Glossary
Secure Score
By Emil Björk · Microsoft ecosystem consultant, Gothenburg
Microsoft's numeric score of a tenant's security posture, with prioritised improvement actions.
Microsoft Secure Score (at security.microsoft.com/securescore) is a numeric score of a tenant's security posture against Microsoft's recommended security controls. Each recommended action is worth points; implementing it raises the score. The portal lists current score, score over time, comparison to similar organisations, and a prioritised backlog of actions covering Microsoft 365 apps, identity (Entra ID), endpoints (Defender for Endpoint), and apps. Secure Score isn't an exhaustive measure of security — it scores configuration against Microsoft's defaults — but it's a useful planning backlog. Many security teams treat the next 10 unimplemented actions as their next quarter's workload.
What the score actually measures — and doesn't
Each Secure Score action has a defined point value and one of three implementation states: not implemented, partially implemented (some but not all scope covered — MFA enforced for some but not all users, for instance), or fully implemented. The score is a percentage of achievable points across every action Microsoft has defined for the licences the tenant holds — a tenant on Microsoft 365 Business Premium sees a different, smaller set of applicable actions than an E5 tenant, because some actions require capabilities the lower plan simply doesn't include. Crucially, the score reflects configuration against Microsoft's recommended controls, not an independent measure of actual breach risk — a tenant can have a high score by implementing every listed action while still carrying real risk from something Secure Score doesn't model at all (a poorly-scoped custom application, weak physical security, an undocumented shadow-IT integration).
Worked example
A tenant's Secure Score sits at 42%. The dashboard's prioritised list shows the next available actions ranked by point value and estimated effort: enabling Conditional Access blocking legacy authentication (high points, low effort — a single policy), enabling Safe Links for Office apps in addition to email (moderate points, low effort — a licensing feature already available but not turned on), and requiring MFA registration within 14 days of a new user's creation (moderate points, moderate effort — requires a Conditional Access policy plus a communication plan for new hires). The security team treats the top five highest-point, lowest-effort actions as this quarter's backlog, working through them in order and watching the score climb as each is marked fully implemented — using the ranked list as a genuinely useful prioritisation tool even though the raw percentage itself isn't the actual goal.
Comparison data and its limits
Secure Score shows how a tenant's score compares to similar organisations by size and industry, which is a reasonable sanity check ("are we meaningfully behind our peers") but shouldn't be read as a target to simply match — an organisation handling more sensitive data than its size-and-industry peers typically do may reasonably need a higher score than the comparison group's average suggests, and the comparison data has no visibility into what any peer tenant actually protects.
Common pitfalls
Treating Secure Score as a compliance certificate or an external-facing security guarantee is a common misstep — it's an internal planning tool, not an audit standard, and it has no bearing on formal certifications like ISO 27001 or SOC 2 even though the underlying controls often overlap. The second common mistake is chasing every available point regardless of actual business fit — some actions carry meaningful user-experience trade-offs (blocking a legitimate but legacy-auth-dependent business process, for instance) that deserve a real cost-benefit conversation rather than being implemented purely because they're worth points.