## We want to hear from you
74
74
75
-
If you have any issues, let us know by posting in the [Security, Privacy & Compliance](https://techcommunity.microsoft.com/t5/Security-Privacy-Compliance/bd-p/security_privacy) community. We're monitoring the community and will provide help.
75
+
If you have any issues, let us know by posting in the [Defender XDR community](https://techcommunity.microsoft.com/category/microsoft-defender-xdr/discussions/microsoftthreatprotection). We're monitoring the community and will provide help.
Copy file name to clipboardExpand all lines: defender-xdr/microsoft-secure-score-improvement-actions.md
+1-1Lines changed: 1 addition & 1 deletion
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -115,7 +115,7 @@ Prerequisites include any licenses that are needed or actions to be completed be
115
115
116
116
## We want to hear from you
117
117
118
-
If you have any issues, let us know by posting in the [Security, Privacy & Compliance](https://techcommunity.microsoft.com/t5/Security-Privacy-Compliance/bd-p/security_privacy) community. We're monitoring the community and will provide help.
118
+
If you have any issues, let us know by posting in the [Defender XDR community](https://techcommunity.microsoft.com/category/microsoft-defender-xdr/discussions/microsoftthreatprotection). We're monitoring the community and will provide help.
Copy file name to clipboardExpand all lines: defender-xdr/microsoft-secure-score-whats-new.md
+30-29Lines changed: 30 additions & 29 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -25,7 +25,7 @@ ms.date: 02/19/2024
25
25
26
26
To make Microsoft Secure Score a better representative of your security posture, we continue to add new features and improvement actions.
27
27
28
-
The more improvement actions you take, the higher your Secure Score will be. For more information, see [Microsoft Secure Score](microsoft-secure-score.md).
28
+
The more improvement actions you take, the higher your Secure Score is. For more information, see [Microsoft Secure Score](microsoft-secure-score.md).
29
29
30
30
Microsoft Secure Score can be found at <https://security.microsoft.com/securescore> in the [Microsoft Defender portal](microsoft-365-defender-portal.md).
31
31
@@ -39,25 +39,25 @@ The following recommendation is added as a Microsoft Secure Score improvement ac
39
39
40
40
## January 2024
41
41
42
-
The following recommendations have been added as Microsoft Secure Score improvement actions:
42
+
The following recommendations were added as Microsoft Secure Score improvement actions:
43
43
44
44
**Microsoft Entra (AAD):**
45
45
46
-
- Ensure 'Phishing-resistant MFA strength' is required for Administrators.
46
+
- Ensure "Phishing-resistant MFA strength" is required for Administrators.
47
47
- Ensure custom banned passwords lists are used.
48
-
- Ensure 'Windows Azure Service Management API' is limited to administrative roles.
48
+
- Ensure "Windows Azure Service Management API" is limited to administrative roles.
49
49
50
50
**Admin Center:**
51
51
52
-
- Ensure 'User owned apps and services' is restricted.
52
+
- Ensure "User owned apps and services" is restricted.
53
53
54
54
**Microsoft Forms:**
55
55
56
56
- Ensure internal phishing protection for Forms is enabled.
57
57
58
58
**Microsoft Share Point:**
59
59
60
-
- Ensure that SharePoint guest users cannot share items they don't own.
60
+
- Ensure that SharePoint guests can't share items they don't own.
61
61
62
62
### Defender for Cloud Apps support for multiple instances of an app
63
63
@@ -67,32 +67,32 @@ For more information, see [Turn on and manage SaaS security posture management (
67
67
68
68
## December 2023
69
69
70
-
The following recommendations have been added as Microsoft Secure Score improvement actions:
70
+
The following recommendations were added as Microsoft Secure Score improvement actions:
71
71
72
72
**Microsoft Entra (AAD):**
73
73
74
-
- Ensure 'Microsoft Azure Management' is limited to administrative roles.
74
+
- Ensure "Microsoft Azure Management" is limited to administrative roles.
75
75
76
76
**Microsoft Sway:**
77
77
78
-
- Ensure that Sways cannot be shared with people outside of your organization.
78
+
- Ensure that Sways can't be shared with people outside of your organization.
79
79
80
80
**Microsoft Exchange Online:**
81
81
82
-
- Ensure users installing Outlook add-ins is not allowed.
82
+
- Ensure users installing Outlook add-ins isn't allowed.
83
83
84
84
**Zendesk:**
85
85
86
86
- Enable and adopt two-factor authentication (2FA).
87
87
- Send a notification on password change for admins, agents, and end users.
88
88
- Enable IP restrictions.
89
89
- Block customers to bypass IP restrictions.
90
-
-Admins and agents can use the Zendesk Support mobile app.
90
+
-Use the Zendesk Support mobile app (admins and agents).
91
91
- Enable Zendesk authentication.
92
92
- Enable session timeout for users.
93
93
- Block account assumption.
94
94
- Block admins to set passwords.
95
-
-Automatic redaction.
95
+
-Enable automatic redaction.
96
96
97
97
**Net Document:**
98
98
@@ -135,31 +135,31 @@ For more information, see [Microsoft Defender for Identity's security posture as
135
135
136
136
## October 2023:
137
137
138
-
The following recommendations have been added as Microsoft Secure Score improvement actions:
138
+
The following recommendations were added as Microsoft Secure Score improvement actions:
139
139
140
140
**Microsoft Entra (AAD):**
141
141
142
-
- Ensure 'Phishing-resistant MFA strength' is required for administrators.
142
+
- Ensure "Phishing-resistant MFA strength" is required for administrators.
143
143
- Ensure custom banned passwords lists are used.
144
144
145
145
**Microsoft Sway:**
146
146
147
-
- Ensure that Sways cannot be shared with people outside of your organization.
147
+
- Ensure that Sways can't be shared with people outside of your organization.
148
148
149
149
**Atlassian:**
150
150
151
-
- Enable multi-factor authentication (MFA).
151
+
- Enable multifactor authentication (MFA).
152
152
- Enable Single Sign On (SSO).
153
153
- Enable strong Password Policies.
154
-
- Enable session timeout for web users.
154
+
- Enable session time out for web users.
155
155
- Enable Password expiration policies.
156
-
- Atlassian mobile app security - Users that are affected by policies.
156
+
- Atlassian mobile app security - Users who are affected by policies.
157
157
- Atlassian mobile app security - App data protection.
158
158
- Atlassian mobile app security - App access requirement.
159
159
160
160
## September 2023:
161
161
162
-
The following recommendations have been added as Microsoft Secure Score improvement actions:
162
+
The following recommendations were added as Microsoft Secure Score improvement actions:
163
163
164
164
**Microsoft Information Protection:**
165
165
@@ -172,7 +172,7 @@ The following recommendations have been added as Microsoft Secure Score improvem
172
172
- Ensure modern authentication for Exchange Online is enabled.
173
173
- Ensure MailTips are enabled for end users.
174
174
- Ensure mailbox auditing for all users is enabled.
175
-
- Ensure additional storage providers are restricted in Outlook on the web.
175
+
- Ensure other storage providers are restricted in Outlook on the web.
176
176
177
177
**Microsoft Defender for Cloud Apps:**
178
178
@@ -184,11 +184,11 @@ The following recommendations have been added as Microsoft Secure Score improvem
184
184
- Ensure all forms of mail forwarding are blocked and/or disabled.
185
185
- Ensure Safe Links for Office Applications is enabled.
186
186
- Ensure Safe Attachments policy is enabled.
187
-
- Ensure that an anti-phishing policy has been created.
187
+
- Ensure that an anti-phishing policy was created.
188
188
189
189
## August 2023
190
190
191
-
The following recommendations have been added as Microsoft Secure Score improvement actions:
191
+
The following recommendations were added as Microsoft Secure Score improvement actions:
192
192
193
193
**Microsoft Information Protection:**
194
194
@@ -201,20 +201,20 @@ The following recommendations have been added as Microsoft Secure Score improvem
201
201
- Ensure all forms of mail forwarding are blocked and/or disabled.
202
202
- Ensure MailTips are enabled for end users.
203
203
- Ensure mailbox auditing for all users is enabled.
204
-
- Ensure additional storage providers are restricted in Outlook on the web.
204
+
- Ensure other storage providers are restricted in Outlook on the web.
205
205
206
206
**Microsoft Entra ID:**
207
207
208
208
To see the following new Microsoft Entra controls in the Office 365 connector, you need to turn on Microsoft Defender for Cloud Apps in the App connectors settings page:
209
209
210
210
- Ensure password protection is enabled for on-premises Active Directory.
211
-
- Ensure 'LinkedIn account connections' is disabled.
211
+
- Ensure "LinkedIn account connections" is disabled.
212
212
213
213
**SharePoint:**
214
214
215
215
- Ensure Safe Links for Office Applications is enabled.
216
216
- Ensure Safe Attachments for SharePoint, OneDrive, and Microsoft Teams is enabled.
217
-
- Ensure that an anti-phishing policy has been created.
217
+
- Ensure that an anti-phishing policy was created.
218
218
219
219
To see the following new SharePoint controls in the Office 365 connector, you need to turn on Microsoft Defender for Cloud Apps in the App connectors settings page:
220
220
@@ -244,14 +244,14 @@ A new data source **Secure Score – Additional data source** is also available.
244
244
245
245
The following Microsoft Defender for Identity recommendations were added as Microsoft Secure Score improvement actions:
246
246
247
-
- Remove the attribute 'password never expires' from accounts in your domain.
247
+
- Remove the attribute "password never expires" from accounts in your domain.
248
248
- Remove access rights on suspicious accounts with the Admin SDHolder permission.
249
249
- Manage accounts with passwords more than 180 days old.
250
250
- Remove local admins on identity assets.
251
251
- Remove non-admin accounts with DCSync permissions.
252
252
- Start your Defender for Identity deployment, installing Sensors on Domain Controllers and other eligible servers.
253
253
254
-
The following Google workspace recommendation were added as a Microsoft Secure Score improvement action:
254
+
The following Google workspace recommendations were added as a Microsoft Secure Score improvement action:
255
255
256
256
- Enable multifactor authentication (MFA)
257
257
@@ -309,7 +309,7 @@ New Microsoft Defender for Office 365 recommendations for anti-phishing policies
309
309
- Quarantine messages that are detected from impersonated users.
310
310
- Quarantine messages that are detected from impersonated domains.
311
311
- Move messages that are detected as impersonated users by mailbox intelligence.
312
-
- Enable the 'show first contact safety tip' option.
312
+
- Enable the "show first contact safety tip" option.
313
313
- Enable the user impersonation safety tip.
314
314
- Enable the domain impersonation safety tip.
315
315
- Enable the user impersonation unusual characters safety tip.
@@ -395,11 +395,12 @@ New Microsoft Defender for Office 365 recommendations are now available as Secur
395
395
396
396
## We want to hear from you
397
397
398
-
If you have any issues, let us know by posting in the [Security, Privacy & Compliance](https://techcommunity.microsoft.com/t5/Security-Privacy-Compliance/bd-p/security_privacy) community. We're monitoring the community to provide help.
398
+
If you have any issues, let us know by posting in the [Defender XDR community](https://techcommunity.microsoft.com/category/microsoft-defender-xdr/discussions/microsoftthreatprotection). We're monitoring the community to provide help.
399
399
400
400
## Related resources
401
401
402
402
-[Assess your security posture](microsoft-secure-score-improvement-actions.md)
403
403
-[Track your Microsoft Secure Score history and meet goals](microsoft-secure-score-history-metrics-trends.md)
0 commit comments