Identity and security

Secure Score

Microsoft Secure Score

Microsoft Secure Score is a measurement and benchmarking tool within the Microsoft 365 Defender portal. It converts an organisation's security configuration across identity, devices, applications, and data into a single numeric score, alongside a prioritised list of specific improvement actions.

Why Secure Score matters in a Microsoft estate

Secure Score matters because identity, access, endpoint, and data controls shape how Microsoft environments are protected. Readers should understand the term and then be able to move into security assessment, conformity, or remediation guidance.

How Secure Score shows up in practice

Each action carries a defined point value, based on Microsoft's assessment of its security impact and, for many actions, its implementation effort. The score itself is intentionally comparative rather than absolute. It is presented as a percentage of the maximum achievable score for the organisation's specific licensed products, alongside a benchmark against similar organisations by size and industry. That is meant to answer "how does our posture compare to peers" rather than "are we secure," a distinction worth being precise about: a high percentage score reflects how many of Microsoft's recommended configurations have been implemented, not an independent, holistic assessment of actual resilience against the specific threats an organisation faces.

Each improvement action links directly to where it can be configured. Many, particularly around Conditional Access baselines, Defender policy settings, and Entra ID configuration, can be implemented or partially automated directly from within the Secure Score interface itself. That makes it a genuinely useful starting checklist for organisations early in a security maturity journey, giving a concrete, ranked list of next steps rather than an open-ended "improve security" mandate with no clear starting point.

The score's most significant practical limitation is that it can be gamed, deliberately or not, by implementing recommended controls that do not actually fit the organisation's environment purely to gain points. Examples include enabling a restrictive Conditional Access policy that technically satisfies a scored recommendation but was never properly tested against real sign-in patterns, or completing actions that only apply to features the organisation does not meaningfully use. A security team optimising primarily for the numeric score rather than for actual risk reduction can end up with a high Secure Score and a materially unchanged, or even worse, real-world security posture. Trend tracking over time is where the tool earns most of its ongoing value.

A consistently rising score, tracked against a defined target, gives a concrete, auditable basis for internal security reporting to leadership or a board, translating what would otherwise be a qualitative "we've been working on security" statement into a specific, trackable metric. It is increasingly referenced directly in cyber insurance underwriting conversations and vendor security questionnaires, as one data point alongside more specific controls like MFA coverage and patch cadence, in demonstrating an organisation's overall security investment and trajectory. It does not function as a certification or compliance attestation in its own right.

Related terms

Glossary