MC1466750: Microsoft Secure Score Adds AI-Readiness Recommendations for Device Security in Defender for Endpoint

MWPRO IMPACT SCORE
OPERATIONAL IMPACT
43
0 25 50 75 100
MODERATE IMPACT • ASSESS BUSINESS IMPACT
Recommended Action:
Take a look and decide whether this affects your tenant, users or support teams.
What is MWPro Impact Score? Watch our 60‑second explainer

Primary Audience

Tenant AdminsMicrosoft 365 AdminsSecurity TeamsCompliance TeamsIT ManagersService Owners
Why this score?
AI Confidence
HIGH
Enough detail is available to trust this assessment.
Assessment Reasoning
This introduces four new Secure Score recommendations in Defender for Endpoint to improve device security and AI readiness. Admin teams will need to review and prioritise remediation for TPM 2.0, VBS, HVCI, and LAPS across eligible Windows devices. While no immediate action is required for enablement, it may trigger additional work such as compatibility checks, exception handling and internal communication as Secure Score metrics change. User-facing impact is minimal because changes relate to security baselines rather than UI or workflows.
60
🛡️ Admin Impact
10
👥 User Impact
40
Urgency
45
🔧 Effort
ℹ️ WHAT YOU NEED TO KNOW
📌

AT A GLANCE

Secure Score is adding new checks for TPM 2.0, VBS, HVCI, and LAPS to help assess device readiness against AI-accelerated threats.
👥

END USERS

No major end-user change expected.
🛡️

IT ADMINS

Review new Secure Score recommendations in Defender portal and plan remediation for devices missing these security features.
📅

ROLLOUT TIMELINE

Start:
Early September 2026

📢 Official Microsoft Message Center Announcement


Microsoft Secure Score: New AI-readiness recommendations for device security
Message ID: MC1466750

[What and why]

Microsoft is adding four new Microsoft Secure Score recommendations in Microsoft Defender for Endpoint to help organizations assess device readiness for AI accelerated threats and strengthen foundational device security.

The new recommendations identify eligible Windows devices that do not have key security capabilities enabled:

  • Trusted Platform Module (TPM) 2.0
  • Virtualization-based Security (VBS)
  • Hypervisor-Protected Code Integrity (HVCI), also known as Memory Integrity
  • Windows Local Administrator Password Solution (LAPS)

These capabilities help protect credentials, improve platform integrity, and strengthen device security. The new recommendations provide visibility into devices that do not meet these security baselines so administrators can prioritize remediation and track improvement over time.

[Rollout schedule]

  • Public Preview: Beginning in early September 2026 and expected to complete by mid-September 2026
  • General Availability (Worldwide, GCC, GCC High, DoD): Beginning in mid-September 2026 and expected to complete by late September 2026

[Impact on your organization]

Who is affected

  • Administrators who manage Microsoft Defender for Endpoint and monitor Microsoft Secure Score
  • Organizations with Windows devices onboarded to Microsoft Defender for Endpoint that are eligible for TPM 2.0, VBS, HVCI, or LAPS

Platforms and services

  • Microsoft Defender for Endpoint
  • Microsoft Secure Score in the Microsoft Defender portal
  • Windows devices onboarded to Microsoft Defender for Endpoint

What will happen

21820 2

Four new recommendations will be added to Microsoft Secure Score:

  • Ensure that TPM 2.0 is present, enabled, and activated
  • Enable Virtualization-based Security (VBS)
  • Enable Memory Integrity (HVCI)
  • Ensure LAPS is enabled on every endpoint and server

21820 1

The recommendations will:

  • Identify eligible devices where TPM 2.0, VBS, HVCI, or LAPS are not enabled.
  • Help administrators prioritize remediation activities.
  • Reflect progress in Secure Score as eligible devices are brought into compliance.
  • Appear automatically and require no configuration.

Because these are new Secure Score recommendations, your available points and overall Secure Score percentage may change after the rollout.

[Action required and recommendations]

No action is required to receive these recommendations.

After rollout, Microsoft recommends that administrators:

  • Review the new recommendations in the Microsoft Defender portal by filtering Secure Score recommendations using the AI-Readiness tag.
  • Identify eligible devices where TPM 2.0, VBS, HVCI, or LAPS are not enabled.
  • Validate device, application, and driver compatibility before enabling HVCI where testing is required.
  • Follow the remediation guidance provided in each recommendation.
  • Document and manage approved exceptions when security controls cannot be enabled because of validated business or compatibility requirements.
  • Notify security operations and help desk teams that Secure Score values may change when these recommendations become available.

[Compliance considerations]

No compliance considerations identified, review as appropriate for your organization.

Source: Microsoft Message Center • Analysed by MWPro

Share This Update