Favorite your Message Center and Roadmap items. Access them anytime via your Profile. Export and share with your team or your LLM.

(Updated) Microsoft Secure Score: New recommendation to reduce inbound internet exposure

Message ID
MC1358832
View in Message Center
Service
Microsoft Defender XDR
Category
Stay Informed
Tags
New featureAdmin impact
Rollout
June 2026

Summary

Microsoft Secure Score in Microsoft Defender for Endpoint introduces a new default recommendation to reduce unnecessary inbound internet exposure by identifying internet-facing devices. Rolling out from June 2026, it helps admins validate and remediate exposure risks, improving enterprise security posture with no user impact or required configuration.

Details

Updated June 9, 2026: We have updated the timeline. Thank you for your patience. 

[What and Why:]

We’re introducing a new Microsoft Secure Score recommendation in Microsoft Defender for Endpoint (MDE) to help organizations reduce unnecessary inbound exposure from the public internet. This update strengthens your enterprise security posture by giving admins clear visibility into internet-facing devices, helping validate whether exposure is expected, approved, and appropriately secured. By highlighting potential attack surface risks, this recommendation supports proactive risk reduction and aligns with Microsoft’s commitment to enterprise-ready security and manageability.

[Rollout Schedule:]

  • Public Preview (Worldwide): Rollout started on June 3, 2026.
  • General Availability (Worldwide): We will begin rolling out in mid-June 2026 (previously early June) and expect to complete by end of June 2026 (previously mid-June).

[Impact on Your Organization:]

Who is affected: Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score

Platforms/Services: Microsoft Defender for Endpoint, Microsoft Secure Score

What will happen:

  • A new Secure Score recommendation, "Reduce unnecessary inbound internet exposure on internet-facing devices," will appear.
  • Screenshot: New Secure Score recommendation in Microsoft Defender:

    user settings

  • Admins will gain visibility into devices with observed inbound connectivity from the public internet.
  • Devices or services reachable from the internet will be identified for review.
  • Secure Score will reflect progress as remediation or validation actions are taken.
  • The recommendation is on by default and requires no configuration to appear.
  • No user experience changes.

[Action Required / Recommendations:]

No immediate action is required to enable this feature.

Recommended actions for admins:

  • Review the new recommendation in Microsoft Secure Score once it appears.
  • Identify devices flagged as internet-facing.
  • Validate whether each exposure is expected, approved, and required.
  • Follow provided remediation guidance to reduce unnecessary exposure.
  • For devices that must remain internet-facing:
    • Ensure the exposure is approved, documented, and properly secured.
    • Consider applying an exception where the risk is accepted by your organization.

For more information, review documentation on Microsoft Defender for Endpoint and Microsoft Secure Score in Microsoft Learn.

[Compliance considerations:]

No compliance considerations identified, review as appropriate for your organization.

Change History

Show
June 9, 2026 at 6:30 PM Updated
Title
Previous
Microsoft Secure Score: New recommendation to reduce inbound internet exposure
New
(Updated) Microsoft Secure Score: New recommendation to reduce inbound internet exposure
Summary
Previous
A new Microsoft Secure Score recommendation in Microsoft Defender for Endpoint will identify and help reduce unnecessary inbound internet exposure on internet-facing devices. Rolling out worldwide in June 2026, it provides admins visibility, requires no configuration, and supports proactive risk reduction without affecting user experience.
New
Microsoft Secure Score in Microsoft Defender for Endpoint introduces a new default recommendation to reduce unnecessary inbound internet exposure by identifying internet-facing devices. Rolling out from June 2026, it helps admins validate and remediate exposure risks, improving enterprise security posture with no user impact or required configuration.
Last Updated Date
Previous
2026-06-04T23:10:02.847Z
New
2026-06-09T16:08:02.240Z
Tags
Previous
New feature,Admin impact
New
Updated message,New feature,Admin impact
Body Content
Previous
<p><b>[What and Why:]</b></p> <p>We’re introducing a new Microsoft Secure Score recommendation in <b>Microsoft Defender for Endpoint (MDE)</b> to help organizations reduce unnecessary inbound exposure from the public internet. This update strengthens your <b>enterprise security posture</b> by giving admins clear visibility into internet-facing devices, helping validate whether exposure is expected, approved, and appropriately secured. By highlighting potential attack surface risks, this recommendation supports proactive risk reduction and aligns with Microsoft’s commitment to enterprise-ready security and manageability.</p><p><b>[Rollout Schedule:]</b></p> <ul> <li>Public Preview (Worldwide):&nbsp;We will begin rolling out in <b>early June 2026</b> and expect to complete by <b>mid-June 2026</b>.</li> <li>General Availability (Worldwide):&nbsp;We will begin rolling out in <b>early June 2026</b> and expect to complete by <b>mid-June 2026</b>.</li> </ul> <p><b>[Impact on Your Organization:]</b></p> <ul> </ul><p><b>Who is affected:</b> Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score</p><p><b>Platforms/Services:</b> Microsoft Defender for Endpoint, Microsoft Secure Score</p><p><b>What will happen:</b></p><ul><li>A new Secure Score recommendation, "<b>Reduce unnecessary inbound internet exposure on internet-facing devices</b>," will appear.</li><p>Screenshot: <i>New Secure Score recommendation in Microsoft Defender:</i></p><p><img src="https://cxcs.microsoft.net/static/public/messagecenter/neutral/40334c8c-0079-4ba3-85bb-af5933f26217/e7104fdb087d8fd730303115173bff63a36e48e0.png" style="width: 400px;" alt="user settings"></p></ul><ul><li>Admins will gain visibility into devices with observed inbound connectivity from the public internet.</li><li>Devices or services reachable from the internet will be identified for review.</li><li>Secure Score will reflect progress as remediation or validation actions are taken.</li><li>The recommendation is <b>on by default</b> and <b>requires no configuration</b> to appear.</li><li>No user experience changes.</li> </ul><ul> </ul> <p><b>[Action Required / Recommendations:]</b></p> <ul> </ul><p>No immediate action is required to enable this feature.</p><p>Recommended actions for admins:</p><ul> <li>Review the new recommendation in Microsoft Secure Score once it appears.</li><li>Identify devices flagged as internet-facing.</li><li>Validate whether each exposure is expected, approved, and required.</li><li>Follow provided remediation guidance to reduce unnecessary exposure.</li><li>For devices that must remain internet-facing:<ul><li>Ensure the exposure is approved, documented, and properly secured.</li><li>Consider applying an exception where the risk is accepted by your organization.</li></ul></li></ul><p>For more information, review documentation on Microsoft Defender for Endpoint and Microsoft Secure Score in Microsoft Learn.</p><p><b>[Compliance considerations:]</b></p><p></p><p>No compliance considerations identified, review as appropriate for your organization.</p>
New
<p>Updated June 9, 2026: We have updated the timeline. Thank you for your patience.&nbsp;</p><p><b>[What and Why:]</b></p> <p>We’re introducing a new Microsoft Secure Score recommendation in <b>Microsoft Defender for Endpoint (MDE)</b> to help organizations reduce unnecessary inbound exposure from the public internet. This update strengthens your <b>enterprise security posture</b> by giving admins clear visibility into internet-facing devices, helping validate whether exposure is expected, approved, and appropriately secured. By highlighting potential attack surface risks, this recommendation supports proactive risk reduction and aligns with Microsoft’s commitment to enterprise-ready security and manageability.</p><p><b>[Rollout Schedule:]</b></p> <ul> <li>Public Preview (Worldwide): Rollout started on June 3, 2026.</li> <li>General Availability (Worldwide):&nbsp;We will begin rolling out in <b>mid-June 2026 </b>(previously early June)&nbsp;and expect to complete by <b>end of June 2026</b> (previously&nbsp;mid-June).</li> </ul> <p><b>[Impact on Your Organization:]</b></p> <ul> </ul><p><b>Who is affected:</b> Admins managing Microsoft Defender for Endpoint and Microsoft Secure Score</p><p><b>Platforms/Services:</b> Microsoft Defender for Endpoint, Microsoft Secure Score</p><p><b>What will happen:</b></p><ul><li>A new Secure Score recommendation, "<b>Reduce unnecessary inbound internet exposure on internet-facing devices</b>," will appear.</li><p>Screenshot: <i>New Secure Score recommendation in Microsoft Defender:</i></p><p><img src="https://cxcs.microsoft.net/static/public/messagecenter/neutral/40334c8c-0079-4ba3-85bb-af5933f26217/e7104fdb087d8fd730303115173bff63a36e48e0.png" style="width: 400px;" alt="user settings"></p></ul><ul><li>Admins will gain visibility into devices with observed inbound connectivity from the public internet.</li><li>Devices or services reachable from the internet will be identified for review.</li><li>Secure Score will reflect progress as remediation or validation actions are taken.</li><li>The recommendation is <b>on by default</b> and <b>requires no configuration</b> to appear.</li><li>No user experience changes.</li> </ul><ul> </ul> <p><b>[Action Required / Recommendations:]</b></p> <ul> </ul><p>No immediate action is required to enable this feature.</p><p>Recommended actions for admins:</p><ul> <li>Review the new recommendation in Microsoft Secure Score once it appears.</li><li>Identify devices flagged as internet-facing.</li><li>Validate whether each exposure is expected, approved, and required.</li><li>Follow provided remediation guidance to reduce unnecessary exposure.</li><li>For devices that must remain internet-facing:<ul><li>Ensure the exposure is approved, documented, and properly secured.</li><li>Consider applying an exception where the risk is accepted by your organization.</li></ul></li></ul><p>For more information, review documentation on Microsoft Defender for Endpoint and Microsoft Secure Score in Microsoft Learn.</p><p><b>[Compliance considerations:]</b></p><p></p><p>No compliance considerations identified, review as appropriate for your organization.</p>

Never Miss a Microsoft 365 Update

Join thousands of IT professionals who rely on DeltaPulse for real-time Microsoft 365 change intelligence, automated notifications, and community insights.