Prioritising Microsoft Secure Score Instead of Chasing Points

By · Published

Microsoft Secure Score measures in the Microsoft Defender portal how many of the recommended security measures are implemented in your tenant. It covers Entra ID, Exchange Online, SharePoint Online, Teams and the Defender products, among others.

Many organisations treat the number like a grade to be maximised. That often leads to collecting easy points while the measures with the greatest protective value are left undone. This article explains how the score works and how to prioritise it sensibly.

How the score is calculated

Each recommendation is worth at most 10 points. Some are awarded all or nothing, others proportionally: if 50 of 100 users are protected with MFA, you receive half the points.

The values in the portal update continuously, and achieved points are synchronised with system data daily. Some recommendations for Teams and Entra ID refresh less often, so a change does not always show immediately.

Which statuses earn points – and which do not

Every recommendation has a status. Only three of them earn points: “Completed” (detected by the system), “Resolved through third party” and “Resolved through alternate mitigation”. “To address”, “Planned” and “Risk accepted” earn no points.

The two manual statuses for third-party and alternate mitigation are legitimate, for example when another email security product covers the task. They should be documented and verifiable – otherwise the score rises without protection improving.

How Microsoft prioritises

Microsoft ranks recommendations by points remaining, implementation difficulty, user impact and complexity. At the top are measures with many open points that are easy to implement without disrupting users.

That order is useful for a quick start. It does not, however, consider which risks actually exist in your organisation.

Better: prioritise by attack path

Additionally rank recommendations by the real attack path they close. In most Microsoft 365 environments, this produces a clear order:

  • Identities: MFA for every account, especially administrators, and blocking legacy authentication.
  • Privileged roles: as few Global Administrators as possible, protected with strong authentication.
  • Email: protection against phishing and malicious attachments in Exchange Online and Defender for Office.
  • Data: limiting external sharing in SharePoint and OneDrive.
  • Devices: compliance requirements through Intune, linked to Conditional Access.

Use “Risk accepted” deliberately

Not every recommendation fits every organisation. If you deliberately decide not to implement a measure, set the status to “Risk accepted” and record the reason. That keeps it clear that it was a decision, not an oversight.

Use the history as a KPI

Secure Score keeps a history and can be compared with organisations of similar size. For management, the trend over months says more than the absolute value – especially when reported together with the core measures implemented.

Key takeaway

A high Secure Score is not an end in itself. Prioritising recommendations by attack path, documenting exceptions and using the history as a KPI improves actual protection – and the score rises as a side effect.

Sources