BLOG

Microsoft Secure Score Explained: What It Measures, What It Misses, and What Actually Moves It

Microsoft Secure Score in Microsoft 365: a tenant security rating that measures configuration, not full posture

By David Chernitzky, CEO, Armour Cybersecurity  ·  Serving Toronto and organizations across North America  ·  Last updated August 21, 2026

Key Takeaways

  • Microsoft Secure Score measures configuration, not posture. A high Secure Score indicates that the tenant has implemented the controls Microsoft recommends. It does not indicate that those controls are configured correctly for the organization’s specific environment, that they are being monitored and operated effectively, or that there are no security-relevant configurations outside the Secure Score recommendation set. An organization can have a Secure Score of 80 percent and still have critical gaps in its DLP configuration, its incident response procedures, or its admin account governance that the Secure Score does not surface.
  • The maximum possible Secure Score varies by license tier and product configuration. An organization with Microsoft 365 Business Standard has access to fewer security controls than one with Microsoft 365 E5, which means the maximum achievable Secure Score is lower regardless of how well the available controls are configured. Comparing raw Secure Score numbers across organizations without accounting for license differences is not meaningful. Within a single tenant over time, the score is a useful trend indicator: a rising score indicates configuration is improving, and a falling score indicates something has changed, either a new recommended action was added to the scoring model or a previously implemented control has drifted from its configured state.
  • Some of the highest-impact M365 security controls do not appear in Secure Score recommendations. The auto-forwarding block that prevents attackers from silently exfiltrating email after account compromise, the OAuth consent policy that prevents consent phishing, and specific DLP policies tuned to the organization’s data types and regulatory obligations may not generate Secure Score points even though they address material security risks. An M365 hardening engagement that focuses exclusively on Secure Score improvement may implement lower-impact controls that generate points while missing higher-impact controls that do not.
  • Secure Score recommended actions include a risk acceptance option. For each recommendation, the administrator can mark it as resolved through a third-party alternative, planned for future implementation, or accepted as a risk. Actions marked in any of these ways continue to appear in the recommendation list but do not negatively affect the score. This means a high Secure Score may partly reflect risk acceptance decisions rather than implemented controls. Auditors reviewing Secure Score as a compliance artifact should review the accepted and planned actions alongside the implemented actions to understand the complete picture.
  • Secure Score is a useful communication tool for leadership audiences. A score of 45 out of 100 communicates security posture in a format that non-technical leadership can engage with. The before-and-after comparison, from 45 at the start of a hardening engagement to 78 at the end, communicates the impact of the investment in a quantified form that a detailed technical report does not. The compliance mapping that connects specific Secure Score actions to framework requirements gives auditors a starting point for control evidence review. These communication uses are valuable independently of Secure Score’s limitations as a technical assessment tool.

What Secure Score Actually Measures

The recommendation categories

Microsoft Secure Score organizes its recommendations into categories that align roughly with the M365 product areas: identity (Entra ID and MFA), device (Intune and endpoint), data (information protection and DLP), apps (application security), and infrastructure (Azure security). Each category contains a set of recommended actions, each with a point value, a description of what implementing it involves, and a status indicating whether it has been implemented, accepted, or not yet addressed. The categories are weighted differently in the overall score; identity and device recommendations typically carry the highest point values because compromised identities and unmanaged devices are the most common initial compromise vectors.

The recommendations are drawn from Microsoft’s security best practices, aligned to frameworks including CIS Benchmarks and NIST CSF, and updated periodically as the threat landscape and the M365 platform evolve. New recommendations are added when Microsoft identifies a new control that its data suggests has meaningful security impact. When a new high-value recommendation is added to the scoring model, tenants that have not yet implemented it see their effective score drop relative to the new maximum, which can be disorienting for administrators who have not added any new controls but see their score decline.

What it does not measure

Secure Score does not evaluate the correctness or completeness of an implemented control. If an organization has enabled a DLP policy but configured it with rules that do not match the sensitivity classification of the data it actually handles, the Secure Score records the DLP policy as implemented and awards the points. The mismatch between the policy and the actual data protection need is not visible in the score. Similarly, if conditional access policies are configured but include so many exceptions for legacy authentication or specific user groups that the coverage is actually thin, the score reflects that conditional access is in place without reflecting the gaps in coverage.

Secure Score also does not measure operational security practices that live outside the M365 platform configuration: the rigor of the access review process for M365 accounts, the effectiveness of the incident response procedures for M365 security events, the quality of the admin training program, or the degree to which the monitoring alerts configured in the tenant are actually reviewed and acted upon. These operational dimensions are material to the organization’s actual security posture and are evaluated in a comprehensive M365 security assessment even though they do not appear in the Secure Score.

What Actually Moves the Score in a Meaningful Way

The highest-impact Secure Score actions

The recommended actions that carry the most Secure Score points and correspond to genuine security improvements are concentrated in the identity category, which is why identity and access management hardening produces the largest score gains. Enabling MFA for all users is consistently one of the highest-point recommendations because it addresses the most common initial compromise vector across M365 environments. Requiring MFA for administrative roles is a separate recommendation with its own point value, reflecting the elevated risk of a compromised admin account. Enabling sign-in risk policies that block or challenge high-risk authentications, configuring self-service password reset with registration required, and disabling legacy authentication protocols that bypass MFA enforcement are all high-point identity recommendations that correspond to material risk reductions.

In the data and apps categories, enabling Microsoft Defender for Office 365 Safe Attachments and Safe Links, configuring anti-phishing policies, enabling Microsoft Defender for Cloud Apps, and turning on audit logging are recommendations that carry meaningful point values and address genuine attack vectors. External sharing policy configuration and sensitivity label deployment appear in the recommendations with varying point values depending on the license tier. The key distinction in prioritizing recommendations is to sequence the actions that close the highest-risk attack surfaces before addressing the lower-risk configurations that generate fewer points but satisfy a specific compliance checkbox.

Configuration drift and score maintenance

Microsoft Secure Score is not a set-and-forget measure. Configuration drift, where implemented controls are modified, disabled, or bypassed over time without a security review, can reduce the score from a hardened baseline without any deliberate decision to do so. An administrator who disables a conditional access policy to troubleshoot a connectivity issue and forgets to re-enable it, a DLP policy that is modified to reduce false positives but ends up with rules that no longer cover the intended data types, or a new application added to the tenant that requires legacy authentication and prompts an exception that undermines the legacy authentication block: each of these represents score drift that is not visible until the next deliberate score review.

The post-hardening baseline captured at the end of an M365 hardening engagement is the reference point for monitoring drift over time. Armour Cybersecurity documents the post-hardening score, the specific controls implemented, and the configuration state of each control so that subsequent reviews can identify what has changed. The quarterly protection review included in ongoing managed monitoring checks the current Secure Score against the post-hardening baseline and investigates any unexplained decline. For compliance purposes, the post-hardening report and periodic score reviews provide the historical record that demonstrates consistent maintenance of the hardened configuration.

Across the 260+ organizations Armour Cybersecurity protects in 52+ industries, the tenants with the highest Secure Scores are not always the best defended, and the gap is almost always the same: a strong number built by implementing every cheap recommendation while the two or three controls that would actually stop the likely attack sit unaddressed because they carry few points or none at all.

Frequently Asked Questions

What is a good Microsoft Secure Score for a mid-market organization?

There is no universally correct target score because the maximum achievable score depends on the license tier and the products in use. A more meaningful benchmark than a specific number is the percentage of the maximum achievable score that the tenant has reached: an organization at 70 to 80 percent of its achievable maximum with a Business Premium license has implemented most of the controls available to it. Organizations significantly below 50 percent of their achievable maximum are likely to have material configuration gaps in the highest-impact areas. The most useful comparison is the organization’s score before and after a hardening engagement, which demonstrates the specific improvement achieved and the controls that produced it.

Can Secure Score be gamed by accepting risks without implementing controls?

Yes, to a degree. Recommendations that are marked as risk accepted are excluded from the denominator of the achievable score, which can mechanically raise the percentage even though no additional controls have been implemented. This behavior is visible to anyone who looks at the recommendation list with the status filter set to show accepted risks. For compliance purposes, auditors reviewing the Secure Score should review the accepted risk actions alongside the implemented actions and ask for the business justification for each accepted risk. A score that reflects a combination of implemented controls and accepted risks tells a different story than the same numerical score achieved entirely through implementation.

Does Microsoft Secure Score align with SOC 2 or ISO 27001 requirements?

Microsoft Secure Score recommendations overlap substantially with the access management, data protection, and monitoring requirements of SOC 2, ISO 27001, and other compliance frameworks, but the mapping is not one-to-one. Some high-priority SOC 2 or ISO 27001 requirements are addressed by M365 controls that appear in Secure Score recommendations; others require documentation, operational processes, or controls outside the M365 platform that the Secure Score does not capture. The compliance mapping document produced as part of an M365 hardening engagement explicitly maps each implemented M365 control to the framework requirements it satisfies, which is more useful for audit purposes than a raw Secure Score number. Auditors need to understand not just that a control is implemented but what framework requirement it satisfies and what evidence demonstrates that it is operating effectively.

How often should we review our Secure Score?

A formal Secure Score review should be conducted at minimum quarterly. The quarterly review checks the current score against the post-hardening baseline, identifies any recommendations that have moved from implemented to not implemented indicating configuration drift, and evaluates any new recommendations that Microsoft has added to the scoring model since the last review. Beyond the quarterly formal review, the Microsoft Defender portal provides ongoing visibility into the score and highlights newly available recommendations as they are added. For organizations with active compliance programs, the Secure Score review is typically scheduled to coincide with the quarterly access review and the broader compliance monitoring cadence so that all of the compliance-relevant operational reviews happen on a consistent schedule.

The Bottom Line

Microsoft Secure Score is a genuinely useful instrument as long as you remember what it is: a measure of how many recommended settings you have turned on, shown in a number that leadership and auditors can follow. What it is not is a verdict on whether you are actually secure. It does not check that a control is configured correctly, it does not see the highest-impact controls that carry no points, and it quietly rewards accepting a risk the same as fixing it. The right way to use it is to chase real attack-surface reduction first and let the number follow, then hold the hardened score against drift with a regular review. Armour Cybersecurity’s M365 Security Optimization uses Secure Score as one measurement among several, moves it with the controls that actually reduce risk, and documents the baseline so a strong score stays a true one.

Leave the first comment