Microsoft Secure Score
Security Posture
Microsoft Secure Score is a built-in security measurement tool that helps organizations identify risks, implement recommended security controls, and continuously improve their Microsoft 365 security posture. By reviewing your Secure Score and applying Microsoft's best-practice recommendations, businesses can reduce vulnerabilities, improve compliance, and gain greater visibility into their organization's security health.
Need help?
Contact Us
What is Microsoft Secure Score?
Microsoft Secure Score is a built-in security measurement tool within Microsoft 365 and Microsoft Defender that helps organisations understand and improve their cybersecurity posture. It provides a numerical score that represents how well your Microsoft 365 environment is protected against common security threats such as phishing, malware, and unauthorised access.
The score is calculated based on the security controls and configurations enabled across your Microsoft 365 services. As recommended security settings are implemented, the score increases, giving businesses a clear way to track improvements and identify areas that require attention.
Microsoft Secure Score is more than just a number — it provides organisations with a clear and measurable view of their Microsoft 365 security posture. By analysing security configurations across identities, devices, applications, and data, Secure Score highlights areas where improvements can significantly reduce cybersecurity risks.
How It WorksWhy Microsoft Secure Score Matters
Microsoft Secure Score is more than just a number — it provides organisations with a clear and measurable view of their Microsoft 365 security posture
Visibility
Understand what security controls are enabled and where improvements are needed across your Microsoft 365 environment.
Accountability
Assign recommended actions to IT teams and track security improvements over time with measurable goals.
Continuous Improvement
Monitor how your organisation's security posture evolves as new protections are implemented across your tenant.
Benchmarking
Compare your Secure Score against similar organisations and industry standards to understand your competitive position.
Compliance Alignment
Many recommendations support frameworks such as the ACSC Essential Eight, ISO 27001, NIST, and GDPR.
How is Microsoft Secure Score Calculated?
Understanding how your Microsoft Secure Score is calculated is key to improving your Microsoft 365 security posture and strengthening your overall cybersecurity framework. Secure Score provides a measurable benchmark to assess how effectively your organisation protects identities, devices, data, and applications.
Your Microsoft Secure Score is displayed as a percentage that reflects how your current security configuration compares to Microsoft's recommended best practices. The score is calculated based on the security controls and configurations enabled across your Microsoft 365 services.
While Secure Score isn't a compliance tool, improving your score often aligns with regulatory frameworks like ISO 27001, NIST, and GDPR. It's a solid step in your compliance journey. As recommended security settings are implemented, the score increases, giving businesses a clear way to track improvements and identify areas that require attention.
Improve Your Score
Secure Score Categories
Secure Score is divided into four main categories that cover the full spectrum of your Microsoft 365 security posture
Identity Protection
Multi-Factor Authentication (MFA), secure sign-in policies, Conditional Access, Entra ID Protection, password policies, admin account protection, and legacy authentication blocking.
Device Security
Compliance policies, endpoint protection, Microsoft Intune device management, device health monitoring, and attack surface reduction rules across Windows, macOS, iOS, and Android.
Data Protection
Email security, file protection controls, Data Loss Prevention (DLP), sensitivity labels, SharePoint and OneDrive sharing controls, and Microsoft Purview compliance tools.
Application Security
Safe configuration of Microsoft 365 services, Microsoft Defender for Office 365, Safe Links, Safe Attachments, anti-phishing policies, and impersonation protection.
How to Improve Your Secure Score
Microsoft provides specific recommendations to improve your Secure Score. Addressing Identity actions first delivers the highest risk reduction per point. Complete these before moving to other categories.
Enable Multi-Factor Authentication (MFA) for all users
The single most impactful control in any M365 tenant. Password compromise does not lead to account takeover when MFA is required. Ideally enforced via Conditional Access policy rather than per-user MFA, which gives more granular control and supports phishing-resistant methods.
Disable legacy authentication protocols
Disable legacy authentication protocols (e.g., POP, IMAP, SMTP basic auth). Legacy protocols do not support MFA and represent a significant attack vector for credential theft and account compromise.
Apply Intune compliance policies
Apply Intune compliance policies for device health and encryption. Ensure only trusted and compliant devices can access company systems through device compliance policies and endpoint protection.
Use Microsoft Defender for Office 365
Use Microsoft Defender for Office 365 to protect against phishing and malware. Deploy Safe Links and Safe Attachments for real-time content scanning and anti-phishing impersonation protections.
Deploy Sensitivity Labels
Deploy Sensitivity Labels to classify and protect data across Microsoft 365. Ensure only authorised users access sensitive content, whether stored or shared, supporting zero-trust data protection.
Implement Conditional Access
Implement Conditional Access to enforce secure access rules. Define policies that evaluate user identity, device compliance, location, risk level, and application type before granting access.
Audit privileged roles
Audit privileged roles and restrict global admin usage. Enforce least-privilege access with Role-Based Access Control (RBAC) and Privileged Identity Management (PIM).
Enable Safe Links and Safe Attachments
Enable Safe Links and Safe Attachments for real-time content scanning. Protect against phishing attempts, malware, and ransomware attacks across email, Teams, and SharePoint.
How Often Should You Review Your Secure Score?
Regularly reviewing your Microsoft Secure Score is essential for maintaining a strong Microsoft 365 security posture. We recommend reviewing your Secure Score monthly, or weekly for high-risk industries such as healthcare, finance, or legal services.
Monthly Reviews
As your environment evolves — adding new users, devices, applications, or licences — new security recommendations may appear. Making Secure Score reviews part of your ongoing IT security checklist ensures continuous improvement and proactive risk management.
- Review all new recommended actions from the previous period
- Revisit Risk accepted items to confirm justification is still valid
- Check whether any previously unlicensed actions have become available
- Export the list to CSV and attach to security review documentation
Key Best Practices
- Address all Identity actions with "Have license? = Yes" first
- Document every "Risk accepted" decision with reason, date, and owner
- Do not treat Secure Score as a substitute for a security assessment
- Review weekly for high-risk industries (healthcare, finance, legal)
- Track changes over time rather than chasing a specific number
Important Limitations to Consider
- • Not all third-party security tools are reflected in your score
- • Some recommendations may not apply to your licensing or business needs
- • Secure Score is not a guarantee of protection — it is a baseline framework to guide stronger cybersecurity resilience
- • Secure Score does not evaluate Conditional Access policy quality, RBAC hygiene, incident response capability, or user awareness
Need Help Improving Your Secure Score?
Microsoft Secure Score is a powerful tool for organizations looking to enhance their Microsoft 365 security posture. It offers visibility, direction, and measurable goals in a format that's easy to understand. Whether you're an SMB or an enterprise, reviewing your Secure Score regularly and acting on its recommendations should be a core part of your cybersecurity strategy. Partnering with a proven and skilled Microsoft 365 Security partner can help you achieve the best combination between a secure IT environment and a great user experience.
Useful Links
Microsoft Secure Score Portal
Access your organisation's Microsoft Secure Score directly in the Microsoft Defender portal to review recommendations and track improvements.
Find Out More →Microsoft Secure Score Documentation
Official Microsoft documentation explaining how Secure Score works, how it's calculated, and how to interpret your results.
Find Out More →Microsoft 365 Cyber Security
Learn how Microsoft 365 provides comprehensive cybersecurity features to protect your business from modern threats.
Find Out More →Frequently Asked Questions
Common questions about Microsoft Secure Score
Microsoft Secure Score is a built-in tool in Microsoft 365 that helps organizations understand and improve their security posture. It analyzes your current configuration and behaviors and provides a score along with recommended actions to enhance security. It provides a numerical score representing how well your Microsoft 365 environment is protected against common security threats.
Your Secure Score is displayed as a percentage that reflects how your current security configuration compares to Microsoft's recommended best practices. It is calculated based on the security controls and configurations enabled across your Microsoft 365 services, including identity protection, device security, data protection, and application security.
We recommend reviewing your Secure Score at least monthly, or weekly if you're in a regulated industry or working toward compliance. Secure Score updates automatically as your environment changes — adding new users, devices, applications, or licences may trigger new recommendations.
Absolutely. We specialize in Microsoft 365 security, and we can assess your current score, implement best-practice policies, remediate high-risk items, monitor improvements over time, and provide Secure Score reports in our quarterly IT reviews.
While a higher score generally indicates stronger security configurations, Secure Score is not a guarantee of protection. It is a baseline framework to guide cybersecurity improvements. Some recommendations may not apply to your licensing or business needs, and not all third-party security tools are reflected in your score.
While Secure Score isn't a compliance tool, improving your score often aligns with regulatory frameworks like ISO 27001, NIST, and GDPR. Many recommendations also support frameworks such as the ACSC Essential Eight. It's a solid step in your compliance journey.
Secure Score is divided into four main categories: Identity (user accounts, authentication, Conditional Access), Device (endpoint compliance, Defender for Endpoint, Intune), Data (classification, sensitivity labels, DLP policies), and Apps (Defender for Office 365, Exchange Online Protection, Teams, SharePoint).
No. Secure Score is a configuration score, not a threat score. It measures how many of Microsoft's recommended settings are enabled in your tenant. It does not tell you whether you are currently under attack or compromised. Use it as a configuration hygiene baseline alongside other security monitoring tools.