What Is Microsoft Secure Score — and How Can You Improve It?
Microsoft Secure Score gives your organisation a numerical view of its security posture across the Microsoft services you use.
A higher score generally means more of Microsoft’s recommended security actions have been completed.
That sounds simple.
But Secure Score is frequently misunderstood.
It is not:
a cyber-security certification
proof that your organisation cannot be breached
a direct percentage chance of being secure
a reason to enable every recommendation blindly
Microsoft describes Secure Score as a measurement of security posture, with a higher score indicating that more recommended actions have been taken.
The useful question is therefore not:
“How do we get to 100%?”
It is:
“Which recommendations materially reduce our business risk?”
Where Do You Find Microsoft Secure Score?
Secure Score is available through the Microsoft Defender portal.
Go to the Microsoft Defender security portal and open:
Secure Score
Microsoft’s current documentation places the Secure Score experience at:
security.microsoft.com/securescore
and provides a dedicated Recommended actions area for improvement opportunities.
Depending on the Microsoft services and licences in your environment, the score can reflect controls relating to areas such as:
identity
devices
applications
data
Microsoft 365 security
The exact recommendations available depend on the services your organisation uses. Microsoft explicitly notes that Secure Score is representative of the Microsoft security services in use.
How Is the Score Calculated?
Each improvement action has a potential point value.
You gain points when Microsoft detects that the associated security control has been implemented or an applicable action has been completed.
Some actions can receive partial credit.
For example, Microsoft notes that Identity Secure Score can award partial completion for controls such as enabling MFA for only some users rather than the entire organisation.
The broad idea is:
Current points ÷ available points = Secure Score percentage
But that percentage should be treated as an indicator of control adoption rather than an absolute statement of security.
Is 100% Secure Score the Goal?
Not necessarily.
In theory, completing every applicable recommendation would maximise the score.
In practice, some recommendations may:
not fit your architecture
conflict with operational requirements
require unavailable licensing
create disproportionate user impact
be mitigated by another control
Microsoft’s own guidance emphasises balancing security with usability, because security controls have an impact on users.
That means a sensible security programme may intentionally leave some points unclaimed.
The important thing is that those decisions are understood and documented.
A company with an 82% score and well-reasoned compensating controls may be in a better real-world position than a company with 95% that enabled recommendations without testing their impact.
Secure Score Is Not a Breach Guarantee
This deserves to be very prominent.
A high Secure Score does not mean:
“We cannot be hacked.”
Attackers do not need your average security posture to be poor.
They need one viable route.
That might be:
stolen credentials
unpatched application
phishing
excessive privilege
exposed remote service
compromised supplier
Microsoft positions Secure Score as a posture measurement and improvement mechanism—not a guarantee of protection.
Use the score as:
a map of improvement opportunities
rather than:
a cyber-security certificate.
Start With Identity
For most Microsoft 365 businesses, identity should be near the top of the priority list.
Why?
Because Microsoft 365 is fundamentally identity-driven.
If an attacker compromises a user or administrator account, they may gain access to:
SharePoint
OneDrive
Teams
cloud applications
High-value controls commonly include:
MFA
phishing-resistant authentication
reducing legacy authentication
protecting privileged accounts
reviewing risky sign-ins
Do not simply implement whatever recommendation has the highest point value.
Start with controls that reduce the most dangerous attack paths in your organisation.
MFA Should Be a Baseline, Not a Score-Chasing Exercise
If Secure Score says only part of the organisation has MFA enabled, that is more than a scoring opportunity.
It is a real identity risk.
Microsoft explicitly uses MFA rollout as an example of a control where partial implementation can produce partial score.
But the operational objective should be:
protect the accounts that matter
not:
collect the points.
Pay particular attention to:
administrators
finance
executives
users with access to sensitive systems
For privileged roles, stronger phishing-resistant methods may be more appropriate than relying solely on push notifications or SMS.
Protect Administrator Accounts Separately
A normal employee account and a Global Administrator account should not necessarily have identical security treatment.
Review:
number of administrators
standing privilege
MFA strength
emergency access accounts
daily-use administrator accounts
A high Secure Score combined with excessive administrative privilege is still an uncomfortable environment.
Least privilege should be part of the security discussion even where it does not produce the most dramatic immediate score increase.
Device Security Matters Too
Secure Score can also reflect device security where the organisation uses Microsoft Defender and related services.
Microsoft’s current Secure Score for Devices represents the collective configuration state of devices across areas including operating system, applications, network and security controls.
Relevant improvements may involve:
endpoint protection
firewall
attack-surface reduction
encryption
vulnerability remediation
security configuration
This is another reason Secure Score is more useful when considered alongside Defender Vulnerability Management and Exposure Management rather than viewed as an isolated percentage.
Microsoft now explicitly prioritises security recommendations using factors including threat, breach likelihood and value.
Prioritise Risk, Not Points
Imagine Secure Score offers:
Recommendation A
Worth 8 points.
Low business impact if ignored.
Recommendation B
Worth 2 points.
Closes a real attack path against a critical finance system.
Which should you do first?
Probably:
B.
This is where chasing the percentage becomes dangerous.
Microsoft’s newer Exposure Management approach combines posture information with risk and attack-surface context to help organisations prioritise what actually matters.
Use Secure Score together with:
vulnerability severity
exploitability
asset importance
privileged access
business impact
That produces a much stronger remediation plan.
Use the Recommended Actions Page Properly
In Secure Score, open:
Recommended actions
For each recommendation, review:
potential score increase
affected users/devices
implementation details
user impact
prerequisites
whether it applies to your environment
Microsoft documents this area as the main place to work through improvement actions.
Do not implement 25 recommendations in one afternoon.
Prioritise them.
Test changes.
Then measure the effect.
Look at Score History
One of Secure Score’s most useful features is the ability to track changes over time.
Microsoft provides history and trends so organisations can understand which activities caused their score to increase or regress.
This lets you answer:
Why did our score fall this week?
Possible reasons include:
configuration regression
new users
new devices
Microsoft adding/reweighting recommendations
licences changing
controls being removed
A falling score does not automatically mean somebody changed a setting incorrectly.
Microsoft continues to update Secure Score recommendations and calculations as its security products evolve.
Don't Panic When the Score Changes Unexpectedly
This is worth adding.
Secure Score is not completely static.
Your percentage can change because Microsoft changes:
recommendations
scoring
product integration
available controls
So if the score drops from:
78% → 70%
don't immediately assume eight percentage points of security vanished overnight.
Check the history.
Identify exactly which recommendations changed.
Then decide whether action is required.
Licensing Affects What You Can Score
Secure Score only reflects controls associated with the services available in the environment.
That means two similar companies can have different:
available recommendations
maximum score
achievable actions
depending on licensing and products deployed.
Microsoft explicitly says Secure Score represents the Microsoft security services your organisation uses.
So comparing:
Company A = 82%
with:
Company B = 74%
isn't necessarily meaningful unless their environments are broadly comparable.
Don't Buy Licences Just to Increase Secure Score
This follows naturally.
A recommendation may require:
Defender
Intune
Entra capabilities
another security licence
That does not automatically mean buying that licence is bad.
It means the business case should be:
risk reduction + operational value
not:
the score will go up.
The score is a consequence.
Security value is the objective.
Document Accepted Risks
Suppose a recommendation is technically valid but inappropriate for a particular workload.
Do not simply ignore it forever.
Document:
why it isn't being implemented
what risk remains
compensating controls
review date
owner
Modern Microsoft security products also increasingly support exceptions/exclusions so organisations can distinguish genuinely accepted risk from simply unfinished work. Defender Vulnerability Management, for example, supports exceptions that can affect exposure and secure-score reporting.
This makes reporting more honest.
A Practical Improvement Order for SMEs
For many SMEs, I would prioritise something like:
1. Identity
MFA, strong authentication, privileged accounts.
2. Email
Phishing and malicious-content protection.
3. Devices
Endpoint protection, encryption, patching and attack-surface controls.
4. Permissions
Reduce excessive access and old privileged accounts.
5. Vulnerabilities
Address exploitable weaknesses on important systems.
6. Data
Review sensitive-data and sharing controls.
7. Lower-impact optimisation
Then work through less urgent recommendations.
That order will vary by organisation.
The point is to create a risk-based roadmap, not blindly sort by Secure Score points.
How Often Should You Review Secure Score?
Not once a year.
Secure Score should form part of an ongoing security-management process.
A reasonable business workflow might be:
weekly or monthly review
depending on the organisation’s size and risk.
Look for:
regressions
new recommendations
high-impact actions
unresolved identity risks
device posture changes
Microsoft now also provides broader security-summary reporting across the Microsoft security products available to the organisation, giving administrators another way to communicate security posture and improvements to stakeholders.
Secure Score vs Exposure Score
This distinction is increasingly useful in 2026.
Think of:
Secure Score
as:
How much recommended security hardening have we implemented?
and Exposure Management as helping answer:
Where are attackers most likely to find useful routes through our environment?
Microsoft Security Exposure Management provides a broader attack-surface view across identities, devices, cloud resources and other assets.
You want both perspectives.
A configuration score without attack-path context is incomplete.
Attack-path information without improving configuration is also incomplete.
Secure Score vs Compliance
A high Secure Score does not prove compliance with:
Cyber Essentials
ISO 27001
GDPR
contractual requirements
industry-specific standards
Those frameworks have their own requirements.
Secure Score can provide useful evidence and identify controls that support a wider security programme.
But:
security score ≠ compliance certification.
That distinction should be explicit in any board-level discussion.
Don't Use Secure Score as an Employee KPI
Another trap is turning:
“Get the Secure Score above 90%”
into somebody's performance target.
That creates an incentive to maximise points rather than reduce risk.
A better objective is:
reduce high-impact exposure while increasing appropriate security-control adoption.
The score should inform the decision.
It should not become the decision.
A Useful Board-Level Explanation
If a director asks:
“Our Microsoft Secure Score is 72%. Is that good?”
a better answer is:
> Secure Score shows how many Microsoft-recommended security controls we have implemented. The trend is useful, but the percentage alone doesn't tell us whether our most serious business risks are controlled. We use it alongside vulnerability, identity, endpoint and incident data to prioritise improvements.
That is much more meaningful than:
72% = pretty secure.
The Secure Score Checklist
When reviewing Microsoft Secure Score:
1. Open Recommended actions.
2. Identify identity and privileged-access risks first.
3. Check endpoint/device recommendations.
4. Compare actions against real business risk.
5. Consider user and operational impact.
6. Prioritise exploitable weaknesses and critical assets.
7. Implement changes in controlled stages.
8. Track history and investigate regressions.
9. Document accepted risks and exceptions.
10. Review it regularly.
11. Combine Secure Score with vulnerability and exposure data.
12. Never treat the percentage as proof that the organisation is secure.
The key principle is:
Improve security first. Let the score follow.
How Hamilton Group Can Help
Hamilton Group can help businesses turn Microsoft Secure Score from a dashboard percentage into an actionable security-improvement programme.
We can help with:
Microsoft Secure Score reviews
Microsoft Defender
Microsoft Entra ID
MFA
Conditional Access
endpoint security
vulnerability management
Microsoft Intune
Microsoft 365 security
security hardening
remediation planning
The objective is not simply to make the number bigger.
It is to identify the controls that will meaningfully reduce the chance and impact of a security incident.
Visit hgmssp.com or call 0330 043 0069 to discuss a Microsoft 365 security review.