What Is a Microsoft Secure Score? And How Can You Improve It?
Many businesses use Microsoft 365 every day for email, file sharing, collaboration, remote working and communication.
However, simply subscribing to Microsoft 365 does not mean every available security feature has been configured correctly.
Multi-factor authentication may only protect some users. Administrator accounts may have unnecessary privileges. Older authentication methods may still be enabled, and devices or cloud applications may not be properly monitored.
Microsoft Secure Score helps organisations identify these gaps.
It provides a central view of your Microsoft security posture, highlights recommended improvements and helps you track progress over time.
A higher score generally indicates that more of Microsoft’s recommended security controls have been implemented. However, Secure Score is not a guarantee that your organisation cannot be breached. It is a practical measurement of how extensively you are using security controls that can help reduce risk.
What Is Microsoft Secure Score?
Microsoft Secure Score is a numerical summary of your organisation’s security posture within the Microsoft environment.
It is available through the Microsoft Defender portal and evaluates security controls across areas such as:
- User identities and administrator roles
- Devices
- Email and cloud applications
- Business data
- Microsoft 365 security settings
- Microsoft Defender services
- Microsoft Entra ID
The dashboard shows your current score as a percentage and as the number of points achieved out of the total points available to your organisation. It also provides recommended actions that could improve security.
Secure Score is designed to help organisations:
- Understand their current security position
- Identify missing or incomplete controls
- Prioritise security improvements
- Measure progress
- Compare performance with similar organisations
- Establish security targets and key performance indicators
It gives management and IT teams a clearer way to discuss Microsoft 365 security without relying entirely on complex technical reports.
Where Can You Find Your Microsoft Secure Score?
Authorised users can access Secure Score through the Microsoft Defender portal.
Within the portal, the Secure Score dashboard includes:
- Your current percentage
- Points achieved
- Total available points
- Recommended actions
- Historical score changes
- Benchmark comparisons
- Identity, device, application and data categories
- Planned and achievable score views
Access should be restricted to appropriate administrators and security personnel. Microsoft supports read-only and management permissions, helping organisations follow the principle of least privilege rather than giving everyone highly privileged administrator roles.
How Is Microsoft Secure Score Calculated?
Secure Score awards points when your organisation implements recommended security controls or completes recognised security tasks.
Examples could include:
- Protecting users with multi-factor authentication
- Restricting administrator access
- Blocking legacy authentication
- Improving device-security settings
- Configuring email protection
- Strengthening information-protection policies
- Addressing security recommendations
- Implementing an alternative control through another security product
Each recommended action is normally worth up to ten points.
Some actions are scored on a completed-or-not-completed basis. Others provide partial points based on how widely the control has been implemented.
For example, if a ten-point action requires all users to be protected by MFA but only half of the users are covered, the organisation may receive five points.
The percentage is broadly based on:
Points achieved ÷ total available points
The total number of available points can vary according to the products and services included within the environment.
What Does a Good Secure Score Look Like?
There is no single percentage that is suitable for every organisation.
A business should not assume that reaching a particular number means it is secure.
The appropriate score depends on factors such as:
- Business size
- Industry
- Regulatory requirements
- Microsoft licences
- Working practices
- User requirements
- Devices
- Applications
- Risk tolerance
- Existing third-party security controls
A score of 100% may be unrealistic or even undesirable if some recommendations seriously interfere with necessary business processes.
Conversely, a relatively high score does not prove that every risk has been addressed.
Secure Score should be used to support informed decision-making—not as a target that must be increased at any cost.
Why Can Two Similar Businesses Have Different Scores?
Two organisations using Microsoft 365 may have very different Secure Scores.
Possible reasons include:
- Different Microsoft products have been deployed
- One company uses Microsoft Defender for Endpoint
- One organisation has more cloud applications
- Different security recommendations apply
- Some controls are provided by third-party tools
- One business has accepted specific risks
- Licences and configured workloads differ
- Recommendations have changed over time
This means the raw score should not be used as the only way to compare two businesses.
The most valuable information is often found in the recommended actions, identified risks and progress over time.
What Types of Recommendations Does Secure Score Provide?
Microsoft groups recommended actions into four broad areas.
Identity
Identity recommendations relate to Microsoft Entra accounts, authentication and administrator roles.
They may cover:
- Multi-factor authentication
- Privileged access
- Legacy authentication
- User-risk policies
- Sign-in controls
- Administrator protection
Devices
Device recommendations can relate to Microsoft Defender for Endpoint and device-security configurations.
These may include:
- Endpoint protection
- Security updates
- Attack-surface reduction
- Operating-system configuration
- Vulnerability management
- Device compliance
Applications
Application recommendations may cover email and cloud platforms, including Microsoft 365 and Microsoft Defender for Cloud Apps.
They can address areas such as:
- Email protection
- Cloud application access
- External sharing
- Suspicious application permissions
- Collaboration settings
Data
Data recommendations can relate to Microsoft information-protection capabilities.
They may involve:
- Sensitivity labels
- Data-loss prevention
- Information classification
- Document protection
- Secure sharing
These categories help businesses understand whether weaknesses relate mainly to users, devices, applications or information.
Why Is Microsoft Secure Score Useful?
1. It Provides a Clear Starting Point
Microsoft 365 contains a large number of security settings.
Without a structured review, it can be difficult to know where to begin.
Secure Score presents recommended actions in one place, giving businesses an initial list of potential improvements.
This can be particularly useful for SMEs that do not have a large internal cyber security team.
2. It Identifies Unused Security Features
Businesses may already be paying for security capabilities they have not configured.
For example, a licence may include identity, email or device-protection features that remain unused.
Secure Score can help highlight these opportunities.
Implementing existing features may improve security without immediately purchasing another product.
However, licences and prerequisites must be checked before relying on a recommendation.
3. It Helps Prioritise Improvements
The Recommended Actions page can rank improvements using factors including:
- Points available
- Implementation difficulty
- User impact
- Complexity
Recommendations offering meaningful security benefits with limited disruption may appear higher in the list.
Businesses should still apply their own risk assessment rather than following the ranking automatically.
A lower-scoring recommendation affecting a critical finance system may be more important than a higher-scoring recommendation relating to a low-risk service.
4. It Makes Security Progress Measurable
Secure Score allows organisations to track changes over time.
This can help demonstrate:
- Which improvements have been completed
- When the score increased
- Where security has regressed
- Whether targets are being met
- How the organisation compares with similar tenants
The history and trends views can show achieved points, lost points, risk-accepted actions and changes caused by users, devices or configurations.
This is useful for internal reviews, management meetings and security planning.
5. It Can Highlight Security Regression
Cyber security is not a one-off project.
A control that was fully implemented last month may become incomplete when:
- New employees join
- New devices are introduced
- Policies are changed
- Administrator roles are assigned
- Software is deployed
- A setting is disabled
- A device becomes non-compliant
Secure Score can help show when points have regressed.
This gives the IT team an opportunity to investigate before a configuration gap becomes a serious incident.
6. It Supports Management Reporting
A numerical score can make security easier to discuss with non-technical leaders.
Instead of presenting a long list of Microsoft settings, the IT team can show:
- The current score
- Recent progress
- High-priority recommendations
- Accepted risks
- Planned improvements
- Areas requiring investment
The score should always be accompanied by explanation.
A percentage without context can create either unnecessary alarm or false confidence.
7. It Can Recognise Alternative Security Controls
Your organisation may use a non-Microsoft security platform that already addresses one of Microsoft’s recommendations.
Secure Score allows some actions to be marked as resolved through a third party or alternative mitigation.
This can award the relevant points so the score better reflects the overall security posture.
However, Microsoft cannot independently confirm that the alternative control has been implemented completely. The organisation remains responsible for validating and documenting the protection.
How to Improve Your Microsoft Secure Score
1. Review the Recommended Actions
Begin by opening the Recommended Actions section.
Do not immediately enable every option.
Review:
- What risk the action addresses
- Which users or devices are affected
- Licence prerequisites
- Implementation steps
- Possible user disruption
- Whether another tool already provides the control
- How the change can be tested
- Whether the recommendation suits your environment
Create a structured action plan rather than making several uncontrolled changes at once.
2. Enable Multi-Factor Authentication
MFA is one of the most important protections for cloud accounts.
It helps prevent an attacker from signing in with only a stolen password.
Prioritise MFA for:
- Administrator accounts
- Finance users
- Senior leaders
- Remote workers
- Employees with sensitive access
- All other users
Where possible, use stronger authentication methods such as:
- Microsoft Authenticator number matching
- Passkeys
- FIDO2 security keys
- Certificate-based authentication
Unexpected MFA requests should always be reported.
3. Protect Administrator Accounts
Administrator accounts can make extensive changes across Microsoft 365.
They should be:
- Limited to people who genuinely need them
- Separate from everyday user accounts
- Protected with strong MFA
- Monitored carefully
- Used only for administrative work
- Reviewed regularly
- Removed when no longer required
Avoid assigning Global Administrator access when a more limited role will perform the task.
Least-privilege administration can reduce both accidental changes and the consequences of account compromise.
4. Block Legacy Authentication
Legacy authentication methods may not support modern security controls such as MFA.
Attackers can therefore use them to bypass protections that apply to newer sign-in methods.
Before blocking legacy authentication, identify:
- Older applications
- Printers and scanners
- Email clients
- Service accounts
- Business systems
- Third-party integrations
Any dependencies should be upgraded, replaced or reconfigured.
The change should be tested before being enforced across the organisation.
5. Review Conditional Access
Conditional Access can evaluate sign-ins based on factors such as:
- User identity
- Device compliance
- Location
- Application
- Sign-in risk
- Authentication strength
Policies may be used to:
- Require MFA
- Block risky sign-ins
- Restrict unmanaged devices
- Protect administrators
- Limit access from unwanted locations
- Require stronger authentication for sensitive services
Conditional Access should be planned carefully.
Poorly designed policies can block legitimate users or leave gaps. Emergency-access accounts and exclusions must be controlled and documented.
6. Strengthen Email Security
Email remains a major route for phishing, malware and account compromise.
Depending on your licences and configuration, improvements may include:
- Anti-phishing policies
- Safe Links
- Safe Attachments
- Impersonation protection
- External sender warnings
- Spoof intelligence
- Mailbox auditing
- Suspicious forwarding-rule detection
- SPF, DKIM and DMARC
Email protection should be supported by staff awareness training and clear reporting procedures.
7. Improve Device Security
Devices accessing Microsoft 365 should be managed and protected.
Actions may include:
- Enrolling devices in management
- Enforcing encryption
- Applying security updates
- Deploying endpoint protection
- Restricting local administrator rights
- Using compliance policies
- Blocking access from high-risk or unmanaged devices
- Applying attack-surface reduction rules
Secure Score may identify recommended device actions, but any proposed change should be tested for compatibility with existing applications.
8. Review External Sharing
Microsoft 365 makes collaboration easy, but overly broad sharing can expose sensitive information.
Review:
- SharePoint sharing settings
- OneDrive links
- Teams guest access
- Anonymous links
- External users
- Expired projects
- Former suppliers
- Publicly accessible files
Sharing should be limited to the people who need it.
Sensitive data may require additional restrictions, labels or approval processes.
9. Review Application Permissions
Users can sometimes grant third-party applications access to Microsoft 365 data.
A malicious or overprivileged application may access:
- Calendars
- Contacts
- Files
- User profiles
- Teams data
Review existing application permissions and remove those that are unnecessary or suspicious.
Consider restricting user consent and introducing an administrator-approval process for higher-risk applications.
10. Implement Information Protection
Businesses handling sensitive information may benefit from:
- Sensitivity labels
- Encryption
- Data-loss prevention
- Retention policies
- Controlled sharing
- Automatic classification
These controls can help protect information even when it is emailed, downloaded or shared.
They require planning and employee training. Applying overly restrictive policies without testing can interfere with normal work.
11. Protect Against Password Attacks
Improve identity security by:
- Enforcing MFA
- Blocking compromised passwords
- Encouraging password managers
- Monitoring risky sign-ins
- Removing inactive accounts
- Protecting password-reset processes
- Adopting passkeys where possible
Password expiry alone is not a complete security strategy.
The focus should be on unique passwords, strong authentication and rapid detection of suspicious activity.
12. Review Inactive Users and Devices
Old accounts and unmanaged devices increase risk.
Regularly identify:
- Former employee accounts
- Dormant users
- Unused shared mailboxes
- Old mobile devices
- Stale guest accounts
- Inactive administrator accounts
- Devices that no longer meet security standards
Access should be removed promptly when it is no longer needed.
13. Use Planned Actions
Secure Score allows actions to be marked as planned.
This can help the organisation document a realistic improvement programme.
For each action, record:
- Owner
- Priority
- Target date
- Dependencies
- Licence requirements
- User impact
- Testing plan
- Rollback plan
A planned score view can show the potential improvement once selected actions are completed.
14. Document Accepted Risks
Not every recommendation will be appropriate.
A business may choose not to implement an action because:
- It would prevent a critical application from working
- A different security control already addresses the risk
- The business impact is excessive
- A replacement project is already planned
- The affected system is due to be retired
When risk is accepted, document:
- The reason
- The affected systems
- The business owner
- Alternative protections
- The review date
- The planned long-term solution
Risk acceptance should be a conscious management decision, not a way to hide unresolved work.
15. Review Secure Score Regularly
Secure Score should be reviewed on a routine basis.
A monthly review may be suitable for many SMEs, with additional checks after:
- Major Microsoft 365 changes
- New security licences
- Acquisitions
- Security incidents
- Device-management projects
- New application deployments
- Policy changes
- Significant recruitment
Microsoft states that many score updates appear after configuration data has been processed, and some recommended actions may take around 24 to 48 hours to reflect completed work.
Common Secure Score Mistakes
Chasing 100%
The objective should be better security, not simply the highest possible number.
Making Changes Without Testing
A recommendation may affect applications, users or devices.
Ignoring User Impact
Security controls that prevent people from working may be bypassed or disabled.
Treating the Score as Proof of Security
Secure Score does not measure every possible threat or guarantee protection against a breach.
Focusing Only on Easy Points
High-risk weaknesses should be prioritised even when they offer fewer points.
Ignoring Regressions
A declining score can indicate that devices, users or configurations have changed.
Failing to Document Alternative Controls
Third-party security tools should be recorded and independently verified.
Reviewing the Score Only Once
Microsoft services and business environments change constantly.
Does a High Secure Score Mean You Are Secure?
No.
A high score means the organisation has implemented a larger proportion of the controls measured by Microsoft Secure Score.
It does not confirm that:
- Every device is secure
- Employees will identify phishing
- Backups will restore successfully
- Third-party suppliers are protected
- Every vulnerability has been patched
- An incident-response plan will work
- Sensitive data has been classified correctly
- The organisation cannot be breached
Secure Score does not cover every attack surface associated with each supported product. Microsoft describes the recommendations as a useful baseline rather than complete protection.
It should be combined with broader cyber security management.
What Else Should You Review?
A comprehensive cyber security programme should also consider:
- Security awareness training
- Vulnerability scanning
- Patch management
- Backup testing
- Incident response
- Cyber Essentials
- Network security
- Supplier risk
- Penetration testing
- Business continuity
- Security monitoring
- Policy and governance
Microsoft Secure Score is valuable, but it is only one view of your organisation’s risk.
How Hamilton Group Can Help
Hamilton Group can review your Microsoft Secure Score, explain the recommendations and create a practical improvement plan.
Our services can include:
- Microsoft Secure Score assessments
- Microsoft 365 security reviews
- Multi-factor authentication
- Conditional Access
- Microsoft Entra identity protection
- Administrator-role reviews
- Email security
- Defender configuration
- Intune device management
- Application-permission reviews
- Information-protection policies
- Security monitoring
- Managed IT support
We focus on meaningful risk reduction rather than increasing the number without considering business impact.
We can identify quick improvements, prioritise more complex projects and document any risks that need to be accepted or addressed through alternative controls.
To discuss improving your Microsoft Secure Score and strengthening your Microsoft 365 environment, contact Hamilton Group on 0330 043 0069 and book an appointment with one of our experts.