Skip to main content

What Is Microsoft Secure Score — and How Can You Improve It?

Media What Is a Microsoft Secure Score? And How Can You Improve It

 

Microsoft Secure Score gives your organisation a numerical view of its security posture across the Microsoft services you use.

A higher score generally means more of Microsoft’s recommended security actions have been completed.

That sounds simple.

But Secure Score is frequently misunderstood.

It is not:

a cyber-security certification

proof that your organisation cannot be breached

a direct percentage chance of being secure

a reason to enable every recommendation blindly


Microsoft describes Secure Score as a measurement of security posture, with a higher score indicating that more recommended actions have been taken.

The useful question is therefore not:

“How do we get to 100%?”

It is:

“Which recommendations materially reduce our business risk?”

Where Do You Find Microsoft Secure Score?

Secure Score is available through the Microsoft Defender portal.

Go to the Microsoft Defender security portal and open:

Secure Score

Microsoft’s current documentation places the Secure Score experience at:

security.microsoft.com/securescore

and provides a dedicated Recommended actions area for improvement opportunities.

Depending on the Microsoft services and licences in your environment, the score can reflect controls relating to areas such as:

identity

devices

applications

data

Microsoft 365 security


The exact recommendations available depend on the services your organisation uses. Microsoft explicitly notes that Secure Score is representative of the Microsoft security services in use.

How Is the Score Calculated?

Each improvement action has a potential point value.

You gain points when Microsoft detects that the associated security control has been implemented or an applicable action has been completed.

Some actions can receive partial credit.

For example, Microsoft notes that Identity Secure Score can award partial completion for controls such as enabling MFA for only some users rather than the entire organisation.

The broad idea is:

Current points ÷ available points = Secure Score percentage

But that percentage should be treated as an indicator of control adoption rather than an absolute statement of security.

Is 100% Secure Score the Goal?

Not necessarily.

In theory, completing every applicable recommendation would maximise the score.

In practice, some recommendations may:

not fit your architecture

conflict with operational requirements

require unavailable licensing

create disproportionate user impact

be mitigated by another control


Microsoft’s own guidance emphasises balancing security with usability, because security controls have an impact on users.

That means a sensible security programme may intentionally leave some points unclaimed.

The important thing is that those decisions are understood and documented.

A company with an 82% score and well-reasoned compensating controls may be in a better real-world position than a company with 95% that enabled recommendations without testing their impact.

Secure Score Is Not a Breach Guarantee

This deserves to be very prominent.

A high Secure Score does not mean:

“We cannot be hacked.”

Attackers do not need your average security posture to be poor.

They need one viable route.

That might be:

stolen credentials

unpatched application

phishing

excessive privilege

exposed remote service

compromised supplier


Microsoft positions Secure Score as a posture measurement and improvement mechanism—not a guarantee of protection.

Use the score as:

a map of improvement opportunities

rather than:

a cyber-security certificate.

Start With Identity

For most Microsoft 365 businesses, identity should be near the top of the priority list.

Why?

Because Microsoft 365 is fundamentally identity-driven.

If an attacker compromises a user or administrator account, they may gain access to:

email

SharePoint

OneDrive

Teams

cloud applications


High-value controls commonly include:

MFA

phishing-resistant authentication

reducing legacy authentication

protecting privileged accounts

reviewing risky sign-ins


Do not simply implement whatever recommendation has the highest point value.

Start with controls that reduce the most dangerous attack paths in your organisation.

MFA Should Be a Baseline, Not a Score-Chasing Exercise

If Secure Score says only part of the organisation has MFA enabled, that is more than a scoring opportunity.

It is a real identity risk.

Microsoft explicitly uses MFA rollout as an example of a control where partial implementation can produce partial score.

But the operational objective should be:

protect the accounts that matter

not:

collect the points.

Pay particular attention to:

administrators

finance

executives

users with access to sensitive systems


For privileged roles, stronger phishing-resistant methods may be more appropriate than relying solely on push notifications or SMS.

Protect Administrator Accounts Separately

A normal employee account and a Global Administrator account should not necessarily have identical security treatment.

Review:

number of administrators

standing privilege

MFA strength

emergency access accounts

daily-use administrator accounts


A high Secure Score combined with excessive administrative privilege is still an uncomfortable environment.

Least privilege should be part of the security discussion even where it does not produce the most dramatic immediate score increase.

Device Security Matters Too

Secure Score can also reflect device security where the organisation uses Microsoft Defender and related services.

Microsoft’s current Secure Score for Devices represents the collective configuration state of devices across areas including operating system, applications, network and security controls.

Relevant improvements may involve:

endpoint protection

firewall

attack-surface reduction

encryption

vulnerability remediation

security configuration


This is another reason Secure Score is more useful when considered alongside Defender Vulnerability Management and Exposure Management rather than viewed as an isolated percentage.

Microsoft now explicitly prioritises security recommendations using factors including threat, breach likelihood and value.

Prioritise Risk, Not Points

Imagine Secure Score offers:

Recommendation A

Worth 8 points.

Low business impact if ignored.

Recommendation B

Worth 2 points.

Closes a real attack path against a critical finance system.

Which should you do first?

Probably:

B.

This is where chasing the percentage becomes dangerous.

Microsoft’s newer Exposure Management approach combines posture information with risk and attack-surface context to help organisations prioritise what actually matters.

Use Secure Score together with:

vulnerability severity

exploitability

asset importance

privileged access

business impact


That produces a much stronger remediation plan.

Use the Recommended Actions Page Properly

In Secure Score, open:

Recommended actions

For each recommendation, review:

potential score increase

affected users/devices

implementation details

user impact

prerequisites

whether it applies to your environment


Microsoft documents this area as the main place to work through improvement actions.

Do not implement 25 recommendations in one afternoon.

Prioritise them.

Test changes.

Then measure the effect.

Look at Score History

One of Secure Score’s most useful features is the ability to track changes over time.

Microsoft provides history and trends so organisations can understand which activities caused their score to increase or regress.

This lets you answer:

Why did our score fall this week?

Possible reasons include:

configuration regression

new users

new devices

Microsoft adding/reweighting recommendations

licences changing

controls being removed


A falling score does not automatically mean somebody changed a setting incorrectly.

Microsoft continues to update Secure Score recommendations and calculations as its security products evolve.

Don't Panic When the Score Changes Unexpectedly

This is worth adding.

Secure Score is not completely static.

Your percentage can change because Microsoft changes:

recommendations

scoring

product integration

available controls


So if the score drops from:

78% → 70%

don't immediately assume eight percentage points of security vanished overnight.

Check the history.

Identify exactly which recommendations changed.

Then decide whether action is required.

Licensing Affects What You Can Score

Secure Score only reflects controls associated with the services available in the environment.

That means two similar companies can have different:

available recommendations

maximum score

achievable actions


depending on licensing and products deployed.

Microsoft explicitly says Secure Score represents the Microsoft security services your organisation uses.

So comparing:

Company A = 82%

with:

Company B = 74%

isn't necessarily meaningful unless their environments are broadly comparable.

Don't Buy Licences Just to Increase Secure Score

This follows naturally.

A recommendation may require:

Defender

Intune

Entra capabilities

another security licence


That does not automatically mean buying that licence is bad.

It means the business case should be:

risk reduction + operational value

not:

the score will go up.

The score is a consequence.

Security value is the objective.

Document Accepted Risks

Suppose a recommendation is technically valid but inappropriate for a particular workload.

Do not simply ignore it forever.

Document:

why it isn't being implemented

what risk remains

compensating controls

review date

owner


Modern Microsoft security products also increasingly support exceptions/exclusions so organisations can distinguish genuinely accepted risk from simply unfinished work. Defender Vulnerability Management, for example, supports exceptions that can affect exposure and secure-score reporting.

This makes reporting more honest.

A Practical Improvement Order for SMEs

For many SMEs, I would prioritise something like:

1. Identity

MFA, strong authentication, privileged accounts.

2. Email

Phishing and malicious-content protection.

3. Devices

Endpoint protection, encryption, patching and attack-surface controls.

4. Permissions

Reduce excessive access and old privileged accounts.

5. Vulnerabilities

Address exploitable weaknesses on important systems.

6. Data

Review sensitive-data and sharing controls.

7. Lower-impact optimisation

Then work through less urgent recommendations.

That order will vary by organisation.

The point is to create a risk-based roadmap, not blindly sort by Secure Score points.

How Often Should You Review Secure Score?

Not once a year.

Secure Score should form part of an ongoing security-management process.

A reasonable business workflow might be:

weekly or monthly review

depending on the organisation’s size and risk.

Look for:

regressions

new recommendations

high-impact actions

unresolved identity risks

device posture changes


Microsoft now also provides broader security-summary reporting across the Microsoft security products available to the organisation, giving administrators another way to communicate security posture and improvements to stakeholders.

Secure Score vs Exposure Score

This distinction is increasingly useful in 2026.

Think of:

Secure Score

as:

How much recommended security hardening have we implemented?

and Exposure Management as helping answer:

Where are attackers most likely to find useful routes through our environment?

Microsoft Security Exposure Management provides a broader attack-surface view across identities, devices, cloud resources and other assets.

You want both perspectives.

A configuration score without attack-path context is incomplete.

Attack-path information without improving configuration is also incomplete.

Secure Score vs Compliance

A high Secure Score does not prove compliance with:

Cyber Essentials

ISO 27001

GDPR

contractual requirements

industry-specific standards


Those frameworks have their own requirements.

Secure Score can provide useful evidence and identify controls that support a wider security programme.

But:

security score ≠ compliance certification.

That distinction should be explicit in any board-level discussion.

Don't Use Secure Score as an Employee KPI

Another trap is turning:

“Get the Secure Score above 90%”

into somebody's performance target.

That creates an incentive to maximise points rather than reduce risk.

A better objective is:

reduce high-impact exposure while increasing appropriate security-control adoption.

The score should inform the decision.

It should not become the decision.

A Useful Board-Level Explanation

If a director asks:

“Our Microsoft Secure Score is 72%. Is that good?”

a better answer is:

> Secure Score shows how many Microsoft-recommended security controls we have implemented. The trend is useful, but the percentage alone doesn't tell us whether our most serious business risks are controlled. We use it alongside vulnerability, identity, endpoint and incident data to prioritise improvements.

 

That is much more meaningful than:

72% = pretty secure.

The Secure Score Checklist

When reviewing Microsoft Secure Score:

1. Open Recommended actions.


2. Identify identity and privileged-access risks first.


3. Check endpoint/device recommendations.


4. Compare actions against real business risk.


5. Consider user and operational impact.


6. Prioritise exploitable weaknesses and critical assets.


7. Implement changes in controlled stages.


8. Track history and investigate regressions.


9. Document accepted risks and exceptions.


10. Review it regularly.


11. Combine Secure Score with vulnerability and exposure data.


12. Never treat the percentage as proof that the organisation is secure.

 

The key principle is:

Improve security first. Let the score follow.

How Hamilton Group Can Help

Hamilton Group can help businesses turn Microsoft Secure Score from a dashboard percentage into an actionable security-improvement programme.

We can help with:

Microsoft Secure Score reviews

Microsoft Defender

Microsoft Entra ID

MFA

Conditional Access

endpoint security

vulnerability management

Microsoft Intune

Microsoft 365 security

security hardening

remediation planning


The objective is not simply to make the number bigger.

It is to identify the controls that will meaningfully reduce the chance and impact of a security incident.

Visit hgmssp.com or call 0330 043 0069 to discuss a Microsoft 365 security review.