Microsoft Secure Score, What It Is, What’s a Good Number, and How to Improve Yours
By Jamie Hamilton · Published
If you have Microsoft 365 and have never opened Secure Score, it is worth half an hour. It is included with what you already pay for, it is in the Microsoft Defender portal, and it will tell you things about your environment that nothing else surfaces in one place.
It will also mislead you if you read the number rather than the list, which is what most people do.
What Secure Score measures
It is a running total. Microsoft maintains a set of recommended actions covering identity, devices, applications and data. Each one carries points. Configure it, and your score goes up. The percentage you see is your points against the total available to you.
Two things follow from that and both matter. It measures configuration, not outcome: it knows whether a control is switched on, not whether it works or whether anybody is watching what it produces. And the denominator moves, because the total available depends on which licences you hold and Microsoft adds and retires actions over time.
Why the percentage is slippery
Because the total is licence-dependent, two businesses with the same percentage can be in very different states, and the same business can see its percentage drop without changing anything, simply because Microsoft added new recommended actions to the pool.
As a rough reading for a Business Premium tenant: below 30% usually means fundamental controls are missing rather than merely unoptimised. Above 50% suggests the basics are in place. Above 70% is a well-managed environment. Those are orientation rather than targets, and chasing a number past the point where the remaining actions stop making sense for your business is a way of spending effort without buying safety.
The more useful reading is the trend and the list. A score that has not moved in a year says nobody is looking, whatever the number is.
The actions worth doing first
Roughly in order of what they buy you against what they cost to do:
- •Enforce MFA for every user, with the exceptions documented. Consistently the highest value action available and the one most often partially done.
- •Block legacy authentication. These are the older protocols that cannot present a second factor, so they go around MFA rather than through it. Blocking them is what makes the previous item true.
- •Make sure every administrative account has MFA registered, and that administrators use dedicated accounts rather than their daily email login.
- •Reduce the number of Global Administrators, and check none of them belong to people or providers who have left.
- •Enable DKIM for every domain you send from, which is usually the fastest email authentication win because it is two DNS records and a switch.
The first two are a pair. MFA with legacy authentication still permitted is a locked front door beside an open window, and the score will happily credit you for the door.
What Secure Score cannot see
This is the part worth internalising, because a good score creates a feeling of completeness that the score itself has not earned.
- •Whether your people can recognise a convincing phishing email, which is where most incidents actually begin
- •Whether you have ever tested restoring from a backup, as opposed to having one configured
- •Whether anybody reads the alerts the controls generate
- •Whether your administrators use a phishing-resistant second factor or an SMS code, which the score treats far more equally than reality does
- •Whether a previous IT provider still holds delegated administrative access to your tenant
- •Whether your DMARC policy is actually enforcing, as opposed to a record existing
Every one of those has caused a real incident somewhere, and none of them moves the number.
How to use it well
Read the list, not the score. Work down the recommended actions and, for each, decide one of three things: do it, do not do it for a reason you write down, or it does not apply. Dismissing an action with a documented reason is a legitimate outcome and Secure Score supports it.
Then check it quarterly rather than continuously. The value is in the movement and in noticing what has appeared, not in the daily figure. A tenant whose score is slowly falling is usually one where new users are being added faster than anybody is configuring them.
Frequently asked questions
What is Microsoft Secure Score?
A running total of how many of Microsoft’s recommended security controls you have configured across identity, devices, applications and data. Each action carries points, and the percentage is your points against the total available for your licences. It lives in the Microsoft Defender portal and it is included with what you already pay for.
What is a good Microsoft Secure Score?
As a rough orientation for a Business Premium tenant, below 30% usually means fundamental controls are missing, above 50% suggests the basics are in place, and above 70% is a well-managed environment. Treat those as directions rather than targets. The total available depends on your licences, so two businesses on the same percentage can be in quite different states, and the trend matters more than the figure.
Why did my Secure Score go down when I changed nothing?
Because the denominator moves. Microsoft adds and retires recommended actions over time, so new actions entering the pool increase the total available and your unchanged points become a smaller share of it. A licence change does the same thing. This is one of the reasons the list is more useful than the number.
What is the fastest way to improve Secure Score?
Enforcing multi-factor authentication for every user and blocking legacy authentication, in that order and treated as a pair. Legacy protocols cannot present a second factor, so they bypass MFA rather than prompting for it, and MFA with legacy authentication still permitted is a locked door beside an open window. After that, dedicated administrator accounts and enabling DKIM are the next best value for the effort.
Is a high Secure Score enough?
No, and a high score is quietly the more dangerous position because it feels finished. The score measures whether controls are configured, not whether they work or whether anybody reads what they produce. It cannot see whether your people would recognise a phishing email, whether a restore has ever been tested, whether alerts are read, or whether a previous IT provider still holds administrative access to your tenant.
How often should I check it?
Quarterly is enough for most small businesses. The value is in the movement rather than the daily figure, and in noticing which actions have newly appeared. A score drifting slowly downwards usually means new users are being added faster than anybody is configuring them, which is worth catching before it becomes the normal state.
Related Articles
Want the open actions read and prioritised for your business rather than in general?
Health Check, $599or call 0403 401 250