| Message Content |
[What and why]
Microsoft is adding four new Microsoft Secure Score recommendations in Microsoft Defender for Endpoint to help organizations assess device readiness for AI accelerated threats and strengthen foundational device security.
The new recommendations identify eligible Windows devices that do not have key security capabilities enabled:
- Trusted Platform Module (TPM) 2.0
- Virtualization-based Security (VBS)
- Hypervisor-Protected Code Integrity (HVCI), also known as Memory Integrity
- Windows Local Administrator Password Solution (LAPS)
These capabilities help protect credentials, improve platform integrity, and strengthen device security. The new recommendations provide visibility into devices that do not meet these security baselines so administrators can prioritize remediation and track improvement over time.
[Rollout schedule]
- Public Preview: Beginning in early September 2026 and expected to complete by mid-September 2026
- General Availability (Worldwide, GCC, GCC High, DoD): Beginning in mid-September 2026 and expected to complete by late September 2026
[Impact on your organization]
Who is affected
- Administrators who manage Microsoft Defender for Endpoint and monitor Microsoft Secure Score
- Organizations with Windows devices onboarded to Microsoft Defender for Endpoint that are eligible for TPM 2.0, VBS, HVCI, or LAPS
Platforms and services
- Microsoft Defender for Endpoint
- Microsoft Secure Score in the Microsoft Defender portal
- Windows devices onboarded to Microsoft Defender for Endpoint
What will happen

Four new recommendations will be added to Microsoft Secure Score:
- Ensure that TPM 2.0 is present, enabled, and activated
- Enable Virtualization-based Security (VBS)
- Enable Memory Integrity (HVCI)
- Ensure LAPS is enabled on every endpoint and server

The recommendations will:
- Identify eligible devices where TPM 2.0, VBS, HVCI, or LAPS are not enabled.
- Help administrators prioritize remediation activities.
- Reflect progress in Secure Score as eligible devices are brought into compliance.
- Appear automatically and require no configuration.
Because these are new Secure Score recommendations, your available points and overall Secure Score percentage may change after the rollout.
[Action required and recommendations]
No action is required to receive these recommendations.
After rollout, Microsoft recommends that administrators:
- Review the new recommendations in the Microsoft Defender portal by filtering Secure Score recommendations using the AI-Readiness tag.
- Identify eligible devices where TPM 2.0, VBS, HVCI, or LAPS are not enabled.
- Validate device, application, and driver compatibility before enabling HVCI where testing is required.
- Follow the remediation guidance provided in each recommendation.
- Document and manage approved exceptions when security controls cannot be enabled because of validated business or compatibility requirements.
- Notify security operations and help desk teams that Secure Score values may change when these recommendations become available.
[Compliance considerations]
No compliance considerations identified, review as appropriate for your organization.
|
| Machine Translation |
[何となぜ]
Microsoftは、Microsoft Defender for Endpoint に4つの新しいMicrosoft Secure Score推奨事項を追加し、組織がAIによる脅威に対するデバイス対応状況を評価し、基盤となるデバイスセキュリティを強化するのを支援します。
新しい推奨事項では、主要なセキュリティ機能が有効でない対象となるWindowsデバイスを特定しています。
- 信頼プラットフォームモジュール(TPM)2.0
- 仮想化ベースセキュリティ(VBS)
- ハイパーバイザー保護コード整合性(HVCI)、別名メモリ整合性
- Windowsローカル管理者パスワードソリューション(LAPS)
これらの機能は認証情報の保護、プラットフォームの整合性の向上、デバイスセキュリティの強化に役立ちます。新しい推奨事項は、これらのセキュリティベースラインを満たさないデバイスを可視化し、管理者が修復の優先順位をつけ、時間経過による改善を追跡できるようにします。
[展開スケジュール]
- パブリックプレビュー:2026年9月初旬から開始され、2026年9月中旬までに完了予定です
- 一般稼働期間(世界、GCC、GCC High、DoD): 2026年9月中旬から開始、2026年9月下旬までに完了予定
[組織への影響]
影響を受ける人物
- Microsoft Defender for Endpointを管理し、Microsoft Secure Scoreを監視する管理者
- Microsoft Defender for EndpointにオンボーディングされたWindowsデバイスを持ち、TPM 2.0、VBS、HVCI、またはLAPSの対象となる組織
ホームとサービス
- Microsoft Defender for Endpoint
- Microsoft DefenderポータルにおけるMicrosoft Secure Scoreについて
- Microsoft Defender for EndpointにオンボーディングされたWindowsデバイス
何が起こるのか

Microsoft Secure Scoreには4つの新しい推奨事項が追加されます:
- TPM 2.0が存在し、有効化され、有効化されていることを確認してください
- 仮想化ベースセキュリティ(VBS)を有効にする
- メモリ整合性(HVCI)を有効にする
- すべてのエンドポイントとサーバーでLAPSが有効であることを確認しましょう

勧告内容は以下の通りです:
- TPM 2.0、VBS、HVCI、またはLAPSが有効でない対象機器を特定します。
- 管理者が修復活動の優先順位を決めるのを支援しましょう。
- 対象機器が適合するにつれてSecure Scoreの進捗を反映してください。
- 自動表示され、設定不要です。
これらは新しいSecure Score推奨であるため、展開後に利用可能なポイントや全体のSecure Score割合が変わる可能性があります。
[行動が必要と提言]
これらの勧告を受け取るためには、いかなる措置も必要ありません。
展開後、Microsoftは管理者に以下のことを推奨しています:
- Microsoft Defenderポータルで、AI-Readinessタグを使ってSecure Scoreの推奨をフィルタリングして新しい推奨を確認しましょう。
- TPM 2.0、VBS、HVCI、またはLAPSが有効でない対象機器を特定します。
- テストが必要な場合にHVCIを有効にする前に、デバイス、アプリケーション、ドライバーの互換性を検証してください。
- 各勧告に記載された除染ガイダンスに従ってください。
- 認証済みのビジネスや互換性要件によりセキュリティコントロールが有効にできない場合、承認された例外を文書化・管理します。
- セキュリティ運用やヘルプデスクチームに、これらの推奨が提供された際にSecure Scoreの値が変更される可能性があることを通知してください。
[コンプライアンスの考慮事項]
コンプライアンス上の懸念事項は特定されず、組織に応じてレビューしてください。
|