What Microsoft Secure Score measures, and what it doesn't
Microsoft Secure Score tracks how many of Microsoft's recommended security configurations an organization has turned on, across whichever Microsoft 365 and partner products it holds a license for. That makes it genuinely useful for watching configuration adoption over time and comparing against similarly sized organizations. It does not measure whether the organization has actually been attacked, whether sensitive data is labeled, whether backups would restore, or whether anyone reads the alerts a licensed product raises. This is for the IT lead asked to explain what a specific score means, and for the owner who set the target in the first place.
01 / 11
A board asks for a number above seventy
Consider a fictional 90-person distributor. At the quarterly board meeting, a director who read about a competitor's ransomware incident asks IT to get the Microsoft Secure Score above seventy. IT nods, opens the Microsoft Defender portal, and finds the number sitting at fifty-eight.
The instruction sounds like a security target, and everyone in the room treats it that way. It is actually a target for something narrower: how many of Microsoft's own recommended configurations, across the products the company already pays for, are switched on. That is a genuinely useful number to track. It is not the number most boards think they just asked for.
02 / 11
What the number actually is
Microsoft's own definition is plain: Microsoft Secure Score is a measurement of an organization's security posture, with a higher number indicating more recommended actions taken. You earn points, per Microsoft, for three kinds of activity: Configuring recommended security features, Doing security-related tasks, and Addressing the recommended action with a non-Microsoft application or software, or an alternate mitigation.
Recommendations only appear for products the tenant is licensed for, and once there is any license for a product family, Microsoft shows every recommendation in that family regardless of the specific plan. As of 7 March 2026, Microsoft lists recommendations across identity, devices, apps and data — Microsoft Entra ID, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Office, Exchange Online, Microsoft Defender for Cloud Apps, Microsoft Purview Information Protection, Microsoft Teams and SharePoint Online among them, plus a handful of non-Microsoft apps including Docusign, GitHub, Okta, Salesforce, ServiceNow and Zoom.
03 / 11
How a single point gets earned
Each recommended action is worth ten points or less, and Microsoft scores most of them one of two ways. In its own words: If you implement the recommended action, like create a new policy or turn on a specific setting, you get 100% of the points. For other recommended actions, points are given as a percentage of the total configuration.
Microsoft's own worked example shows the second kind clearly: a recommendation worth ten points for protecting every user with multifactor authentication, with only fifty of one hundred users actually covered, pays out at fifty protected divided by one hundred total, times ten maximum points, equal to five points. Half the users, half the points. Nothing in that formula asks whether the fifty unprotected accounts include the finance director's.
04 / 11
Five statuses, and only one that pays nothing
Every recommended action carries a status someone in IT sets, and the five choices are not interchangeable:
- To address — you recognize that the recommended action is necessary and plan to address it at some point in the future. No points yet.
- Planned — there are concrete plans in place to complete the recommended action. No points yet either; the separate Planned score view projects what the total would be once these land.
- Risk accepted — the organization chooses not to act, and you won't be given any points for this status.
- Resolved through third party — a non-Microsoft product already covers it. The action gains the points that the action is worth, but Microsoft will have no visibility into the completeness of implementation.
- Resolved through alternate mitigation — the same trade, credited for an internal control instead of a vendor's product.
05 / 11
How often the number actually moves
Only risk accepted rules points out for good; to address and planned wait on Microsoft's own data, while the two resolved-elsewhere statuses pay in full, on the word of whoever set the status. Microsoft names that trade openly rather than auditing it — it takes the tenant's account of what covers the gap.
The number does not update on one clock, either. Visualizations and recommended-action pages refresh in real time, and Secure Score syncs daily to pull in achieved points. Two products move on a slower, published cadence: For Microsoft Teams and Microsoft Entra related recommendations, the recommendation state will get updated when changes occur in the configuration state. In addition, the recommendation state is refreshed once a month or once a week, respectively. Fix a Conditional Access gap on a Tuesday, and Entra's slice of the score may not catch up until the following week.
06 / 11
Why the number can fall without an attack
A new license changes what can be seen, not what has already been done. Microsoft's own wording: We show you the full set of possible recommendations for a product, regardless of license edition, subscription, or plan... Your absolute security posture, represented by Secure Score, stays the same no matter what licenses your organization owns for a specific product.
Read that against the intuition most owners bring to the number. Upgrading the plan on a product already held does not unlock a new pool of recommendations, because every one of them was already visible. What does move the total is licensing a product that was not held before — Defender for Identity, say, where there was none. That adds a fresh set of recommendations to the denominator, unmet on day one. Our reading, not Microsoft's own wording: a purchase on Tuesday can lower Friday's percentage, simply because there is now more that could have been done.
The other mover is Microsoft's own catalogue. Its changelog for the score states the intent directly: To make Microsoft Secure Score a better representative of your security posture, we continue to add new features and improvement actions. Every addition enlarges the total for every tenant already licensed for that product, whether or not anyone touched a setting that week.
07 / 11
The comparison the board actually wanted
Above seventy is really a request for a competitive baseline, and Microsoft does supply one, with a guardrail attached. Under Metrics and trends, a comparison trend chart shows how the organization's score compares with others' over time, and a comparison bar chart on the Overview tab does the same for a single point in time. Microsoft states the limit plainly: the comparison data is anonymized so we don't know exactly which other tenants are in the mix. What comes back is an average banded by similar seat count, not a named competitor.
Three further score views sit next to the headline number, each answering a different question. Planned score projects the total once planned actions land. Current license score shows what is reachable with the licenses already owned. Achievable score shows what is reachable given those licenses and the risk already chosen to accept. None of the four is the score. They are the same number under four different assumptions, and a board that hears only one of them is hearing a quarter of the picture.
08 / 11
What Microsoft itself says the score is not
Below the dashboard, in a section titled Risk awareness, Microsoft states its own limit directly, and it is worth reading in full because it cuts against how the number gets used in board meetings: Microsoft Secure Score is a numerical summary of your security posture based on system configurations, user behavior, and other security-related measurements. It isn't an absolute measurement of how likely your system or data could be breached. Rather, it represents the extent to which you are using security controls in your Microsoft environment that can help offset the risk of being breached. No online service is immune from security breaches, and secure score shouldn't be interpreted as a guarantee against security breach in any manner.
Two tenants can land on the same seventy-eight with very different exposure. One has every recommended control switched on and a finance team nobody has trained on phishing. The other has weaker configuration and a security lead who reads every alert the same day it fires. Secure Score cannot see either fact, because neither is a configuration Microsoft can check. Whether the organization was actually attacked, whether its sensitive files are labeled, whether last night's backup would restore, and whether a human reads what a licensed product raises — none of it enters the formula. That is not a flaw so much as the boundary the name already promises: a secure score, not a secured one.
09 / 11
Who can see it, and who can change it
Viewing and changing the score are governed by role, not by license. Full read-and-write access — able to change a status, edit score zones, or set custom comparisons — goes to Security Administrator or higher, plus Exchange Administrator and SharePoint Administrator. A longer list can look without touching: Helpdesk Administrator, User Administrator, Service Support Administrator, Security Reader, Security Operator and Global Reader. Anyone outside those roles does not see the score at all.
That split is worth keeping in mind before the next board meeting. The person able to move the number and the person who reports it to leadership are often not the same seat, and Microsoft's own guidance leans toward keeping it that way: Microsoft recommends that you use roles with the fewest permissions.
10 / 11
The questions the number can't answer
Put the board's real question next to what Secure Score actually covers, and the gap is easy to see:
| Question | Answered by Secure Score | What answers it instead |
|---|---|---|
| Were we attacked recently? | No | Defender incidents and alerts |
| Is sensitive data labeled? | No | Microsoft Purview labeling |
| Would last night's backup restore? | No | Nobody knows; test it |
| Does anyone read the alerts? | No | A named job, not a score |
| Are recommended settings on? | Yes | Exactly what it counts |
| How do we compare to peers? | Partly | Anonymized, seat-banded |
11 / 11
Where to start
Before the next board meeting, do not chase the headline number. Open Recommended actions, filter to anything marked Risk accepted or Resolved through third party, and read the notes attached to each one. If more than a couple carry no note at all, that is the real finding — not what the score is, but what nobody has actually verified. Fixing that is a free afternoon, not a purchase.
Disclosure: this is a category we sell into. Avalon CloudSec tracks an organization's Secure Score and its improvement actions over time, alongside its own separate 0-100 risk score that lists every contributing factor and its weight rather than compressing them into one figure. The two are never blended: Microsoft's score stays Microsoft's, and Avalon's stays labeled as Avalon's. One limitation worth naming plainly: neither number tells you whether a person actually read what it found, only that the finding exists somewhere it can be found again. Questions on either score, email support@awservices.org.
Microsoft, Microsoft 365, Azure, Entra, Intune and Defender are trademarks of the Microsoft group of companies. Avalon CloudSec is an independent service and is not endorsed by Microsoft.
Primary sources
- Microsoft — Microsoft Secure Score, updated 7 March 2026
- Microsoft — Assess your security posture through Microsoft Secure Score, updated 28 April 2025
- Microsoft — Track your Microsoft Secure Score history and meet goals, updated 28 April 2025
- Microsoft — What's new in Microsoft Secure Score, updated 19 February 2024